NetsPWN: Assessment Services

Penetration Testing – Deception through Vocabulary

View all posts by Alex Crittenden

Alex Crittenden

April 24, 2012

I’ve also discovered that non-security executives often seem to think that a pen test is a pen test is a pen test and while this certainly isn’t the case (there is real skill involved in effective penetration testing, as well as the need for a solid process), what’s really frustrating is that it’s often the situation that what people call a pen test is actually a vulnerability assessment or a scan and that drives me nuts.
READ POST

NetsPWN: Assessment Services

Introduction to Windows Dictionary Attacks

View all posts by Scott Sutherland

Scott Sutherland

April 9, 2012

In nine out of ten environments at least one account is found configured with a weak password. In this blog I cover the basics of conducting dictionary attacks against Windows systems so you can find them before attackers do.
READ POST

NetsPWN: Assessment Services

Mobile security is the new hotness

View all posts by Michael Anderson

Michael Anderson

April 2, 2012

...there isn’t a technical control that can prevent a given user from installing a malicious app and accidentally compromising anything from their email to their entire corporate environment.
READ POST

NetsPWN: Assessment Services

When Databases Attack: SQL Server Express Privilege Inheritance Issue

View all posts by Scott Sutherland

Scott Sutherland

September 29, 2011

By default, SQL Server Express supports a lot of great options that make it a very practical solution to many business problems. However, it also comes configured with a not so great option that could allow domain users to gain unauthorized access to SQL Server Express instances. In this blog I’ll cover what the issue is, how to attack it, and how to fix it.
READ POST

NetsPWN: Assessment Services

Hacking with JSP Shells

View all posts by Scott Sutherland

Scott Sutherland

July 7, 2011

Most enterprise datacenters today house at least a few web servers that support Java Server Pages (JSP). In this blog, I’ll provide two JSP shell code examples and outline five common upload methods that can be used to get the shells onto vulnerable servers in order to execute arbitrary system commands.
READ POST

NetsPWN: Assessment Services

When Databases Attack: Secure360

View all posts by Scott Sutherland

Scott Sutherland

June 6, 2011

We put together a revised version of our "When Databases Attack" presentation based on some feedback from the Bsides crowd. It includes some new SQL script examples that should be fun to play with.
READ POST

NetsPWN: Assessment Services

Business Logic Time

View all posts by abacchus

abacchus

February 15, 2011

You've noticed a sudden loss in clients, and a sharp gain in the success of one of your closest competitors; the app containing all your intellectual property and sales information was owned.
READ POST