(function(i,s,o,g,r,a,m){ i['GoogleAnalyticsObject']=r; i[r]=i[r]||function(){(i[r].q=i[r].q||[]).push(arguments)}, i[r].l=1*new Date(); a=s.createElement(o),m=s.getElementsByTagName(o)[0]; a.async=1; a.data-privacy-src=g; m.parentNode.insertBefore(a,m) })(window,document,'script','//www.google-analytics.com/analytics.js','ga'); ga('create', 'UA-132428928-1', 'auto'); ga('send', 'pageview');

Hacking

Why going after wp-config is a quick way to get banned

2022-06-15T00:59:14-04:00

The first is actually more common place. The second assumes the admin that maintains WordPress leaves a backup or older version of the file readable by any visitor that happens to “guess” a filename. In the past, CompSec Direct has been successful employing both techniques for customers during security audits, however the second leaves a 404 [...]

Why going after wp-config is a quick way to get banned2022-06-15T00:59:14-04:00

Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks – ArsTechnica

2022-06-15T01:26:03-04:00

Excellent report by Kaspersky that unmasks a breach inside their corporate infrastructure. Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks

Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks – ArsTechnica2022-06-15T01:26:03-04:00

Bsides PR 2015 – Fun with Tor : How anonymity services complicate actor attribution CompSec Direct

2022-06-13T18:35:49-04:00

Hello from Puerto Rico. Here are our slides from Jose Fernandez’s talk on Tor and attribution. We are very exited to have participated in BSides PR 2015, and look forward to speaking again in the future. By the time we got to the beach, the Internet is hopefully in a slightly better state than we left [...]

Bsides PR 2015 – Fun with Tor : How anonymity services complicate actor attribution CompSec Direct2022-06-13T18:35:49-04:00

Cybergeddon: Why the Internet could be the next “failed state” -ArsTechnica

2022-06-15T01:25:09-04:00

Excellent article by Sean Gallagher from ArsTechnica. It truly captures the essence of how our world is likely headed into an unfortunate collision with technology. http://arstechnica.com/information-technology/2015/02/fear-in-the-digital-city-why-the-internet-has-never-been-more-dangerous/1/

Cybergeddon: Why the Internet could be the next “failed state” -ArsTechnica2022-06-15T01:25:09-04:00

How to exploit Domain Controllers with MS14-068 / From Zero 2 Hero

2022-06-13T18:39:44-04:00

Hello! This is jfer from compsec direct. I would like to show you how to leverage the new Kerberos exploit against Windows domain controllers called ms14-068. This vulnerability allows a user with domain credentials to forge a Kerberos ticket and receive domain admin privileges via the forged ticket. I want to thank Sylvain Monné aka Bidord [...]

How to exploit Domain Controllers with MS14-068 / From Zero 2 Hero2022-06-13T18:39:44-04:00

IT threat evolution Q2 2014 – Kaspersky

2022-06-15T01:06:41-04:00

Please take time to read this insightful publication by David Emm, Roman Unuchek, Victor Chebyshev, Maria Garnaeva and Denis Makrushin from Kaspersky Labs. The publication offers unparalleled insight and examples of current evolving threats through the info sec lens. Click to Download

IT threat evolution Q2 2014 – Kaspersky2022-06-15T01:06:41-04:00

Ransomware going strong, despite takedown of Gameover Zeus – ArsTechnica

2022-06-15T01:08:52-04:00

Despite numerous public takedowns, cyber criminals will continue to extort users by leveraging their own data as ransom.Click Here for Original Post

Ransomware going strong, despite takedown of Gameover Zeus – ArsTechnica2022-06-15T01:08:52-04:00
Go to Top