Category: Security Research

  • March – April Events

    After a quiet start for the year (and keeping up with my promise to try and cut down on travel) we are fast approaching exciting times. March will have a couple of great events I’m really looking forward to, and April packs a really great conference and training. So, without further adue: DC9723 kicking off…

  • Hackers, Credit Cards, and the Media

    In the past couple of weeks there has been an interesting “hacking” trend going on in Israel. It started from the publication of a few thousand credit card records (out of an alleged 400,000). Continued with the publication of “SCADA” systems with default credentials, and a handful of gov.il email addresses and passwords, and more…

  • Advanced Data Exfiltration – full paper

    This paper has been published in several security conferences during 2011, and is now being made fully available (as well as a PDF version for downloading)   Abstract Penetration testing and red-team exercises have been running for years using the same methodology and techniques. Nevertheless, modern attacks do not conform to what the industry has…

  • IL-CERT finally picking up speed

    It’s been a long time since I talked about IL-CERT. My personal story with the IL-CERT (or lack thereof) started somewhere in 2009 when I was dealing with some incidents that affected constituencies in multiple countries – Israel included (which were part of my background research for my Cyber[Crime|War] talk). It then picked up some…

  • Intelligence on Ashiyane and the Iranian Cyber Army

    One of my favorite OSINT resources internet-haganah have opened up a new thread on their forums that are dedicated to Iran, called Ashiyane. This is basically the hacker forum that I was researching a couple of years ago (see my DefCon18 talk, and here, and here). The forum thread is here: http://forum.internet-haganah.com/showthread.php?440-Ashiyane And an interesting intelligence profile…