This year at RSA, I remember meeting with a vendor who dealt with database security by encrypting the database. I forget the name, but found a open source project - Acra, which I think is a promising product if designed & developed right. Read more about Acra: Database Protection With Encryption & Intrusion Detection!
Archives for March 2017
Pwnbox: A Docker Container For Reverse Engineering & Exploitation!
Since I blogged a bit about docker security tools, I thought of continuing the trend and introduce Pwnbox, is an open source docker container that has tools to aid you in reverse engineering and exploitation. It allows you to package up an container with all of the tools of trade you need in a capture-the-flag situation, or elsewhere too! Read more about Pwnbox: A Docker Container For Reverse Engineering & Exploitation!
Ostinato: The Network Traffic Generator and Analyzer!
I had covered Ostinato in our earlier blog, before it got blown away and was reminded of it when I was working on the Apache Struts S2-046 vulnerability. I had a .pcap file which I had to replay and this is where Ostinato came into picture. A bit off track, if you want to protect yourself from S2-045 & S2-046, and your application is on Apache, simply add the following to Read more about Ostinato: The Network Traffic Generator and Analyzer!
Wifiphisher: Perform Automated Customized Phishing Attacks Against Wi-Fi Clients!
A human is the weakest link in cyber security and tools like Wifiphisher cement the fact. This tool exploits this weak link by launching a social-engineering attack leading the user to a phishing page and then you can get the users password or install your stuff. Read more about Wifiphisher: Perform Automated Customized Phishing Attacks Against Wi-Fi Clients!
Dagda: The Docker Security Suite!
The Docker security god must surely be smiling and thinking he must have done something right to have tools like Dagda that helps in performing static analysis of known vulnerabilities on Docker containers. If you did not get my "Docker security guard" analogy, I won't blame you either. Google told me that Dagda is an important god of Irish mythology. Read more about Dagda: The Docker Security Suite!