feeds2read
Latest Flows from this sub-category:
PCHubs.com

Blog: No Adware Spyware Tool

Digital Rights Management, IPR and copy control

黄大鬼's Blog

灰熊网

Computer Security

Internet Security and Programming

Blank89 - Technology Exposed

Talk to a Real Geek Podcast

RegCure Blog

random selection from this sub-category:
The Register - Security: Enterprise Security

ITSecurityPortal.com

Anti Spyware 101

Shon Harris' CISSP Blog

Sys Admin Magazine

Lifedork

Security Crawler

security.bl0gg.nl | advisories, exploits and patches

Packet Storm Security Exploits

Intelore.com - Password Recovery Software

Rss Directory > Computer > Security > Lenny Zeltser's Website


Lenny Zeltser's publications, research, and projects related to information security, risk management, business, and life in general.
Copyright: Copyright 1995-2008 Lenny Zeltser. All rights reserved.
Malware authors increasingly use Flash SWF programs, often in the form of banner ads, as infection vectors. The community's skills of analyzing such files are still rather basic, as are the tool available to us. I've been researching this topic, and would like to share my findings and ask you for feedback. I'm putting finishing touches on a new section of the reverse-engineering malware course (SEC610) that will deal with Flash file analysis. Would you like to participate in a 60-minute "dress-rehearsal" webcast of these materials? It's free, and scheduled for September 18, 1pm Eastern Time. Drop me a note, via the "Contact Me" page, and I'll send you connection details.
  Mon, 18 Aug 2008 17:08:22 +0200
I created a one-page cheat sheet of shortcuts and tips for reverse-engineering malware. It covers the general malware analysis process, as well as useful tips for OllyDbg, IDA Pro, and other tools. An editable version of this file is also available, if you'd like to customize the cheat sheet for your own needs. My reverse-engineering malware course explores these, and other useful techniques.
In this free one-hour webcast, I discuss tools and techniques for going beyond the basic exploits-focused penetration testing methodology. To attend it live, tune in on August 5 at 1:00 PM EDT. An archived version of the webcast will be available.
  Thu, 12 Jun 2008 18:45:11 +0200
In this free one-hour webcast, I examine the characteristics of today's malware, exemplified by recently-seen bots, downloaders, keyloggers, and malicious scripts.An archived version of the webcast is available, complete with audio and presentation slides.
  Sat, 07 Jun 2008 23:07:12 +0200
This article presents recommendations for addressing the risks associated with modern malware. Stopping malware requires an approach grounded in awareness and control. The article includes a link to my related webcast on protecting users from web-based threats.
I will teach the Reverse-Engineering Malware course at SANS conferences in July 2008 (Washington, DC), September 2008 (Las Vegas, NV), and December 2008 (Washington, DC). I will also teach it via an interactive video format in June 2008; this event is a unique opportunity for higher education, and local and state government employees to take the course at a 75% discount.
  Thu, 01 May 2008 18:40:15 +0200
When searching for low-hanging fruit, attackers are paying closer attention to client-side vulnerabilities on internal workstations. So should you, when performing security assessments. This article describes how to test for client-side vulnerabilities during a security assessment.
  Thu, 20 Mar 2008 03:36:16 +0100
Rare is the case when a determined penetration tester or attacker fails to trick his targets into releasing sensitive information. This article explains how to incorporate social engineering testing into information security assessments.
PaulDotCom interviewed SEC602 course co-authors during its January 24, 2008, webcast. We discussed key procedures for malware analysis, malware trends, and the expansion of the Reverse-Engineering Malware course. MP3 of the webcast is now available.
Announcing the expansion of the Reverse-Engineering Malware course. Here's the full announcement.
  Sat, 29 Dec 2007 02:21:25 +0100
I lead a regional security team at SAVVIS, a premier provider of IT infrastructure and hosting services. We offer a range of consulting services, including vulnerability assessments and penetration testing.
  Sun, 10 Jun 2007 18:12:15 +0200
This article reviews the emerging threats landscape of information security, including targeted attacks, client-side infections, advanced malware, bots, and browser malware. It was originally published in May 2007 issue of Information Security magazine.
In this SANS webcast I present 10 key issues you need to address for a successful penetration test.
The reporter interviewed me for this article on protecting organizations against endpoint threats.
  Sun, 14 Jan 2007 17:28:13 +0100
In this SANS' Ask The Expert webcast I review several techniques and free tools for speeding-up the analysis of malicious software.
This article presents several tips for establishing a practical routine for reviewing information security logs.
This article, published in Information Security Magazine, describes an approach to ensuring a project's success by becoming attuned to the organization's dynamics.
  Mon, 04 Sep 2006 07:42:32 +0200
This webcast, presented at SANS Institute, examines the nature of threats that target the Web browser, reviewing three major categories of browser-oriented attacks.
  Sun, 21 May 2006 18:23:45 +0200
This presentation, prepared for ISSA, explores common information security risks that organization face, and suggests 10 questions worth asking when establishing a robust IT security program.
  Thu, 19 Jan 2006 03:18:06 +0100
This 1-minute video of Magellan Penguins records my observations from a visit to Argentina's Patagonia region.
  Fri, 04 Nov 2005 05:17:44 +0100
This book, which I produced and co-authored, is a practical guide to designing, deploying, and maintaining network defenses.
  Tue, 07 Jun 2005 06:42:37 +0200
If you are interested in learning a bit more about me, this page is for you. Here I list some autobiographical facts and outline a several of my projects and accomplishments. After all, activity suggests a life filled with purpose.
  Tue, 04 Nov 2003 05:17:11 +0100
I contributed a few chapters to this Ed Skoudis' book, which focuses on defending against the threat of malicious code.
  Thu, 04 Nov 2004 05:16:53 +0100
Organizations periodically invite me to present to them on topics related to IT risk management and security in business. Here are some of my recent presentations.
This paper examines trends and dynamics of the endpoint security industry, and evaluates the performance of market leaders such as Symantec in the context of these factors.
  Sat, 06 Apr 2002 06:15:51 +0200
This article explores the use of multiple firewalls for protecting resources according to business requirements of multitier applications.
  Thu, 02 Nov 1995 05:15:31 +0100
This often-cited article discusses the history and the structure of the Web, and offers a peak at the future of information sharing.
  Sat, 04 Nov 2000 05:15:07 +0100
This article examines the evolution of malicious agents by analyzing popular viruses, worms, and trojans, and detailing the possibility of a new breed of malicious software.
  Fri, 04 Nov 2005 05:02:03 +0100
Save time when researching security issues by focusing on specific sites of interests.
  Sat, 04 Mar 1995 05:14:41 +0100
This paper explores early radio broadcasting efforts by the United States and the Soviet Union.
  Sat, 04 May 1996 06:23:41 +0200
This paper examines views of American Founders on education, and applies them to the Internet's role as a catalyst for improving the American education system.
  Sun, 04 Jun 2000 06:13:36 +0200
This paper provides a detailed analysis of several anomalous network events, and illustrates the techniques for examining alerts and logs generated by a network intrusion detection system.
  Sun, 04 Nov 2001 05:13:19 +0100
This report presents results of a detailed information security audit of UNIX systems that belong to a fictitious company. It illustrates an approach to performing such an examination.
This paper documents a comprehensive architecture for defending network resources of a fictitious company. It illustrates an approach to setting up a strong security perimeter.
  Sun, 04 Nov 2001 05:12:39 +0100
This paper defines a framework for using easily-accessible tools and a dual-phased approach to examine malware such as viruses, worms, and trojans.
This paper documents my team's thesis research on natural language processing systems for retrieving documents based on short queries.
  Mon, 04 Apr 2005 06:11:24 +0200
Slap a high five to the infamous Calvin, just because you have nothing better to do.
  Mon, 04 Apr 2005 06:08:54 +0200
"Lying in bed listening to the rain outside." "Laughing for no reason at all." Take a look at what folks submitted to me over the years, and see what inspires people of the world.
  Sun, 03 Apr 2005 06:08:13 +0200
Relax. Here you will find some of the poems I enjoy, written by well-established "professional" authors and by less-known amateur ones.
  Sat, 02 Apr 2005 05:57:49 +0200
I've assembled a few humorous lists circulating on the Internet, such as "The Canonical List of Answering Machine Messages" and "More Than Fifty Ways to Get Rid of Blind Dates."

Disclaimer|Rss Directory|Try a Feed|Suggest a Feed|F-A-Q|Partners
Links: Référencement internet | Annuaire Webmaster  | ubuntu/debian tips
Comparateur de Prix | Logos, Sonneries, Jeux Java | Sonneries pour portables | Ringtones and logos for mobile phone | Accéssoires pour téléphone portable | Sonneries Et Logos
© copyright feeds2read.net 2005-2008