Category · Tutorials

Your Guide to Evaluating Security CBT Programs (Part 1)

posted on May 3, 2013 by Oliver Ng Comments:0

Note: At the end of this series, I’ll provide a free tool that you can use to make your own evaluations easier, so keep an eye out for it! With the variety of Computer Based Security Training (CBTs) out there, it can be tough to make a decision around what to consider when choosing the…

Mobile Application For Your Hacking Pleasures

posted on Apr 3, 2013 by sahba Comments:0

A short while back we released ExploitMe Mobile (EMM), our free, open source project demonstrating common Mobile Security vulnerabilities  in the iOS and Android platforms. ExploitMe Mobile is a training platform built based on the common Mobile Security and Application Security pitfalls. The objectives of the ExploitMe Mobile training platform are: Capture the common security…

I know youd love CPEs and free OWASP training

posted on May 25, 2012 by Oliver Ng Comments:0

Author: +Oliver Ng I’m happy to announce a partnership with ISC2 to bring you our OWASP course complimentary  for CISSP members.  Access is limited to the next 30 days, so get in on it fast and collect your 2 CPEs for watching these videos. These videos also outline our great new training format for CBTs that…

New Mobile Security Course and ExploitMe Mobile

posted on Oct 15, 2011 by Oliver Ng Comments:0

At Security Compass, we have been working hard to expand our training offerings. We’re most excited about our new Mobile Hacking and Security course. If your organization is working with mobile applications this course is a fantastic primer on how mobile apps can be hacked, and how your teams can defend against these software defects. We’ll…

Viruses and Malware

posted on Aug 3, 2011 by Oliver Ng Comments:0

Our video series continues with the second video in our Safe Online Banking series about Viruses and Malware. You know those annoying viruses that just won’t leave your computer alone? Criminals have realized there is money to be made by placing viruses and malware on your computer. The Bad guys make money by tracking you while…

Weaponizing the Android Emulator (plus a new tool)

posted on Jul 22, 2011 by seccom Comments:0

Today, we’re going to look at a scenario where the Android Emulator can be repurposed as an exploitation tool. Specifically, we will look at attacks that involve cloning an application and user data from a stolen Android phone onto a computer running the Android emulator. An attacker that does this will be able to use…

Bypassing Android’s Password Screen

posted on Jul 6, 2011 by seccom Comments:0

This video demonstrates how to bypass the password screen on an android. If you lose your phone, someone who finds it can use this attack to get around the password you set. This attack requires a phone with an unlocked bootloader. Some phones come with unlocked bootloaders, and on others users do this as part…

XSLT Command Execution Exploit

posted on Sep 18, 2009 by Subu Ramanathan Comments:0

This article is based on the Command Injection in XML Signatures and Encryption whitepaper authored by Bradley W. Hill from Information Security Partners. XSLT is a simple language designed to facilitate cross platform content generation by selecting and merging datasets presented in an XML document. The vulnerability described in the whitepaper still exists in today’s…

The True Danger of XSS and CSRF

posted on May 15, 2009 by Rohit Sethi Comments:0

In our one-day training classes and conference talks we make judicious use of videos to demonstrate concepts. One of the most popular videos illustrates the true danger of Cross-Site Scripting (XSS) combined with Cross-Site Request Forgery (CSRF). We constructed a fake bank site and demonstrated that a single XSS vulnerability and money transfer functionality in the bank site could…