p0wnpr0xy.py is a simply python script that acts as a http/https proxy and launches commands such as sqlmap against targets that are in-scope. It relies on httpservers.py from gnucitizen to do the heavy lifting. You can download his module from here and save it to the same directory as p0wnpr0xy. When you launch p0wnpr0xy you […]
I have a couple of web application penetration testing script for you. I will start out with a really simple one. First is a script that will convert the parameters given on the URL as a HTTP GET into a HTTP POST. This makes it easier to demonstrate XSS vulnerabilities in a POST to your […]
Last year on the show, Marcus J. Carey presented a tech segment about using memory analysis in penetration tests. Memory acquisition came into its own for incident responders a few years back. Even before tools like Volatility, Memoryze or HBGary’s Responder were available, many incident responders, including me, used the strings command to perform rudimentary […]
At the podcaster meeting up at Shmoocon 2010 an interesting conversation ensued about the lack of business acumen among penetration testers. “Penetration testers don’t understand business and don’t know how to talk to our executives” was the charge. (IMHO it is my job as the CISO’s job to translate haxor geek speak into boardroom geek […]
Yes yours truly (Larry, that is) Will be teaching the 6 day SANS Wireless Ethical Hacking, Penetration Testing and Defenses (SANS 617) in Regina, Saskatchewan on March 23 – 28, 2009. As this is the first time Wireless Ethical Hacking, Penetration Testing and Defenses is being offered in Saskatchewan it is anticipated to fill quickly. […]
In the spirit of epic sequels, we are pleased to announce the follow-on Webcast to the highly successful Zen and The Art Of An Internal Penetration Testing Program. This webcast is the second part of a series presented by Paul Asadoorian in collaboration with Core Security Technologies. The presentation will be full of tips and […]
This webcast is Part I of a two part series I am doing in collaboration with Core Security Technologies. The presentation is full of tips, tricks, process, and practical knowledge about performing penetration testing within your own organization. Whether you are a third-party doing penetration tests or want to penetration test your internal network, this […]
This is going to be another neat webcast in collaboration with SANS and Core Security. Below is the description and sign-up information: “When beginning a security process at a consortium of non-profits, senior network security engineer, Paul Asadoorian of Security Weekly began looking for a penetration testing tool that did network, web application and social […]
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.