Showing posts with label IT Security. Show all posts
Showing posts with label IT Security. Show all posts

Saturday, February 26, 2011

Hackers meet at Nullcon 2, GOA


Heard of Black Hat, White Hat and also Gray Hat but what does this Brown Hat??

Does it mean the chief of all the hats? or something else??

Had a great time at GOA and the second Nullcon conference in Feb 2011.

2.4 Million email account passwords leaked

Have you ever entered your email account password on some sites like social networking, contact management, birthdates management or may be email marketing? Well the site you used could be legitimate, but how good is their security?? Are they collecting your password or redirecting to a login page on the email server?

Hackers have got 2.4 million email account passwords of gmail, hotmail, yahoo, live etc. The no. is expected to go up to 24 mil soon and as this is not likely to be the result of compromising all the providers at a go, hence it seems to be data from 3rd party sites in possession of the password. If you like to see if you are one of the victims, you can check your email id here - http://dhamaka.nullcon.net

Monday, November 15, 2010

Launch of Packet Master


K-Secure successfully conducted its first batch of the latest training program 'Packet Master' that teaches how to analyze network packets and craft custom packets for security testing.

Hyderabad - 11&12 Dec 2010
Mumbai - 18&19 Dec 2010

Monday, October 25, 2010

Learn how to analyze and craft packets

The skill of analyzing packets is the most essential skill required if you are a pentester / ethical hacker, a network or security administrator, intrusion analyst, forensic analyst, application security tester, researcher of vulnerabilities, or you deploy or audit firewalls and IDS, or you write custom IDS signatures. If you already acquire the skill to analyze packets, learning Scapy would just do wonders in doing your job much more efficiently and making your organizations more secure.


K-Secure's Packet Master training program would be a great help if you:

  • Want to audit or test your firewall rules
  • Do pentest on networks or applications
  • Like to test if your IDS signature / rule works
  • Wondered if your pentesting tools like nmap, arpspoof, hping etc. can give you more control and information

Tuesday, June 1, 2010

Web Attackers will have a tough time now!

The attackers have surely moved their focus on web applications but this team is now fully prepared to detect and analyze any intrustion happening through their web applications. They've acquired these skills by going through a specialized training from K-Secure.

Monday, April 26, 2010

Security Professionals' Group

We're glad to have formed a group of professionals working in the area of information security. In our first meeting yesterday, which was conducted at K-Secure's office in Mumbai, we discussed on the Vulnerability Assessment services, where the members shared their experiences talking about what vulnerabilities are commonly found and the challenges they face in closing them. There was also a demonstration of tools which made it more interesting.

The meeting was supposed to be for a 1 hour duration but there was so much excitement that we wanted to go on and on but finally decided to wind up after about 10 hours.

We have lots and lots of plans for the future of the group, so if you are interested in joining this group, please email to spg@ksecure.net.

Wednesday, April 21, 2010

OWASP Top 10 - 2010 released

Want to get started with application security? OWASP (The Open Web Application Security Project) has released the list of ten most critical web application security risks.

Top 10
------
A1: Injection
A2: Cross-Site Scripting (XSS)
A3: Broken Authentication and Session Management
A4: Insecure Direct Object References
A5: Cross-Site Request Forgery (CSRF)
A6: Security Misconfiguration (New)
A7: Insecure Cryptographic Storage
A8: Failure to Restrict URL Access
A9: Insufficient Transport Layer Protection
A10: Unvalidated Redirects and Forwards (New)

More on Top 10 is given here - OWASP Top 10