• Uncategorized

    Concurrent Joomla Bruteforcing

    by  • August 6, 2013 • Uncategorized

    I recently saw a tweet from Andre DiMino about wanting to see more hype around CMS hacking instead of letting it fall by the wayside. Given some of the more recent events with Operation Ababil, I kind of agree with him. This software is riddled with bugs and users often neglect updating their platforms...

    Read more →

    FIRST Slides and Incubations Introduction

    by  • July 15, 2013 • Uncategorized

    Last month I was privileged enough to speak at the 25th annual FIRST conference hosted in Bangkok, Thailand and wanted to explain my slides a bit. I am not sure if FIRST will put the videos of the talks on the Internet, but until they do, I think it’s valuable for those who weren’t...

    Read more →

    PRISM Lure in Use by NetTraveler Attackers

    by  • June 18, 2013 • Uncategorized

    In between FIRST conference and a couple beers, I stumbled upon an email uploaded to Virustotal. The file itself is an EML and has the name of “CIA’s _prism Watchlist_.eml”. Inside the email, the content is the following: It appears the intended recipient of the malicious mail was a yahoo account linked to the...

    Read more →

    Asia Adventure Time

    by  • June 15, 2013 • Uncategorized

    It’s that time of year again and I will be migrating across Asia for the next several weeks. If you happen to be at any of the locations mentioned below during those time frames, please let me know and maybe we can meetup! June 17-21 – Speaking at FIRST conference in Bangkok, Thailand July...

    Read more →

    CommentCrew Developer Disconnect

    by  • June 14, 2013 • Uncategorized

    Last week, my colleague on the advanced threat research team, Rob Falcone, pointed me over at a sample that hit on our CommentCrew DES signature. Normally I would shrug this off as something old, but the compilation time on the binary showed June 4, 2013 and the command-and-control (C&C) server appeared to be active....

    Read more →