Open Challenge: Ruby YAML.load(YOUR_STRING_HERE) == RCE?
For some, the challenge may already be quite clear by the title of this post, but I'm going to add ...
Read MoreSign up to receive the latest security news and trends straight to your inbox from Trustwave.
For some, the challenge may already be quite clear by the title of this post, but I'm going to add ...
Read MoreThe latest update to the TrustKeeper scan engine that powers our Trustwave Vulnerability Management ...
Read MoreBetween April and May of 2013, I presented at SOURCE Boston and THOTCON and blogged about some of ...
Read MoreAs someone who's responsible for a number of Ruby projects, both open-source and commercially ...
Read MoreWhen trying to identify crimeware/malware, it's a good idea to design a multi-part system that ...
Read MoreFor those of you not familiar with monkey patching, it's a mechanism to "extend or modify the ...
Read MoreA few months ago I was trying to PoC a known cross-site scripting vulnerability in the Cisco ASA ...
Read MoreA little over a month ago, I published a Metasploit auxiliary module for brute-forcing Cisco ASDM ...
Read MoreOver the past couples weeks, I've been working on enhancingthe operating system detection logic in ...
Read MoreLast week, I was making some performance enhancements to theVNC protocol implementations in the ...
Read MoreLast Friday I was trying out some new code that one of my colleagues wrote to help automate some of ...
Read MoreOver the past couple weeks, I've been spending a lot of time hacking on various embedded devices to ...
Read MoreThis past weekend I ended up coming into the SpiderLabs office and "nerded out" with my good friend ...
Read MoreHave you ever dumped LM and NTLM password hashes from a Windows system using the registry and never ...
Read MoreAbout two weeks ago, a Brazilian security researcher by the name of Gabriel Menezes Nunes released ...
Read MoreLate last week, a vulnerability in PHP-CGI was disclosed, which allows all sorts of bad for folks ...
Read MoreBack in January we released a security advisory for WordPress, which included four vulnerabilities ...
Read MoreJust this week, we were asked to help out with some "TCP weirdness" that was identified out on a ...
Read More