[Honeypot Alert] Inside the Attacker's Toolbox: Botnet Credit Card Validation Scripts
In our previous blog post "Inside the Attacker's Toolbox: Botnet Web Attack Scripts" we analyzed ...
Read MoreIn our previous blog post "Inside the Attacker's Toolbox: Botnet Web Attack Scripts" we analyzed ...
Read MoreWhen penetration-testing you get to see lots of seemingly unbelievable security failures, but ...
Read MoreThere's a lot of buzz going around in the security field about a big piece of malware, code named ...
Read MoreEven though it's sometimes easy to forget that there are exploit kits other than BlackHole, other ...
Read MoreHaving investigated cardholder data security breaches for a few years now, I have noticed changes ...
Read MoreHello. I'm Tom Neaves. I recently joined SpiderLabs as a Senior Security Consultant based out of ...
Read MoreWe are evolving how the penetration testing industry reports vulnerabilities. Traditional PDF ...
Read MoreThis is the second blog in this series of blogs. The previous blog provided a general overview of ...
Read MoreHave you ever wondered what script/code/tool was behind the automated web attacks that you see in ...
Read MoreUntil tonight, I'd never gotten a chance to try an xml external entity (XXE) attack. Earlier, I was ...
Read MoreThis is the fourth part in a series of blogs. The prior blogs describe the technical details of the ...
Read MoreIn the next series of blogs we will describe in detail an attack from one of the most sophisticated ...
Read MoreBananaStand learned from last time (to see last time, go here ). Systems were patched, ACL's were ...
Read MoreAbout two weeks ago, a Brazilian security researcher by the name of Gabriel Menezes Nunes released ...
Read MoreThis may sound a bit odd but "nosteve" who usually gives his take on the patch Tuesday release is ...
Read MoreThis year's instantiation of the THOTCON hacking conference issued a unique challenge:
Read MoreThe SpiderLabs team at Trustwave published a new advisory yesterday, which details multiple ...
Read MoreLate last week, a vulnerability in PHP-CGI was disclosed, which allows all sorts of bad for folks ...
Read MoreUPDATE - we have received more exploit attempt details from web hosting provider DreamHost. Thanks ...
Read MoreDuring our research we have recently encountered a new private exploit kit. The developers behind ...
Read MoreBefore I jump into this blog post, I'd like to point out some interesting developments with the ...
Read MoreThere have been a number of mass SQL Injection campaigns targeting ASP/ASP.Net/MS-SQL sites over ...
Read MoreIt was a hectic week in London. In case you hadn't heard its was InfoSec Europe week, but we were ...
Read MoreI recently got wind of an interesting little sample that I believe originated as part of a ...
Read MoreWe Won! :-) Thanks to all the hard work of the Trustwave's Engineering teams, IT, SpiderLabs, and ...
Read MoreBack in January we released a security advisory for WordPress, which included four vulnerabilities ...
Read More