NetsPWN: Assessment Services

Presenting at OWASP AppSec Conference

View all posts by Scott Sutherland

Scott Sutherland

August 16, 2010

Antti Rantasaari and I will be delivering our presentation “Escalating Privileges through Database Trusts” at the National OWASP AppSec conference in Irvine, CA on September 10th. We are very excited to have the opportunity to share some the of the common application and database implementation weaknesses we see in the real world.
READ POST

NetsPWN: Assessment Services

Windows Tools in BackTrack

View all posts by Scott Sutherland

Scott Sutherland

July 21, 2010

For those of you who aren’t in the loop, BackTrack is a Live Linux distribution that ships with a large number of open source tools that can be used to assess the security of networks, systems, and applications. At this …
READ POST

NetsPWN: Assessment Services

Invisible Threats: Insecure Service Accounts

View all posts by Scott Sutherland

Scott Sutherland

July 1, 2010

In the wonderful world of Windows, service accounts are basically the man behind the curtain. Almost invisible to the naked eye, they can be used to run almost any application you can dream up. That includes everything from database services …
READ POST

NetsPWN: Assessment Services

The Systems That Time Forgot

View all posts by Scott Sutherland

Scott Sutherland

June 15, 2010

Do you know about ALL of the systems on your network? If so, you’re in the minority. Identifying and actively managing all the systems on a network is not an easy task. Environments are constantly changing, asset owners come and …
READ POST

NetsPWN: Assessment Services

Manual vs. Automated Testing

View all posts by Seth Peter

Seth Peter

January 22, 2010

. . . no single application assessment or code review product could find more than about 35% of the total vulnerabilities GE could find with a manual process. That alone should encourage anyone serious about eradicating vulnerabilities within their applications to step it up a notch!
READ POST