Microsoft Patch Tuesday, November 2014

Compared to previous Microsoft Patch Tuesday's, November's is a pretty big one clocking in at 14 ...

Read More

SpiderLabs Radio for the week of November 3, 2014

In this episode:

Read More

Microsoft Advance Notification for November 2014

This coming Tuesday, November 11, Microsoft will publish their next security update. With sixteen ...

Read More

Smuggler - An interactive 802.11 wireless shell without the need for authentication or association

I've always been fascinated by wireless communications. The ability to launch seemingly invisible ...

Read More

SpiderLabs Radio for the week of October 27, 2014

In this episode:

Read More

Setting HoneyTraps with ModSecurity: Adding Fake Cookies

This blog post continues with the topic of setting "HoneyTraps" within your web applications to ...

Read More

Bitcoin Transaction Malleability Theory in Practice – Ruxcon Australia 2014

Two weeks ago we gave a talk at the Ruxcon 10 conference in Melbourne, Australia titled "Bitcoin ...

Read More

Reflected File Download - A New Web Attack Vector

PLEASE NOTE: As promised, I've published a full white paper that is now available for download: ...

Read More

Hacking a Reporter: UK Edition

Over the summer, a U.K. journalist asked the Trustwave SpiderLabs team to target her with an online ...

Read More

SpiderLabs Radio: October 22, 2014

In this episode:

Read More

Powerpoint Vulnerability (CVE-2014-4114) used in Malicious Spam

Following last week's announcement of a zero-day vulnerability for PowerPoint (CVE-2014-4114), we ...

Read More

Spam Campaign Taking Advantage of Ebola Scare May Lead To Malware Infections

Cybercriminals have inevitably taken advantage of the publicization of the Ebola virus in the news ...

Read More

SpiderLabs Radio: October 16, 2014

In this episode we'll be talking about the zero days patched by Microsoft's Patch Tuesday as well ...

Read More

Jailbreak Detection Methods

This post concludes our three-part series about mobile security. Today's post will outline some ...

Read More

Microsoft Patch Tuesday, October 2014

Today is the October Microsoft Patch Tuesday, and it addresses eight separate bulletins. Three ...

Read More

Exploring and Exploiting iOS Web Browsers

Today we begin a three-post series about mobile security. We start with a discussion of ...

Read More

Executing Apps on Jailbroken Devices

This post is part two of a three-part series about mobile security. Today's post will discuss the ...

Read More

SpiderLabs Radio: October 9, 2014

In this episode:

Read More

Microsoft Advance Notification for October 2014

On Tuesday, October 14, Microsoft will publish their newest security update. This patch Tuesday ...

Read More

SpiderLabs Radio: October 2, 2014

In this episode:

Read More

Shellshock a Week Later: What We Have Seen

Trustwave, like most other information security firms, has been busy investigating the ShellShock ...

Read More

SpiderLabs Radio: September 25, 2014

The SpiderLabs Radio podcast is on hiatus this week as we absorb all of the wonderful content from ...

Read More

Cracking IKE Mission:Improbable (Part3)

Introduction

Read More

Identify Crimeware Strains with Edit Distance

When trying to identify crimeware/malware, it's a good idea to design a multi-part system that ...

Read More

SpiderLabs Radio: September 18, 2014

In this episode:

Read More

CVE-2014-6283: Privilege Escalation Vulnerability and Potential Remote Code Execution in SAP Adaptive Server Enterprise

On May 12, 2014, SAP published updates to Adaptive Server Enterprise versions 15.0. 15.5 and 15.7 ...

Read More

Leveraging LFI To Get Full Compromise On WordPress Sites

In this post I will discuss how a serious but mostly ignored vulnerability can lead to a full ...

Read More

[Honeypot Alert] New Bot Malware (BoSSaBoTv2) Attacking Web Servers Discovered

Our web honeypots picked up some interesting attack traffic. The initial web application attack ...

Read More