Blog Entries

ARBSEC Officially Launched

February 19th, 2009

ARBSEC, a CitySec-style meetup for security professionals in the Ann Arbor area, has been officially launched!  Our first meeting, ARBSEC 01, will be at 6:00pm on March 4th at Bar Louie in Ann Arbor.

Read the rest of this entry »


dpkt Tutorial #3: DNS Spoofing

December 20th, 2008

In our first and second dpkt tutorials, we looked at the simple construction and parsing of packets respectively.  Our third tutorial combines both parsing and construction of packets in a single utility for performing DNS spoofing (a la dsniff’s dnsspoof).

Read the rest of this entry »


VirusTotal Python Submission Script

November 20th, 2008

Here is a simple python script for batch malware submissions to VirusTotal via its email interface.  Simply replace the SMTP-related variables at the top of the script and you’re ready to rock!

Read the rest of this entry »


dpkt Tutorial #2: Parsing a PCAP File

October 15th, 2008

As we showed in the first dpkt tutorial, dpkt makes it simple to construct packets.  dpkt is equally useful for parsing packets and files, so in this second tutorial we will demonstrate parsing a PCAP file and the packets contained within it.

Read the rest of this entry »


Bash Brace Expansion Cleverness

September 4th, 2008

Brace expansion is a nice feature in the Bash interpreter that happened to be exactly what I needed during an audit.  A good thing to log away in memory in case you ever find yourself in a pen-test environment with similar constraints.

Read the rest of this entry »


dpkt Tutorial #1: ICMP Echo

August 25th, 2008

In this dpkt tutorial, I will demonstrate how to construct and send a simple ICMP echo packet.

Read the rest of this entry »


Hardening DNS with IP TTLs

August 10th, 2008

During Paul Vixie’s talk at WOOT on some of the operational challenges of deploying source port randomization functonality in BIND, I started thinking of a few simple ways to harden DNS infrastructure against VU#800113 by leveraging the IP TTL value.

Read the rest of this entry »


HotSec 2008 and USENIX Security 2008

August 2nd, 2008

I’m back from San Jose finally and while I won’t be breaking down a full review of HotSec and USENIX Security like I did for WOOT, I thought I would point out some of the more interesting presentations I was able to attend.

Read the rest of this entry »


WOOT 2008: The Good, The Bad, and The Ugly

July 28th, 2008

Day one of my trip out to San Jose to attend the WOOT, HotSec, and USENIX Security trifecta is over.  The 2nd Workshop on Offensive Technologies (WOOT) took place today and I’ll be breaking it down with “The Good, The Bad, and The Ugly”.

Read the rest of this entry »


UofM-Specific Phishing Campaign

July 21st, 2008

While receiving phishing emails in my University inbox is a common occurrence, a recent email caught my eye due to its increased sophistication and University-specific information.

Read the rest of this entry »