Welcome to The Professional Security Testers Warehouse for the GPEN GSEC GCIH GREM CEH QISP Q/ISP OPST CPTS
Search
Nickname Password Security Code Security Code Type Security Code  
FITSI the certification program for the federal workforce
You are certified but are your qualified?  Become qualified today.

Video Library

Skimming for ID theft
5 / 2
Views: 180
Comments: 1
11-01-2008 00:18

Latest version of ATM skimmer hidden behind a speaker looking device
5 / 2
Views: 193
Comments: 0
11-01-2008 00:11

ATM Scam, do check your ATM machine before using it
5 / 1
Views: 181
Comments: 1
10-31-2008 23:59

Survey

Whic of the following certifications would you like to get?

GPEN
GCIH
CEH
QEH
GREM
GSEC
CISSP
Security+
Other (please leave a comment)



Results
Polls

Votes: 219
Comments: 0

Who's Online

There are currently, 71 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
The Professional Security Testers Warehouse for the GPEN GSEC GCIH GREM CEH QISP Q/ISP OPST CPTS: Hakin9

Search on This Topic:   
[ Go to Home | Select a New Topic ]

September issue of Hakin9 magazine: Mobile Malware – the new cyber threat
Posted by cdupuis on Tuesday, 31 August 2010 @ 09:18:46 EDT (434 reads)
Topic Hakin9



Hakin9

September issue of Hakin9 magazine:
Mobile Malware – the new cyber threat

New issue of Hakin9 magazine already available!

Inside:

  • Mobile Malware – the new cyber threat
  • Botnet: The Six Laws And Immerging Command & Control Vectors
  • Hacking Trust Relationships – Part 2
  • Web Malware – Part 2
  • Defeating Layer-2 – A ttacks in VoIP
  • Armoring Malware: Hiding Data within Data
  • Is Anti-virus Dead? The answer is YES. Here’s why…


Download your copy NOW -- Click HERE


Mobile Malware – the new cyber threat
Julian Evans
Mobile phone malware first appeared in June 2004 and it was called Cabir. The mobile-phone features at most risk are text messaging (using social engineering), contacts list, video and buffer overflows. GSM, GPS, Bluetooth, MMS and SMS will indeed be some of the attack vector to expect this year and beyond.


Botnet: The Six Laws And Immerging Command & Control Vectors
Richard C. Batka
New BotNet communication vectors are emerging. The industry is not prepared. For the next 20 years, BotNets will be what viruses were for the last 20.


Hacking Trust Relationships – Part 2
Thomas Wilhelm
This is the second article in a series of six that covers the topic of hacking trust relationships. This article focuses specifically on Vulnerability Identification against a target system, in order to identify and exploit potential trust relationships.


Web Malware – Part 2
Rajdeep Chakraborty
In the previous section of the article Web Malwares (Part 1) we discussed various statistics that showed us the increase of Web Malware activity in recent years and why the focus of Malware authors has changed from creating havoc in the infrastructure to infecting the endpoints for various other henious purpose, we have seen it all. Once we are aware of these facts and figures, in the next section we will look into the technical Details of Web Malwares (Part 2).


Defeating Layer-2 – A ttacks in VoIP
Abhijeet Hatekar
ARP Poisoning and other Layer 2 attacks are present since many decades now and one may think that they are absolute. However, we still see them quite often on the network. The biggest advantage is easy access to sensitive information like passwords, credit card details, phone conversations etc.


Armoring Malware: Hiding Data within Data
Israel Torres
We are receiving malware daily via hundreds of facets that the Internet enables with various services; most common are via e-mail and web surfing. At any one time you can be sitting idly on the ‘net when you are presented with something that could be malicious either overtly or covertly. We’ll play through the scenario of where you’ve discovered a binary on your network and unsure of it’s purpose... and then reveal how it was done.


Is Anti-virus Dead? The answer is YES. Here’s why…
Gary Miliefsky
There have been billions of dollars in damages caused by exploiters on the Internet. These exploiters are intelligent cyber terrorists, criminals and hackers who have a plethora of tools available in their war chest – ranging from spyware, rootkits, trojans, viruses, worms, zombies and botnets to various other blended threats. From old viruses to these new botnets, we can categorize them all as malware.


Hakin9 magazine is also available in German.
Download here


Contacts Us

editors@hakin9.org
Editor-in-Chief
Karolina Lesińska
karolina.lesinska@hakin9.org


(Read More... | Score: 0)


Hakin9 August Issue: Securing the cloud
Posted by cdupuis on Tuesday, 03 August 2010 @ 16:46:19 EDT (523 reads)
Topic Hakin9

Hakin9

August issue of Hakin9: Securing the Cloud

New issue of Hakin9 magazine already available!

Inside:

  • Prey: A New Hope by Mervyn Heng
  • An introduction to Reverse Engineering: Flash, .NET by Nilesh Kumar
  • Web Malware - Part 1 by Rajdeep Chakraborty
  • Cyber warfare with DNSbotnets by Francisco Alonso
  • Search Engine Security and Privacy by Rebecca Wynn
  • Securing the Cloud: Is it a Paradigm Shift in Information Security? by Gary Miliefsky
  • Radio Frequency-enabled Identity Theft by Julian Evans
  • Intelligence Monopolies by Matthew Jonkmann
  • Special Report: Capturing the New Frontier: How To Unlock the Power of Cloud Computing by Mike Armistead

Download


Is Prey: A New Hope
Mervyn Heng
Misplaced your laptop or had it stolen? You are not alone.Dell and the Ponemon Institute collaborated on a study with 106 United States airports as well as over 800 business travelers to ascertain the frequency with which laptops are lost in airports.


An introduction to Reverse Engineering: Flash, .NET
Nilesh Kumar
This article is about the demonstration of Reversing of Flash and .NET applications. This is an introductory article showing basics of decompiling/ disassembling. In the first I have chosen to show reversing of Flash files and .NET files and how to patch them.


Web Malware - Part 1
Rajdeep Chakraborty
The Internet has been plagued by a variety of Malware that use the Web for propagation and as these threats loom around in the Internet it can infect even the smartest and the most tech savvy computer users.


Cyber warfare with DNSbotnets
Francisco Alonso
Botnets aren’t just a fad or items being sold and purchased like items on ebay, but are becoming carefully designed tools used for cyber war. In this article we will discuss what a Botnet is, and the next generation of Botnets over DNS.


Search Engine Security and Privacy
Rebecca Wynn
It’s no secret that search engines like Google, Yahoo, Bing (MSN) retain search data and metadata regarding searches. They are open about doing so. What’s unsure, though, is to what extent this creates a long-term threat to information security and privacy. This article briefly reviews what data is retained and stored by these search engines and what readers can do to protect their information.


Securing the Cloud: Is it a Paradigm Shift in Information Security?
Gary Miliefsky
First let me start by saying No. There’s really nothing new in the Cloud except where risk appears to shift. But does it really? I would argue that it increases your risk and there can be no shift of blame for a successful Cloud attack and breach of confidential data stored in the Cloud. You are ultimately responsible.


Contacts Us

editors@hakin9.org
Editor-in-Chief
Karolina Lesińska
karolina.lesinska@hakin9.org


(Read More... | Score: 0)


Haking 9 SECURING VOIP July edition available for FREE download
Posted by cdupuis on Thursday, 15 July 2010 @ 15:37:51 EDT (547 reads)
Topic Hakin9

Securing VoIP -- New ONLINE issue

DOWNLOAD FOR FREE CLICK HERE 


 

See the full list of articles at
  hakin9 website


  

Download 2009/2010 archives of Hakin9 magazine

 

Click here!


(Read More... | Score: 0)


Hackin9 June Edition FREE Download -- Get it now
Posted by cdupuis on Tuesday, 01 June 2010 @ 07:36:29 EDT (858 reads)
Topic Hakin9

Hakin9 Hakin9 magazine JUNE Edition:

Is DDOS Still a Threat?  New issue of Hakin9 magazine already available!

Inside:

* Is DDOS Still a Threat?

* Jailbreaking and Penetrating with the Iphone 3G & 3GS

* Flash Memory Forensic Tools - part two

* Beginner’s Guide to Cybercrime -Understanding Attack Methodologies and a More Proactive Approach to Defense

* Pulling Kernel Forensic with Python

* More Secure PHP Server Side Source Encryption

* Securing Public Services Using Tariq

* Expert Says: Don't let the zombies take you down!

Download you copy now

Is DDOS Still a Threat?
Matt Jonkman Is DDOS, or Distributed Denial of Service, still a credible threat? Do we lay awake at night scared of when the next one might hit us? An obvious question perhaps, they are still a threat to most online enterprises. But they’re not the top of the news issues they once were. Expert Says...: Don’t let the zombies take you down! Ian Kilpatrick

Over the last year, the incidence of botnet (or zombie) attacks has been growing rapidly. Some service providers around the world have already begun to take action against botnets and there is increased interest from other service providers, and from companies, in dealing with this serious security threat.

Beginner’s Guide to Cybercrime – Understanding Attack Methodologies and a More Proactive Approach to Defense Gary Miliefsky How about why nothing with an IP address is secure and why traditional countermeasures such as firewalls, anti-virus and intrusion detection fail? Would you like to learn new methods to proactively defend against attacks? If so, you’ve come to the right place.

Jailbreaking and Penetrating with the Iphone 3G & 3GS Wardell Motley Today Smart phones are getting smarter and smarter. They are a far cry away from the Walkie-Talkie like devices from the the early 90's. Now a smart phone in the hands of skilled attacker can be used to help penetrate networks on the fly. No longer do you need to walk around with a bulky laptop to get the job done.

Flash Memory Forensic Tools - part two This second part is focused on advanced tests done on flash memory embedded in a Nokia mobile phone. Tests presented in this article are not for all as they require a well furbished lab; even that what we try to demonstrate here is that – when flash mobile forensic will leave its infancy – there are some issues forensic officers should take in consideration.

Download your copy now

Contacts Us
editors@hakin9.org
Editor-in-Chief Karolina Lesińska
karolina.lesinska@hakin9.org


(comments? | Score: 0)


Hakin9 Magazine is now FREE -- Get your copy NOW!
Posted by cdupuis on Sunday, 16 May 2010 @ 14:47:22 EDT (1564 reads)
Topic Hakin9

Hakin9

Download May issue of Hakin9 magazine today!

Inside:

  • Writing WIN32 shellcode with a C-compiler
  • Flash memory mobile forensic
  • Threat Modeling Basics
  • Pwning Embedded ADSL Routers
  • Firewalls for Beginners

Regulars:

  • ID Fraud Expert Says by Julian Evans: Identity Theft Protection Services – a new industry is born
  • Interview with:
  • Victor Julien, lead coder for the Open Information Security Foundation
    Ferruh Mavituna, web application penetration tester and security tool developer
  •  
    • Tool reviews: NTFS Mechanic, Active@ Undelete Professional, KonBoot v1.1

Download your copy now -- Click HERE


Pwning Embedded ADSL Routers
by Aditya K Sood
This paper sheds light on the hierarchical approach of pen testing and finding security related issues in the small embedded devices that are used for local area networks. The paper is restricted to not only testing but also discusses the kinds of software and firmware used and incessant vulnerabilities that should be scrutinized while setting up a local network.


Firewalls for Beginners
by Antonio Fanelli
Firewalls are often overlooked, but are actually one of the best deterrents against unauthorized accesses. Learn how to build a low-cost firewall with iptables. Whenever people ask me how they can be sure no one can have unauthorized remote access to their PC, my first answer is: disconnect your PC!


Writing WIN32 shellcode with a C-compiler
by Didier Stevens
Shellcode is hard to write. That is why I worked out the method presented here to generate WIN32 shellcode with a C-compiler. To fully benefit from the content of this article, you should have some experience writing WIN32 programs in C/C++ and WIN32 shellcode, and understand the differences between both approaches.


Flash memory mobile forensic
by Salvatore Fiorillo
This paper is an introduction to flash memory forensic with a special focus on completeness of evidences acquired from mobile phones. Moving through academic papers and industrial documents will be introduced the particular nature of non-volatile memories present in nowadays mobile phones; how they really work and which challenges they pose to forensic investigators.


Threat Modeling Basics
by Timothy Kulp
In the world of software, security is thrown into a system somewhere at the end of the project. For many developers adding security to a system is using a login with SSL/TLS; but sadly, these two are not the security silver bullet developers are led to believe.


Contacts Us

editors@hakin9.org
Editor-in-Chief
Karolina Lesińska
karolina.lesinska@hakin9.org


(comments? | Score: 0)


Hakin9 Magazine now FREE in Digital Format
Posted by cdupuis on Saturday, 24 April 2010 @ 19:37:12 EDT (817 reads)
Topic Hakin9

 
 

 
Hakin9 : Go Green - Choose Download!

Hakin9 magazine - The First FREE ONLINE Magazine Devoted to IT Security


Hakin9 magazine is from now on a FREE, MONTHLY, ONLINE publication.

Due to a great interest in Hakin9 magazine coming from all over the world we
decided to go digital and make the magazine free.

All you need to do in order to get a new issues each month is subscribe to our newsletter.

Those of you who are on the list, just need to wait few more weeks!

The first issue will be released on April 30th.


  Subscribe to the newsletter at:

http://hakin9.org/newsletter

 

Mobile Exploitation
  issue in stores!
 


 

See the full list of articles at
  hakin9 website


  

Download issue 6/2009(25):
Windows FE Forensic Live CD
FOR FREE

Click here!


 

Become a Fan of Hakin9 IT Security Magazine on Facebook!

Click here!

 


 

 

Tool review section on hakin9 website!

Visit our website and read all tool reviews from hakin9 2009 issues
Read now!

 



 

Please spread the word about Hakin9.
Hakin9 team
www.hakin9.org
en@hakin9.org
tel. +1 917 338 36 31

Find hakin9 magazine on:
         

 


(comments? | Score: 0)


Get a FREE copy of the Hakin9 Magazine
Posted by cdupuis on Thursday, 04 March 2010 @ 21:50:58 EST (929 reads)
Topic Hakin9

NOTE FROM CLEMENT:

Here is another issue of Haking 9 being given away for FREE.  It is a bit less than a year old but still VERY relevant to todays threat.  The magazine will give you an idea of the content you usually find in Hakin9. ENJOY!

Clement

21st Century Hacking Techniques

Release Date: 2009-05

H9_en_05_2009

 

  • Free Issue to Download! 05/2009 05_2009.ZIP Click HERE to Download

    Articles in this issue


  • Windows Timeline Analysis

    The increase in sophistication of the Microsoft (MS) Windows family of operating systems (Windows 2000, XP, 2003, Vista, 2008, and Windows 7) as well as that of cybercrime has long required a corresponding increase or upgrade in incident response and computer forensic analysis techniques.


    - Harlan Carvey
  • Analyzing Malware Introduction to Advanced Topics

    In this final article in our three-part series on analyzing malware we will discuss more advanced topics. The topics we are going to include are: polymorphic code, metamorphic code, and alternative data stream.


    - Jason Carpenter
  • Hacking ASLR & Stack Canaries on Modern Linux

    This article will demonstrate methods used to hack stack canaries and Address Space Layout Randomization (ASLR) on modern Linux kernels running the PaX patch and newer versions of GCC.


    - Stephen Sims
  • Mashup Security

    Mashups will have a significant role in the future of Web 2.0, thanks to one of the most recent data interchange techniques: JSON. But what about security


(Read More... | 1 comment | Score: 0)


Get FREE copies of Hakin9 Magazines -- PDF Download
Posted by cdupuis on Tuesday, 02 February 2010 @ 08:23:11 EST (1203 reads)
Topic Hakin9

NOTE FROM CLEMENT:

Below you have a few copies of Hakin9 that you can download for free from the Hakin9 web site.  On the same page as the magazine you will also find dozens of great articles that you can look at.  They are all in PDF Format.

All that is required to access the downloads is to join their mailing list.  You will immediately receive through email a confirmation link with instruction on how to access the files.  Do read the past issues, you will see that coverage is very thorough and most of the content would still be applicable today with minor changes.  Hakin9 is a magazine that I like very much and it always contains great articles and howto.  The printed magazine comes with a bootable version of Backtrack plus many commercial utilities with license to use.  The best way to really appreciate if it is for you or not is by downloading some of the copies below and see for yourself.

MY ERP GOT HACKED!  Release Date: 2009-07

04_2009-1_free

Issue_contents
  • Nokia’s Vow of Silence
  • Phishing
  • Print Your Shell
  • My ERP Got Hacked – An Introduction to Computer Forensics
  • Attacks On Music and Video Files
  • The Strings Decoding Process
  • Hacking Through Wild Cards
  • Create a Self-Signed Digital Certificate with OpenSSL
  • Automating Malware Analysis

FREE ISSUE: My ERP Got hacked! 04/2009  Download pdf


Breaking Client-Side Certificate Protection   Release Date: 2009-03

Hakin9_3_2009_en

Issue_contents
  • Brute Force Attack
  • Exporting Nonexportable Certificates
  • User Enumeration with Burp Suite
  • More Thoughts on Defeating AntiVirus
  • A New Era for Buffer Overflow
  • Automating Malware Analysis
  • Anatomy of Malicious PDF Documents
  • Analyzing Malware Packed Executables
  • Bootleggers and the Internet
  • Interview with Nicholas J. Percoco
  • Self exposure with…

    FREE ISSUE: Breaking Client-Side Certificate Protection 03/2009   Download pdf

 

The Real World Clickjacking  Release Date: 2009-02

Hakin9_2_2009_en

Issue_contents
  • Metasploit Alternate Uses for a Penetration Test
  • Backdooring Frameworks
  • The Real World Clickjacking
  • Apple Super Drive. Set It Free
  • Mapping HTTP Interface Embedded Devices
  • How Does Your Benchmark of Physical Security Affect Your Environment?
  • iPhone Forensics
  • Safer 6.1
  • Making Open Security Research Sustainable
  • Interview with Raffael Marty
  • Self exposure with…
  • ENGARDE SECURE LINUX
  • Analyzing Malware

    FREE ISSUE: The Real World Clickjacking 02/2009    Download pdf

 


Hacking Instant Messenger    Release Date: 2001-01

Hakin9_1_2009_en

Issue_contents
  • Metasploit Alternate Uses for a Penetration Test
  • Backdooring Frameworks
  • The Real World Clickjacking
  • Apple Super Drive. Set It Free
  • Mapping HTTP Interface Embedded Devices
  • How Does Your Benchmark of Physical Security Affect Your Environment?
  • iPhone Forensics
  • Safer 6.1
  • Making Open Security Research Sustainable
  • Interview with Raffael Marty
  • Self exposure with…
  • ENGARDE SECURE LINUX
  • Analyzing Malware

FREE ISSUE: Hacking Instant Messenger 01/2009  Download pdf

 


(comments? | Score: 0)


Special offers to hakin9 magazine subscription for CCCure members and visitors!
Posted by cdupuis on Thursday, 03 December 2009 @ 15:11:36 EST (1557 reads)
Topic Hakin9

Anonymous writes "

CCCure Offer #1 -- One year print edition:

-  10% discount (discounted price: $44.10)
-  CD with 2005-2008 archvies
-  electronic subscription for FREE (one year)

To take advantage of the One Year Subscription offer simply click on the URL below:

Click HERE to subscribe to the One Year Print Edition Offer 

Ensure the email body has the following information:
Your First and Last names
You full mailing address

CCCure Offer #2 -- Two-year print edition:

-  10% discount (discounted price: $71.10)
-  CD with 2005-2008 archives
-  Eelectronic subscription for free (one year)
+ The Best Of Edition Magazine for free

To take advantage of the Two Years subscription offer simply click on the URL below:

Click HERE to subscribe to the Two Years Print Edition Offer 

Ensure the email body has the following information:
Your First and Last names
You full mailing address



CCCure Offer #3 -- PDF only subscription offer:

One-year PDF subscription for $20. The regular price is $30.

To take advantage of this PDF subscription offer simply click on the URL below:

Click HERE to subscribe to the PDF only Offer 

Ensure the email body has the following information:
Your First and Last names
You full mailing address

"

(Read More... | 11 comments | Score: 0)


Hakin9 News: Download Article "My ERP Got Hacked. Part II"
Posted by cdupuis on Thursday, 12 November 2009 @ 07:08:21 EST (1337 reads)
Topic Hakin9

Hakin9 Specials
Download Article "My ERP Got Hacked. Part II" For Free!
Live Hacking, Guide to Computer Hacking!
The Secret of Ethical Hacking!
LIVE HACKING: The Ultimate Guide to Hacking Techniques & Countermeasures for Ethical Hackers & IT Security Experts

Dr. Ali Jahangiri, a world-renowned information technology (IT) expert, brings us the next must-have in IT training: Live Hacking, the definitive and comprehensive guide to computer hacking. Groundbreaking, insightful, and practical, this guide serves to inform IT professionals about and challenge existing conceptions of hacking, its victims, and its consequences, but with an eye to empowering prospective victims with the knowledge they need to thwart the criminal elements in cyberspace. Whether you work in a Fortune 500 company or if you're just looking to protect your home office from hackers, this book will provide you with all the information you need to protect your valuable information. Don't be a victim; be ready!

Live Hackingis straightforward, easy to read, and a reference that you'll use again and again. It's the kind of book you'll want to keep in your back pocket! With a user-friendly writing style and easy-to-follow diagrams and computer screenshots, Dr. Jahangiri expounds on all of the major issues - and more - n hacking:


- Basic Hacking Terminology
- Reconnaissance
- Google Hacking
- Scanning
- Enumeration
- Password Cracking
- Windows Hacking
- Malware
- Data Packet Sniffers
- Web Server and Web Application Hacking
- Denial of Service
- Wireless Network Hacking


Dr. Jahangiri conducts thousands of hours of training per year, has patents in network security, and speaks on a variety of computer security-related issues all over the world. He even offers advice on his web site www.alijahangiri.org. His new book Live Hackingis like having your own private IT security guard. With his knowledge at your fingertips, you can fight back and stay on the offensive!

 

Free Online Security Scan
Scan for XSS, SQL Injection, Web Errors

The Protector Ultimate UTM Appliance

Award Winning Anti Spam - Anti Virus - Web Filter - Web Proxy - IPS - Content Filter
The Protector solves your entire network's spam and security problems with just one appliance!

All in one at one cost

For more information please see the link to http://shop.secpoint.com/

Request a free evaluation unit at: http://www.secpoint.com/

Request a free scan: http://www.secpoint.com/

 

The Secret of Ethical Hacking

 
Free IP Scan:
Get a detailed report on 1 publicly facing IP address

Detect vulnerabilities on your Internet-facing server with this free tool from Qualys

FreeScan allows you to quickly and accurately scan your server for thousands of vulnerabilities that could be exploited by an attacker.

If vulnerabilities exist on the IP address provided, FreeScan will find them and provide detailed information on each risk - including its severity, associated threat, and potential impact.

 Scan now!
 

SAINT
Securing
Your Network Just Got Easier

 

Download Article "My ERP got hacked - An Introduction to Computer Forensics - Part II " For Free 


Now we are finally getting closer to know if there was any unauthorised access to the Web-based Enterprise Resource Planning (ERP) server, how it happened and what was the extent of the damage...

Read the second part of Ismael Valenzuela's article online!
http://hakin9.org/

Windows FE Forensic Live CD
in stores!
 


-Windows FE A Windows-PE Based Forensic Boot CD
-Network Forensics: More Than Looking For Cleartext Passwords
-Unified Communications Intrusion Detection Using Snort
-Protocol Channels
-Fuzzing Finding Vulnerabilities with rand()
-Windows Timeline Analysis, Building a Timeline, Part 2
-Anatomy of Malicious PDF Documents, Part 2
-Recovering Debugging Symbols From Stripped Static Compiled Binaries
-Simple DLP Verification Using Network Grep
-A Look at How the Mobile Phone Opens the Door to Location (LBS) Tracking, Proximity Marketing and Cybercrime
-Interview with Michael Helander
-Viva la Revolucion!

Hakin9 The Real World Clickjacking Magazine!  




The 6 FREE Hakin9 Issues! Read Online Now! 


http://www.hakin9.org/

http://www.hakin9.org/

http://www.hakin9.org/



http://www.hakin9.org/



http://www.hakin9.org/



http://www.hakin9.org/

Please spread the word about Hakin9.
Hakin9 team
www.hakin9.org
en@hakin9.org
tel. +1 917 338 36 31


(comments? | Score: 0)


Hakin9 News: User Enumeration with Burp Suite - Free Article!
Posted by cdupuis on Thursday, 06 August 2009 @ 14:50:08 EDT (1698 reads)
Topic Hakin9

Anonymous writes "

 

Hakin9 News: User Enumeration with Burp Suite!
The Protector Ultimate UTM Appliance!
Get a detailed report on 1 publicly facing IP address!
My ERP Got Hacked - The New Issue is out!

Just a short overview: Take a look at the first article on page 32, and be sure to know what to do when your ERP has been hacked. Give yourself a fresh portion of healthy H9 learning material.
Take a look at the article that touches the strings decoding process – page 46.
Are you a fan of the new attacks? Always something for you in H9. Check page 40.
Go through the rest articles, for sure you will find something worthwhile. For dessert check page 58 – and create a digital certificate with OpenSSL. Also, read the interview with Billy Austin – CSO, at SAINT Corporation – page 78.
This month’s CD is a Live version of BackTrack 3, which is the most top rated Linux distribution focused on penetration testing, plus a few more interesting applications.

Go to http://www.hakin9.org to check the magazine's content.

Read your new hand-picked collection of selected articles and enjoy.
Kind regards,
The Hakin9 Team

 

Are your productivity secured?
The Protector Ultimate UTM Appliance
All In One at One Cost

The Protector Ultimate UTM Appliance

Award Winning Anti Spam - Anti Virus - Web Filter - Web Proxy - IPS - Content Filter

The Protector solves your entire network's spam and security problems with just one appliance!

All in one at one cost!

For more information please see then link to:
http://shop.secpoint.com/shop/protector-utm-with-53c1.html
Request a free evaluation unit at:
http://www.secpoint.com/secpoint-evaluation-unit.html

The Hacker's Nightmare
Unchallenged as the Bible of Computer & Internet Security 


Where do you turn when you absolutely cannot afford to be Hacked, Cracked, Robbed, Impersonated, Phished, Scammed, Spied On, Virus Infected or Otherwise Compromise?

All computer users, at home or in the office, are exposed to more security risks then they can possibly imagine. Criminals and unprincipled deadbeats constantly prey on unsuspecting victims. So for your own protection you need to know...

  • HOW TO keep your sensitive files away from prying eyes;
  • HOW TO protect your PC from malicious attacks;
  • HOW TO keep your online banking, shopping and e-mail safe.

and with The Hacker's Nightmare you'll learn, in simple jargon-free terms, how to...

  • Root out malware* that has already taken up residence in your PC
  • Securely block* the pathways hackers can use to gain access to your data
  • Protect against* future attacks and infestations
  • Recognize the tricks* of the spammers, scammers and eavesdroppers
  • Keep prying eyes* away from your sensitive documents

And that's just a fraction of the knowledge you'll gain from this landmark work.

Invest in your privacy and security now!
http://www.HackerNightmare.com

Free IP Scan
Get a detailed report on 1 publicly facing IP address
Detect vulnerabilities on your Internet-facing server with this free tool from Qualys

FreeScan allows you to quickly and accurately scan your server for thousands of vulnerabilities that could be exploited by an attacker.
If vulnerabilities exist on the IP address provided, FreeScan will find them and provide detailed information on each risk - including its severity, associated threat, and potential impact.

 Scan now!

SAINT
Securing Your Network Just Got Easier

 

SC World Congress - Enterprise Data Security,
October 13-14 in New York City

Make plans now to attend the second annual SC World Congress - Enterprise Data Security, October 13-14 in New York City.

The Congress features a comprehensive, two-day program presented in four tracks-including the unique Editors Choice sessions-and the industry's largest fall product expo showcasing IT security solutions from the leading vendors and hot start-ups. Emphasizing quality content, innovative formats and sessions, global perspectives and ROI, this is the one event you can't afford to miss.

Register by August 31 for big savings.
www.scworldcongress.com

 

User Enumeration with Burp Suite
The Free Hakin9 Article!


written by Chris John Riley

It seems like not a day passes without seeing a website that is vulnerable to user enumeration. No matter if the website is small or large, so many developers don't seem to know the difference between good user feedback and providing too much information.


Download now!

 

Hakin9 1/2009
Hacking Instant Messenger



Still You Can Download Your FREE Issue!
Download now!



"BEST of Hakin9"
magazine is coming


"BEST of" Hakin9 magazine prepared especially for our readers.

220 pages of the best articles ever

In Stores August 2009!



Free BEST OF HAKIN9 Magazine Contest July 2009!


Want to have free issue of BEST OF HAKIN9 magazine?

Join us in 3 easy steps,
go to http://hakin9.org to see details.

Don't miss your chance!

 

Please spread the word about Hakin9.
Hakin9 team
www.hakin9.org
en@hakin9.org
tel. +1 917 338 36 31

"

(Read More... | 5 comments | Score: 0)


Hakin9 News: Download FREE article on Training - The Security Minefield and VID
Posted by cdupuis on Thursday, 12 February 2009 @ 10:43:43 EST (1080 reads)
Topic Hakin9

 

Download FREE article on Training - The Security Minefield and VIDEO TUTORIAL by Lou Lombardy!
 
 
 
Training – The Security Minefield by Chris Riley
– Hakin9 article for free!

Training – The Security Minefield by Chris Riley
Learning something new is a wonderful thing. However, with all the security training on offer right now, how do you know what's right for you?

 

Alternate Data Streams by Lou Lombardy
– Video Tutorial for free!

Alternate Data Streams by Lou Lombardy
This is a great video tutorial presenting the use of Alternate Data Streams. You will need Windows XP environment with ServicePack2.

 

Vulnerability Management Buyer's Checklist

Key Questions to Ask Before You Select a VM Solution

Choosing a solution for VM is a critical step toward protecting your organization's network and data. Without proven, automated technology for precise detection and remediation, no network can withstand the daily onslaught of new vulnerabilities that threaten security.

To help finalize your decision on which solution to buy, download this 12-point short list of considerations that will help you determine what will work best for your organization.

 

IT Underground Conference and Workshop

Hacking and IT security
23rd - 25th of March 2009
Prague, Hotel Step

Take your laptop and join our conference. The IT security experts will show you how to protect your computer against hacker's attacks. You will have the opportunity to discuss security threats and problems with IT security experts. You will have a chance to meet: Wiktor Schmidt, Ferenc Spala, Petr Matousek, Simon Rich, Felix Kronlage and others. We offer you lectures in two sessions. Some of them are BYOL mode.

Register at our website today!
See you soon in Prague!
Contact us!

 

The uCon Conference

uCon is a vendor-neutral and single track conference on hacking, technology and information and telecommunication security to be held again in 28th of February 2009 – three days after the best street carnival in the world, in Recife, Brazil, and aims to bring together academics, hackers and information security enthusiasts from all over the country to share cutting-edge ideas and thoughts about their latest developments and techniques in the field.
Attendees will have the opportunity to network with like-minded people during social events, such as lunch break and aftercon party and during the capture the flag competition.

http://www.ucon-conference.org

 




* BPMTK
* Keylogger 2.0
* Defeating AntiVirus Software
* Hacking IM Encryption Flaws
* HTTP Tunnel
* Agent-based Traffic Generation
* and more...

Video Tutorial on The Art of Black Packaging on Hakin9 CD

Explore Hakin9 Website!


Explore our website to learn more ... about Lizard Safeguard PDF Security.

 







Check our News & HTML Articles sections out!


Hakin9 Forum


Join our forum! Ask for answers!

Don't waste your time!
Visit Hakin9 forum today!

Hakin9 forum!



Please spread the word about Hakin9.
Best regards,
Hakin9 team
www.hakin9.org
en@hakin9.org
tel. +1 917 338 36 31

 



(comments? | Score: 0)


Hakin9 Newsletter
Posted by cdupuis on Wednesday, 08 October 2008 @ 10:46:57 EDT (4417 reads)
Topic Hakin9

Lou writes "

hakin9 article for free!
hakin9 latest article - Exploitation and Defense of Flash Applications - now
available to download for absolutely free. The very useful article which
discusses the specific Flash attack vectors. The paper describes important
Flash security auditing tips as well as the proper development and configuration
techniques.

Download the article from:
http://www.hakin9.org/prt/view/pdf-articles.html

Vulnerability Management for Dummies: Free eBook!


Eliminating network security threats and achieving compliance doesn't need to be complicated,
time consuming, or expensive.

As a network security professional, understanding how to prevent attacks and eliminate network
weaknesses that leave your business exposed is critical.
Vulnerability Management for Dummies arms you with the information needed to implement a successful
security risk management program for your company.

 

In Vulnerability Management for Dummies, you'll get a:
* Complete understanding of the risks posed by cyber criminals and the latest vulnerability trends
* Step-by-step procedures for establishing policies, tracking inventory, scanning systems,
identifying and fixing vulnerabilities, and verifying compliance
* Breakdown of the different vulnerability management options available
* 10 Best-Practice keys to establish a successful vulnerability management program

Download Now!
http://www.qualys.com/forms/dummies/?lsid=7381&leadsource=cccure

 

 

See How The Makers Of The M-16 Rifle Protect Their Mobile Workers


Most companies still face a common IT challenge: managing their employee laptops. Employees
frequently travel for work and take along their laptops that contain sensitive business data.
As more and more employees rely on laptops as their main workplace computer, volumes of information
that previously remained within the confines of the office are now increasingly put at risk
as they travel the world.



Read the special edition case study to find out how FN-Manufacturing:

*   Protects their laptops from attack, loss, and theft
*   Protects their intellectual property from theft and misuse
*   Manages and controls network access and user behavior
*   Benefits from a single, lightweight endpoint security agent

For more information, please visit: www.skyrecon.com


Secure Your Intellectual Property


Control who uses your content, what they can do with it, and how long they can use it for. 
Stop use and misuse of your documents, ebooks, training courses and web based content. 
Prevent copying, saving, sharing, modifying, print screen and screen grabbing. 
Prevent or control the number of prints and views.  Expire or instantly revoke access.

LockLizard http://www.locklizard.com is a DRM (digital rights management) company that specializes
in document security and copy protection for pdf, flash, ebooks, software and web based content
(elearning courses, web portals, etc.).

We protect information with US Government strength encryption and DRM controls to ensure complete
protection against copyright piracy.  We provide copyright protection without the use of passwords to
ensure maximum security and usability, and to protect information, documents and web content from
unauthorized use and misuse no matter where it resides.

LockLizard digital rights management products are aimed at both publishers and companies that share
or sell PDF or web based content where a higher degree of security and control is required - beyond
simple password protection.  Simply, securely, and cost effectively distribute, and manage,
your digital content.  Protect documents inside and outside your organization, and instantly revoke access
to your secure information at any stage.

Control your intellectual property (IPR) securely regardless of where it resides, reduce publishing costs,
ensure regulatory compliance with business processes (e.g. SOX), enforce document retention policies,
establish new revenue generation techniques: these are just some of the business benefits of implementing
LockLizard digital rights management solutions.

Use our DRM software to protect your intellectual property - stop copying, prevent printing, disable
print screen, expire content, and instantly revoke access to information. 
Download a FREE 15 day trial from: www.locklizard.com


High School Programming League


Sphere Research Labs and Hakin9 are thrilled to announce a new major international contest.
The contest is open to participants from all around the world, and is primarily meant for high school
students worldwide. Schools are encouraged to register to become eligible for prizes - 20
schools from 6 countries have already done so, and registration is under way for another 30 schools.
Prizes - portable computers for the winners, and lots gadgets every month - are co-financed by the
contest sponsors, contest organizers, and participating schools.

The contest will consist of seven successive rounds, each approximately 5 weeks in length.
The first problem set opened on September 20 and will last till October 25.

The official contest website (www.hs.spoj.pl) has been open since September 17, 2008.
In the first week nearly 2000 participants created a contest account (accepting contest regulations),
while more than 500 have already started solving problems. These include top rated high students,
such as IOI Cairo gold medallists Maciek Klimek and Jaroslaw Blasiok, and also some ex-pros
participating just-for-fun, for example Reid Barton.

Don't miss your chance!
Register at www.hs.spoj.pl

New issue of hakin9 is now on sale!


Get the latest hakin9 edition - Kernel Hacking. Root Cause Analysis
And Anti-forensics for Memory - and read about:

* VoIPER - VoIP Exploit Research Toolkit
* Web Application Hacking - Attack and Defense of Flash Applications
* Registry Analysis - Find Windows Registry Flaws
* Mobile Devices Security - Locking Down Your Phone from Intrude Abuse
* Rich Internet Applications - Auditing, Attacking, and Breaking Implementations

Don't miss the chance to learn something new. Go to the nearest bookstore or subscribe.

http://www.hakin9.org/prt/view/about-the-mag/issue/893.html

IT UNDERGROUND – XI edition


International Security Workshop & Conference
27.10.2008- 29.10.2008
Hotel Airport Ok?cie, Warsaw, Poland

Your IT Life - Security or Disaster? - the choice is yours.....
Come to Warsaw, meet hackers - the good ones!!
3 days, over a dozen hours of workshops, best-known speakers..

Take care of all IT risks in your company! Join us and feel safe!

As always we assure international speakers: Daniel Mende, Enno Rey,
Angelo Rosiello, Rolf Rolles, Sebastien Doucet, Michael Kemp

Most lectures will be conducted in BYOL (Bring Your Own Laptop) mode,
aimed at participants who have brought their own computers and therefore
will actively participate in sessions.

More information:
http://www.itunderground.org/
SPECIAL DISCOUNTS FOR:
Groups
Students
Participants from previous editions
Hakin9 and Linux+ subscribers

"

(Read More... | 575 comments | Score: 0)


Hakin9 Newsletter
Posted by cdupuis on Friday, 22 August 2008 @ 20:42:26 EDT (8108 reads)
Topic Hakin9

Lou writes "

hakin9 article for free!
hakin9 latest article - File Inclusion Attacks - now available to download for
absolutely free. After reading this paper you will come to know about File
Inclusion Attack's methods and defense techniques against them.

Download the article from:
http://www.hakin9.org/prt/view/pdf-articles.html

Vulnerability Management for Dummies: Free eBook!
Eliminating network security threats and achieving compliance doesn't need to
be complicated, time consuming, or expensive.

As a network security professional, understanding how to prevent attacks and
eliminate network weaknesses that leave your business exposed is critical.
Vulnerability Management for Dummies arms you with the information needed to
implement a successful security risk management program for your company.

In Vulnerability Management for Dummies, you'll get a:
* Complete understanding of the risks posed by cyber criminals and the
latest vulnerability trends
* Step-by-step procedures for establishing policies, tracking
inventory, scanning systems, identifying and fixing vulnerabilities, and
verifying compliance
* Breakdown of the different vulnerability management options
available
* 10 Best-Practice keys to establish a successful vulnerability
management program

Download Now!
http://www.qualys.com/forms/dummies/?lsid=7381&leadsource=93867

Prevent Data Theft From Your PC With Folder Castle
Folder Castle protects your digital data from thieves and snoopers.
It provides two levels of protection: you can lock away files and
folders, or you can put them into a secure container called Secure
Storage with on-the-fly AES-256 encryption. Secure Storage works in
much the same way as an ordinary drive: you can mount or unmount it,
defrag, or check for errors.

Once the file is locked away, you can be sure that it will not be
seen in Windows Explorer or any other file manager even if the
computer is rebooted in Safe Mode. For more peace of mind, you can
enter into the Stealth Mode, which hides the presence of Folder
Castle itself. To run Folder Castle or access Secure Storage, you
should confirm your identity by entering the password.

Folder Castle has a standard layout that makes options readily and
easily available. The program natively integrates into Windows
Explorer, including context menu, toolbar and hot keys. It is fully
compatible with Windows Vista and runs well on the new OS.

Top 5 Reasons To Use Folder Castle:
* Fly below the radar set up by relatives, friends or co-workers
* Secure your personal data on a stolen laptop
* Solid protection of sensitive data
* Take your protected data with you on the USB drive
* Extremely easy to use and quick to install

The product costs $39.95 (US) for a single-user license. You can try
its fully-functional trial version for 15 days before you have to buy it.

Use coupon HAKIN9 at 10% discount.

Product page: http://www.magneticsoft.com/FolderCastle.shtml
Direct download link: http://www.magneticsoft.com/downloads/FolderCastle.exe
Company website: http://www.magneticsoft.com

New issue of hakin9
For those who still haven't got the latest hakin9, we are reminding - it is already in sales! Don't miss it!
Buy and read about:
- File Inclusion Attacks by Ali Recai Yekta and Erhan Yekta
- Hacking RSS Feeds: Insecurities in Implementing RSS Feeds by Aditya K. Sood
- Alternate Data Streams or "Doctor Jekyll and Mr. Hyde"
Move to NTFS (Part II) by Laic Aurelian
- All in Memory Execution under Linux by Anthony Desnos , Frédéric Guihéry,
Mickaël Salaün
- The Real Dangers of Wireless Networks by Stephen Argent
- How to Deploy Robustness Testing by Mikko Varpiola and Ari Takanen
- Protecting Data in a Postgres Database by Robert Bernier
- Global Thermonuclear War – Shall We Play a Game? by Matthew Jonkman
- Consumers Test - Choose the Right Router by Matthew Sabin and hakin9 team
- Interview with Nicolaas Vlok
- Self Exposure by Mike Chan and Bing Liu

Hakin9


New hakin9 forum!
hakin9 magazine has launched a new forum - the place for all hakin9 and IT
Security fans. We encourage you to log in and just discuss.

If you have any suggestions on how to improve its quality and content, feel
free to share your opinions and ideas with us!

Don't waste your time and start posting!

e-mail: monika.drygulska@hakin9.org
http://forum-en.hakin9.org/index.php

No Root for You - now available!
Leetupload.com and Hakin9 Magazine are proud to present No Root for You: A
Series of Tutorials, Rants and Raves, and Other Random Nuances Therein.

This is the network auditor's official bible to spoon-fed network auditing. The
purpose of this book is to take once unclear explanations to particular
network audits and place them in layman's terms so that the curious (from
novice to guru) may understand the information fully, and be able to apply it
without much hassle. This quick-reference guide not only contains
step-by-step, illustrated tutorials, but an explanation in regards to why
each exploitation, or what have you, works, and how to defend against such
attacks. Be prepared, one might also discover a few "rants and raves," as
well as other random nuances. Currently you may purchase a copy of this book
at the Wordclay bookstore, found here:


http://www.wordclay.com/BookStore/BookStoreBookDetails.aspx?bookid=27253


General information about the book itself is as follows: The cost of the book
is $22.99; it consists of 37 topics and is 424 pages in length

www.hakin9.org/en
en@hakin9.org
+1 917 338 36 31

"

(Read More... | 740 comments | Score: 0)


Hakin9 Newsletter
Posted by boss on Friday, 07 March 2008 @ 08:06:58 EST (8617 reads)
Topic Hakin9

Anonymous writes " ---------------------------------------------------------------------------
hakin9 Newsletter, 03-07-2008
http://www.hakin9.org/en/
http://www.buyitpress.com/en/

---------------------------------------------------------------------------
1. Download an article for free
2. New h9 logo
3. New issue of hakin9 is now on sale
4. March Madness – new h9 subscription offer

---------------------------------------------------------------------------
*Download an article for free*
---------------------------------------------------------------------------
Remote and Local File Inclusion Explained - an article by Gordon Johnson to download from hakin9 portal at no charge.

Visit our website and read something new!

http://hakin9.org/prt/view/pdf-articles.html


--------------------------------------------------------------------------
*New h9 logo!*
--------------------------------------------------------------------------
Our magazine has a new LOGO!
Do not miss it when looking for hakin9 at the newsstands!

www.hakin9.org/en


--------------------------------------------------------------------------
*New issue of hakin9 is now on sale*
--------------------------------------------------------------------------
Get the latest hakin9 edition - VoIP Abuse. Storming SIP Security.

You will read about:
  • Hacking SIP
  • Alternate Data Streams
  • Programming with Libpcap - Sniffing the Network from Your Own Application
  • Reverse Engineering
  • Postgres Database Security
  • Writting IPS Rules.
Don't miss the chance to learn something new.

Go to the nearest bookstore or subscribe.

http://hakin9.org/prt/view/about-the-mag/issue/691.html




--------------------------------------------------------------------------
*March Madness – new h9 subscription offer*
--------------------------------------------------------------------------
You have the one and only chance to get hakin9 Exclusive Mega Pack.

All archive issues and 2008 subscription are available this week for only $79.99!

Don't miss your chance and order now.

Offer is valid until 13/03/2008 only.


http://hakin9.org/prt/view/special-offers.html


In case of any questions send an e-mail quoting 'March Madness' to:
wojciech.kowalik@hakin9.org


http://hakin9.org/prt/view/special-offers.html


--------------------------------------------------------------------------
www.hakin9.org/en
en@hakin9.org
+1 917 338 36 31
"

(Read More... | 734 comments | Score: 0)


Our Sponsors

Login

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Big Story of Today

There isn't a Biggest Story for Today, yet.

Old Articles

Wi-Fi Security


You can syndicate our news using the file backend.php or ultramode.txt


All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2003-2008 by Clement Dupuis and Nathalie Lambert (Site Maintainers).

 


 

 


Page Generation: 1.16 Seconds