Posts: (234)

On CVE-2014-1770 / ZDI-14-140 : Internet Explorer 8 "0day"

Hi all,

I have received a ton of questions regarding a recently published ZDI advisory, which provides some details about a bug I discovered and reported to Microsoft (via ZDI), affecting Internet Explorer 8.  I wanted to take Read more

Read More

Corelan Team reply to false allegation made by Kaspersky

Hi,

A few moments ago, I was informed about an article on www.securelist.com and the fact that Corelan Team was mentioned in that post.  Apparently a researcher at Kaspersky Labs found a piece of text ("You have been owned Read more

Read More

Metasploit Meterpreter and NAT

Professional pentesters typically use a host that is connected directly to the internet, has a public IP address, and is not hindered by any firewalls or NAT devices to perform their audit. Hacking "naked" is considered to be the Read more

Read More

A chain is only as strong as its weakest link - DNS Hijack Monitoring

It doesn't really matter how much time your developers have spent writing secure code and how many layers of security you have implemented to protect your website from being hacked and defaced.  Recent incidents have demonstrated that the bad Read more

Read More

Using DBI for solving Reverse Engineering 101 – Newbie Contest from eLearnSecurity

Introduction

Last weekend I had some time so I wanted to have a look at a reversing challenge which you can find here:

https://www.ethicalhacker.net/features/special-events/reverse-engineering-101-newbie-contest-webcast-elearnsecurity

Reverse Engineering 101 Contest Steps

  1. Get the exe to be hacked
  2. Break it open and Read more
Read More

Corelan Logo Contest - The submissions

Hi all,

 

As announced a couple of weeks ago, the Corelan Logo contest is now closed, which means we are no longer accepting new submissions.

3 people have submitted one or more designs:

Design 1

 

Design 2

Read more

Read More

Corelan Logo contest - Derbycon 2013

For the third year in a row, I'll be teaching the Corelan Exploit Dev Bootcamp at Derbycon.  If you were able to grab a ticket to the course, you can expect a true bootcamp-style, very hands-on course, spanning 2 Read more

Read More