Internet Storm Center
Sign In
Sign Up
SANS Network Security: Las Vegas Sept 4-9.
Handler on Duty:
Xavier Mertens
Threat Level:
green
Date
Author
Title
REPUTATION FILTERING INTRUSION PREVENTION PENETRATION TEST PENTEST
2010-02-22
Rob VandenBrink
New Risks in Penetration Testing
REPUTATION
2017-03-04/a>
Xavier Mertens
How your pictures may affect your website reputation
2015-06-02/a>
Alex Stanford
Guest Diary: Xavier Mertens - Playing with IP Reputation with Dshield & OSSEC
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
FILTERING
2023-03-31/a>
Guy Bruneau
Using Linux grep and Windows findstr to Manipulate Files
2019-09-19/a>
Xavier Mertens
Blocklisting or Whitelisting in the Right Way
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
INTRUSION
2016-08-29/a>
Russ McRee
Recommended Reading: Intrusion Detection Using Indicators of Compromise Based on Best Practices and Windows Event Logs
2013-12-16/a>
Tom Webb
The case of Minerd
2013-08-19/a>
Johannes Ullrich
Running Snort on ESXi using the Distributed Switch
2012-09-02/a>
Lorna Hutcheson
Demonstrating the value of your Intrusion Detection Program and Analysts
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
PREVENTION
2010-09-26/a>
Daniel Wesemann
Egosurfing, the corporate way
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
2009-04-24/a>
John Bambenek
Data Leak Prevention: Proactive Security Requirements of Breach Notification Laws
PENETRATION
2020-08-10/a>
Bojan Zdrnja
Scoping web application and web service penetration tests
2019-04-26/a>
Rob VandenBrink
Pillaging Passwords from Service Accounts
2016-09-04/a>
Russ McRee
Kali Linux 2016.2 Release: https://www.kali.org/news/kali-linux-20162-release/
2014-08-09/a>
Adrien de Beaupre
Complete application ownage via Multi-POST XSRF
2011-10-26/a>
Rick Wanner
Critical Control 17:Penetration Tests and Red Team Exercises
2010-08-23/a>
Manuel Humberto Santander Pelaez
Firefox plugins to perform penetration testing activities
2010-08-16/a>
Raul Siles
Blind Elephant: A New Web Application Fingerprinting Tool
2010-06-06/a>
Manuel Humberto Santander Pelaez
Nice OS X exploit tutorial
2010-04-13/a>
Adrien de Beaupre
Web App Testing Tools
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
2009-07-27/a>
Raul Siles
New Hacker Challenge: Prison Break - Breaking, Entering & Decoding
2009-04-21/a>
Bojan Zdrnja
Web application vulnerabilities
2008-09-20/a>
Rick Wanner
New (to me) nmap Features
TEST
2023-09-29/a>
Xavier Mertens
Are You Still Storing Passwords In Plain Text Files?
2020-08-10/a>
Bojan Zdrnja
Scoping web application and web service penetration tests
2020-06-05/a>
Johannes Ullrich
Cyber Security for Protests
2019-11-29/a>
Russ McRee
ISC Snapshot: Search with SauronEye
2019-10-22/a>
Bojan Zdrnja
Testing TLSv1.3 and supported ciphers
2019-07-23/a>
Bojan Zdrnja
Verifying SSL/TLS configuration (part 1)
2019-04-26/a>
Rob VandenBrink
Pillaging Passwords from Service Accounts
2018-12-16/a>
Guy Bruneau
Random Port Scan for Open RDP Backdoor
2018-07-02/a>
Guy Bruneau
Hello Peppa! - PHP Scans
2018-01-28/a>
Didier Stevens
Is this a pentest?
2017-09-06/a>
Adrien de Beaupre
Modern Web Application Penetration Testing , Hash Length Extension Attacks
2017-05-13/a>
Guy Bruneau
Has anyone Tested WannaCry Killswitch? - https://blog.didierstevens.com/2017/05/13/quickpost-wcry-killswitch-check-is-not-proxy-aware/
2017-05-05/a>
Xavier Mertens
HTTP Headers... the Achilles' heel of many applications
2016-11-02/a>
Rob VandenBrink
What Does a Pentest Look Like?
2016-09-28/a>
Xavier Mertens
SNMP Pwn3ge
2016-09-04/a>
Russ McRee
Kali Linux 2016.2 Release: https://www.kali.org/news/kali-linux-20162-release/
2016-01-20/a>
Xavier Mertens
/tmp, %TEMP%, ~/Desktop, T:\, ... A goldmine for pentesters!
2015-11-09/a>
John Bambenek
ICYMI: Widespread Unserialize Vulnerability in Java
2015-10-27/a>
Xavier Mertens
The "Yes, but..." syndrome
2014-08-12/a>
Adrien de Beaupre
Host discovery with nmap
2014-08-09/a>
Adrien de Beaupre
Complete application ownage via Multi-POST XSRF
2014-04-03/a>
Bojan Zdrnja
Watching the watchers
2013-08-21/a>
Rob VandenBrink
Fibre Channel Reconnaissance - Reloaded
2012-03-09/a>
Guy Bruneau
Nmap 5.61TEST5 released with 43 new scripts,improved OS & version detection, and more available for download - http://nmap.org/download.html
2011-10-26/a>
Rick Wanner
Critical Control 17:Penetration Tests and Red Team Exercises
2011-08-26/a>
Daniel Wesemann
User Agent 007
2011-01-24/a>
Rob VandenBrink
Where have all the COM Ports Gone? - How enumerating COM ports led to me finding a “misplaced” Microsoft tool
2010-11-19/a>
Jason Lam
Exchanging and sharing of assessment results
2010-08-23/a>
Manuel Humberto Santander Pelaez
Firefox plugins to perform penetration testing activities
2010-08-16/a>
Raul Siles
Blind Elephant: A New Web Application Fingerprinting Tool
2010-06-06/a>
Manuel Humberto Santander Pelaez
Nice OS X exploit tutorial
2010-05-22/a>
Rick Wanner
SANS 2010 Digital Forensics Summit - APT Based Forensic Challenge
2010-04-13/a>
Adrien de Beaupre
Web App Testing Tools
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
2009-11-25/a>
Jim Clausing
Updates to my GREM Gold scripts and a new script
2009-07-27/a>
Raul Siles
New Hacker Challenge: Prison Break - Breaking, Entering & Decoding
2009-05-31/a>
Tony Carothers
L0phtcrack is Back!
2009-04-21/a>
Bojan Zdrnja
Web application vulnerabilities
2008-11-17/a>
Jim Clausing
A new cheat sheet and a contest
2008-09-20/a>
Rick Wanner
New (to me) nmap Features
PENTEST
2019-11-29/a>
Russ McRee
ISC Snapshot: Search with SauronEye
2018-01-28/a>
Didier Stevens
Is this a pentest?
2017-09-06/a>
Adrien de Beaupre
Modern Web Application Penetration Testing , Hash Length Extension Attacks
2017-05-05/a>
Xavier Mertens
HTTP Headers... the Achilles' heel of many applications
2016-11-02/a>
Rob VandenBrink
What Does a Pentest Look Like?
2016-09-28/a>
Xavier Mertens
SNMP Pwn3ge
2016-01-20/a>
Xavier Mertens
/tmp, %TEMP%, ~/Desktop, T:\, ... A goldmine for pentesters!
2015-11-09/a>
John Bambenek
ICYMI: Widespread Unserialize Vulnerability in Java
2015-10-27/a>
Xavier Mertens
The "Yes, but..." syndrome
2014-08-12/a>
Adrien de Beaupre
Host discovery with nmap
2013-08-21/a>
Rob VandenBrink
Fibre Channel Reconnaissance - Reloaded
2011-08-26/a>
Daniel Wesemann
User Agent 007
2010-11-19/a>
Jason Lam
Exchanging and sharing of assessment results
2010-06-06/a>
Manuel Humberto Santander Pelaez
Nice OS X exploit tutorial
2010-02-22/a>
Rob VandenBrink
New Risks in Penetration Testing
2009-05-31/a>
Tony Carothers
L0phtcrack is Back!
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Contact Us
Contact Us
About Us
Handlers
About Us
Slack Channel
Mastodon
Bluesky
X
This site is powered by
your submissions
, so tell us
what you see happening