The Hack in the Box (#HITB2013AMS) security conference in Amsterdam has a very interesting lineup of talks [pdf]. One that jumped out was the Aircraft Hacking: Practical Aero Series presented by Hugo Teso, a security consultant at n.runs in Germany. . According to the abstract, The link for this article located at Computer World is no longer available. . An in-depth exploration of aviation cybersecurity showcased during the HITB2013AMS summit in Amsterdam by security expert Hugo Teso.. Aircraft Hacking, Android Exploit, Cyber Threats. . LinuxSecurity.com Team
Metasploit provides useful information to people who perform penetration testing, IDS signature development, and exploit research. This project was created to provide information on exploit techniques and to create a useful resource for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only. Metasploit is an open source project managed by Rapid7. . Version 3.3.3 of the Metasploit Framework has been released, featuring exploit safety rankings, a smaller EXE template, the addition of the InitialAutoRunScript option for Meterpreter, and the ability to run a script or command on all open sessions (sessions -c/-s). The complete release notes are online and version 3.3.3 can obtained from the downloads page. . Metasploit Framework 4.1.0 launched, featuring enhanced risk assessments, optimized EXE architecture, and advanced Meterpreter capabilities.. Metasploit Framework, Penetration Testing Tools, Exploit Safety. . Anthony Pell
Damn Vulnerable Linux (DVL) is everything a good Linux distribution isn't. Its developers have spent hours stuffing it with broken, ill-configured, outdated, and exploitable software that makes it vulnerable to attacks. DVL isn't built to run on your desktop -- it's a learning tool for security students. . DVL is a live CD available as a 150MB ISO. It's based on the popular mini-Linux distribution Damn Small Linux (DSL), not only for its minimal size, but also for the fact that DSL uses a 2.4 kernel, which makes it easier to offer vulnerable elements that might not work under the 2.6 kernel. It contains older, easily breakable versions of Apache, MySQL, PHP, and FTP and SSH daemons, as well as several tools available to help you compile, debug, and break applications running on these services, including GCC, GDB, NASM, strace, ELF Shell, DDD, LDasm, LIDa, and more. DVL was initiated by Thorsten Schneider of the International Institute for Training, Assessment, and Certification (IITAC) and Secure Software Engineering (S The link for this article located at Linux.com is no longer available. . Flavor of Risky Linux is an exceptional educational resource loaded with legacy applications meant for cybersecurity evaluation and practice.. Damn Vulnerable Linux, Security Training, Exploit Testing, Vulnerable Software. . LinuxSecurity.com Team
Less rigor in Web programming, an increasing variety of software, and restrictions on Web security testing have combined to make flaws in Web software the most reported security issues this year to date, according to the latest data from the Common Vulnerabilities and Exposures (CVE) project. A draft report on the latest numbers from the vulnerability database found that 4,375 security issues had so far been cataloged in the first nine months of 2006, just shy of the 4,538 issues documented last year. . The data shows that Web flaws have continued their meteoric rise since 2005, capturing the top-three spots on the list of most common vulnerabilities. Buffer overflows, a perennial favorite, fell to the No. 4 slot. "The takeaway is that researchers are paying a lot more attention to Web vulnerabilities, and if companies don't want to get caught up in that, then they need to pay attention to those flaws," said Steven Christey, the security researcher that authored the draft report and the CVE Editor for The MITRE Corp., a nonprofit government contractor. The jump in Web-based vulnerabilities is fueled by the simplicity of exploiting many of the most common Web vulnerabilities, the enormous number of Web applications freely available, and the difficulty in eradicating cross-site scripting flaws. The link for this article located at is no longer available. . In 2006, vulnerabilities in web applications escalated significantly due to more accessible exploits and an increase in software diversity, raising substantial security alarms.. Web Security, Software Flaws, Exploit Techniques. . Brittany Day
Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. . . .. Buffer overflow problems always have been associated with security vulnerabilities. In the past, lots of security breaches have occurred due to buffer overflow. This article attempts to explain what buffer overflow is, how it can be exploited and what countermeasures can be taken to avoid it. Knowledge of C or any other high level language is essential to this discussion. Basic knowledge of process memory layout is useful, but not necessary. Also, all the discussions are based on Linux running on x86 platform. The basic concepts of buffer overflow, however, are the same no matter what platform and operating system is used. The link for this article located at Linux Journal is no longer available. . Buffer overflow attacks are common security vulnerabilities that can lead to crashes, unauthorized access, or code execution by overwriting memory locations. Buffer Overflow, Attack Methods, System Security, Exploit Techniques. . LinuxSecurity.com Team
These days, it doesn't take a computer expert to become a hacker. There are over 30,000 hacking-oriented sites on the Internet, offering easy to use click-and-hack programs and scripts for anyone to download. These easily accessible hacking tools have opened the door for a multitude of new exploits.. . .. These days, it doesn't take a computer expert to become a hacker. There are over 30,000 hacking-oriented sites on the Internet, offering easy to use click-and-hack programs and scripts for anyone to download. These easily accessible hacking tools have opened the door for a multitude of new exploits. The first big-name hackers include Steve Wozniak, Bill Gates and Linus Torvalds, all now highly recognizable names behind many of the computer technologies used today. These early hackers had a love of technology and a compelling need to know how it all worked, and their goal was to push programs beyond what they were designed to do. Back then, the word "hacker" didn't have the negative connotation it has today. The original hacker ethic, rooted out of simple curiosity and a need to be challenged, appears to be dead. The link for this article located at Symantec is no longer available. . These days, it doesn't take a computer expert to become a hacker. There are over 30,000 hacking-orie. these, doesn't, computer, expert, become, hacker, there, hacking-orie. . LinuxSecurity.com Team
The latest version of phrack has been released. This issue covers Advances in kernel hacking, RPC without borders, Developing StrongARM/Linux shellcode, The Security of Vita Vuova's Inferno OS, Phrack World News, and more.. . .. The latest version of phrack has been released. This issue covers Advances in kernel hacking, RPC without borders, Developing StrongARM/Linux shellcode, The Security of Vita Vuova's Inferno OS, Phrack World News, and more. |=[ Table of Contents ]=-------------------------------------------------=| 0x01 Introduction Phrack Staff 0x08 kb 0x02 Loopback Phrack Staff 0x0b kb 0x03 Signalnoise Phrack Staff 0x18 kb 0x04 Advanced return-into-lib(c) exploits (PaX case study) nergal 0x48 kb 0x05 Runtime binary encryption grugq & scut 0x4b kb 0x06 Advances in kernel hacking palmers 0x1d kb 0x07 Linux on-the-fly kernel patching without LKM sd & devik 0x95 kb 0x08 Linux x86 kernel function hooking emulation mayhem 0x1a kb 0x09 RPC without borders stealth 0x10 kb 0x0a Developing StrongARM/Linux shellcode funkysh 0x11 kb 0x0b HP-UX (PA-RISC 1.1) Overflows zhodiac 0x16 kb 0x0c The Security of Vita Vuova's Inferno OS dalai 0x11 kb 0x0d Phrack World News Phrack Staff 0x0c kb 0x0e Phrack magazine extraction utility Phrack Staff 0x15 kb |=-----------------------------------------------------------------------=| The link for this article located at phrack staff is no longer available. . The newest edition of Phrack showcases advancements in system programming, remote procedure calls, exploitation techniques, and additional topics, highlighting significant breakthroughs.. Kernel Hacking, Shellcode Development, Phrack Issue. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.