Sub

What AV software do you use?

----------

Discuss these topics on the Forum.












HTML Articles
Why is there no anti-virus?
Konst will present his ideas on Microsoft activity - why they don't add an anti-virus program to their software.

More ....


Hacking beyond the Net
Many in the IT community have never forgiven the media for twisting the original meaning of hacker. Despair not, though - the constructivist spirit advocated by the likes of Eric S. Raymond and Richard Stallman is not dead.

More ....


Column - The future's so bright I gotta wear shades
Freedom of piracy is one of the greatest freedoms the humanity gained in the most important virtual battle of all. Read more in Konst's column.

More ....


Problems with HTTP Authentication
Authentication is a technique of identification based on knowledge. HTTP provides natural functionality of HTTP authentication. In this article, Emilio will concentrate on basic authentication, which is more widespread among clients and Web servers but also less secure.

More ....


Tools - Acunetix web vulnerability scanner
Carlos shows you how to scan directory structure and perform automatically an entire set of typical attacks that gets profit of configuration or programming errors using Acunetix scanner.

More ....


Efficient and easy to use web services: XFire in practice
Web services have proved the long-awaited solution for communication between distributed applications running on a variety of platforms and created using a variety of programming languages. This article explains how to integrate different applications.

More ....


Beyond keyword search for data sources on the World Wide Web
One of the most important features of the World Wide Web is its ability to empower users with lots of information. However, much of this information is still unorganized and inaccessible beyond a simple keyword search. In this article the authors focus on annotating data sources that are unstructured and ungrammatical.

More ....


Spyware infection methods
Such programs like spyware are usually bundled as a hidden component or downloaded from the Internet unwillingly. They install and run without user knowledge. Christiaan presents what methods such programs use to infect Windows systems and how can one protect oneself against them.

More ....


Sony, rootkit and the fifth power
We present the Rootkits and spyware history putting on audio CDs by Sony company. We describe the scandal.

More ....


Voice over IP security - SIP and RTP protocols
We provide a detailed overview of protocols used in Voice over IP (VoIP) transmissions, particularly of the SIP protocol. Then we take a look at seven most common, most effective and best-described methods of attacking VoIP, and how these methods can be applied in practice.

More ....


Robot Wars - How Botnets Work
We discuss the concept of bots and botnets, then explain how they operate and how victim computers are infected. A practical example of creating a botnet using one of the available tools is presented. We also teach how to protect a computer from being exploited by a botnet.

More ....


XSS in practice
Internet has become more and more important. Millions of dollars are invested in websites. Big businesses don't work with simple HTML sites anymore; everything has to be dynamic these days. But by giving people the opportunity to insert data on a website, the chance of getting vulnerable gets bigger. Roderick will present XSS attacks in practice.

More ....


Advanced SQL Injection Techniques
We demonstrate how to execute advanced attacks against syntax and logic of the SQL language. Several interesting tricks involving SQL injection are presented. Finally, we discuss basic methods of protecting applications against SQL injection attacks.

More ....


Code injection using Windows GUI messages
Few could suspect that an innocuous GUI feature such as Windows messages could pose a danger to system security. We show why this seemingly innocent mechanism can be used to inject malicious code into another application and escalate an intruder's privileges.

More ....


Automating the exploitation process on Linux x86
We describe some automation buffer overflow bugs identification methods and compare some techniques. We present a tool which could identify them and produce exploit code would definitely ease the burden.

More ....


Penetration testing in practice
Penetrationn testing often takes place in situation where the management doesn't fully trust the IT department. It is sometimes ordered by the IT department itself to show its excellent work. However, this is not the case covered by this case study. Leran more about penetration test from Miroslav's article.

More ....


Analysis of Network Traffic
If you administer a network of any kind you can be certain that sooner or later it will become a target of an attack. However, you are capable of eliminating, or at least significantly reducing any chances of its success. Bartosz will show you how to analyse the network traffic.

More ....


Building an IPS using Snort
Computer systems are usually protected by firewalls, with any attacks that do get through being monitored by intrusion detection systems. However, nowadays it is not enough to detect an intruder - what use is detection if we cannot prevent the attack? Intrusion prevention systems (IPS's) provide the answer, and in this article we will go through building an IPS and maintaining it.

More ....


Security tool - SwitchSniffer
We present how simple is SwitchSniffer for monitoring local area networks, and describe more its features like basic administration and abuse detection.

More ....


Writing advanced Linux backdoors – packet sniffing
People create new defences for backdoors and intruders are forced to innovate new techniques to keep pace with the rapidly progressing security industry e.g. packet sniffing backdoors. Brandon describes how they work by writing our own proof-of-concept tool.

More ....


Detection of sniffing in switched networks
Sniffing in switched networks is typically conducted using one of two methods: MAC flooding or ARP spoofing. However, unlike sniffing in traditional, hub-based networks, both these methods are active and so can be detected – though sometimes this is not easy.

More ....