![]() |
| Home RSS Directory F.A.Q Try Custom Feed Sonneries Portable |
Latest Flows from this sub-category: random selection from this sub-category: |
Lenny Zeltser's publications, research, and projects related to information security, risk management, business, and life in general. Copyright: Copyright 1995-2008 Lenny Zeltser. All rights reserved. Fri, 12 Sep 2008 16:55:12 +0200 Malware authors increasingly use Flash SWF programs, often in the form
of banner ads, as infection vectors. The community's skills of analyzing
such files are still rather basic, as are the tool available to us. I've
been researching this topic, and would like to share my findings and ask you
for feedback. I'm putting finishing touches on a new section of the reverse-engineering
malware course (SEC610) that will deal with Flash file analysis. Would you
like to participate in a 60-minute "dress-rehearsal" webcast of these materials? It's free, and scheduled for September 18, 1pm Eastern Time. Drop me a note,
via the "Contact Me" page, and I'll send you connection details.
Mon, 18 Aug 2008 17:08:22 +0200 I created a one-page cheat sheet of shortcuts and tips for reverse-engineering malware.
It covers the general malware analysis process, as well as useful tips for OllyDbg, IDA Pro, and
other tools. An editable version of this file is also available, if you'd like to customize the
cheat sheet for your own needs. My reverse-engineering malware course explores these, and other
useful techniques.
Fri, 18 Jul 2008 23:55:12 +0200 In this free one-hour webcast, I discuss tools and techniques for going beyond the basic exploits-focused penetration testing methodology. To attend it live, tune in on August 5 at 1:00 PM EDT. An archived version of the webcast will be available.
Thu, 12 Jun 2008 18:45:11 +0200 In this free one-hour webcast, I examine the characteristics of today's malware, exemplified by recently-seen bots, downloaders, keyloggers, and malicious scripts.An archived version of the webcast is available, complete with audio and presentation slides.
Sat, 07 Jun 2008 23:07:12 +0200 This article presents recommendations for addressing the risks associated with modern malware. Stopping malware requires an approach grounded in awareness and control. The article includes a link to my related webcast on protecting users from web-based threats.
Wed, 11 Jun 2008 16:07:12 +0200 I will teach the Reverse-Engineering Malware course at SANS conferences in July 2008 (Washington, DC), September 2008 (Las Vegas, NV), and December 2008 (Washington, DC). I will also teach it via an interactive video format in June 2008; this event is a unique opportunity for higher education, and local and state government employees to take the course at a 75% discount.
Thu, 01 May 2008 18:40:15 +0200 When searching for low-hanging fruit, attackers are paying closer attention to client-side vulnerabilities on internal workstations. So should you, when performing security assessments. This article describes how to test for client-side vulnerabilities during a security assessment.
Thu, 20 Mar 2008 03:36:16 +0100 Rare is the case when a determined penetration tester or attacker fails to trick his targets into releasing sensitive information. This article explains how to incorporate social engineering testing into information security assessments.
Mon, 28 Jan 2008 03:49:15 +0100 PaulDotCom interviewed SEC602 course co-authors during its January 24, 2008, webcast. We discussed key procedures for malware analysis, malware trends, and the expansion of the Reverse-Engineering Malware course. MP3 of the webcast is now available.
Fri, 28 Dec 2007 17:58:21 +0100 Announcing the expansion of the Reverse-Engineering Malware course. Here's the full announcement.
Sat, 29 Dec 2007 02:21:25 +0100 I lead a regional security team at SAVVIS, a premier provider of IT infrastructure and hosting services. We offer a range of consulting services, including
vulnerability assessments and penetration testing.
Sun, 10 Jun 2007 18:12:15 +0200 This article reviews the emerging threats landscape of information security, including targeted attacks, client-side infections, advanced malware, bots, and browser malware. It was originally published in May 2007 issue of Information Security magazine.
Sat, 21 Apr 2007 19:57:21 +0200 In this SANS webcast I present 10 key issues you need to address for a successful penetration test.
Tue, 23 Jan 2007 14:18:22 +0100 The reporter interviewed me for this article on protecting organizations against endpoint threats.
Sun, 14 Jan 2007 17:28:13 +0100 In this SANS' Ask The Expert webcast I review several techniques and free tools for speeding-up the analysis of malicious software.
Sun, 29 Oct 2006 18:29:30 +0100 This article presents several tips for establishing a practical routine for
reviewing information security logs.
Mon, 04 Sep 2006 18:01:32 +0200 This article, published in Information Security Magazine, describes an approach to ensuring a project's success by becoming attuned to the organization's dynamics.
Mon, 04 Sep 2006 07:42:32 +0200 This webcast, presented at SANS Institute, examines the nature of threats that target the Web browser, reviewing three major categories of browser-oriented attacks.
Sun, 21 May 2006 18:23:45 +0200 This presentation, prepared for ISSA, explores common information security risks that organization face, and suggests 10 questions worth asking when establishing a robust IT security program.
Thu, 19 Jan 2006 03:18:06 +0100 This 1-minute video of Magellan Penguins records my observations from a visit to Argentina's Patagonia region.
Fri, 04 Nov 2005 05:17:44 +0100 This book, which I produced and co-authored, is a practical guide to designing, deploying, and maintaining network defenses.
Tue, 07 Jun 2005 06:42:37 +0200 If you are interested in learning a bit more about me, this page is for you. Here I list some autobiographical facts and outline a several of my projects and accomplishments. After all, activity suggests a life filled with purpose.
Tue, 04 Nov 2003 05:17:11 +0100 I contributed a few chapters to this Ed Skoudis' book, which focuses on defending against the threat of malicious code.
Thu, 04 Nov 2004 05:16:53 +0100 Organizations periodically invite me to present to them on topics related to IT risk management and security in business. Here are some of my recent presentations.
Sat, 04 Jun 2005 06:16:09 +0200 This paper examines trends and dynamics of the endpoint security industry, and evaluates the performance of market leaders such as Symantec in the context of these factors.
Sat, 06 Apr 2002 06:15:51 +0200 This article explores the use of multiple firewalls for protecting resources according to business requirements of multitier applications.
Thu, 02 Nov 1995 05:15:31 +0100 This often-cited article discusses the history and the structure of the Web, and offers a peak at the future of information sharing.
Sat, 04 Nov 2000 05:15:07 +0100 This article examines the evolution of malicious agents by analyzing popular viruses, worms, and trojans, and detailing the possibility of a new breed of malicious software.
Fri, 04 Nov 2005 05:02:03 +0100 Save time when researching security issues by focusing on specific sites of interests.
Sat, 04 Mar 1995 05:14:41 +0100 This paper explores early radio broadcasting efforts by the United States and the Soviet Union.
Sat, 04 May 1996 06:23:41 +0200 This paper examines views of American Founders on education, and applies them to the Internet's role as a catalyst for improving the American education system.
Sun, 04 Jun 2000 06:13:36 +0200 This paper provides a detailed analysis of several anomalous network events, and illustrates the techniques for examining alerts and logs generated by a network intrusion detection system.
Sun, 04 Nov 2001 05:13:19 +0100 This report presents results of a detailed information security audit of UNIX systems that belong to a fictitious company. It illustrates an approach to performing such an examination.
Mon, 04 Dec 2000 05:12:59 +0100 This paper documents a comprehensive architecture for defending network resources of a fictitious company. It illustrates an approach to setting up a strong security perimeter.
Sun, 04 Nov 2001 05:12:39 +0100 This paper defines a framework for using easily-accessible tools and a dual-phased approach to examine malware such as viruses, worms, and trojans.
Sun, 04 May 1997 06:12:05 +0200 This paper documents my team's thesis research on natural language processing systems for retrieving documents based on short queries.
Mon, 04 Apr 2005 06:11:24 +0200 Slap a high five to the infamous Calvin, just because you have nothing better to do.
Mon, 04 Apr 2005 06:08:54 +0200 "Lying in bed listening to the rain outside." "Laughing for no reason at all." Take a look at what folks submitted to me over the years, and see what inspires people of the world.
Sun, 03 Apr 2005 06:08:13 +0200 Relax. Here you will find some of the poems I enjoy, written by well-established "professional" authors and by less-known amateur ones.
Sat, 02 Apr 2005 05:57:49 +0200 I've assembled a few humorous lists circulating on the Internet, such as "The Canonical List of Answering Machine Messages" and "More Than Fifty Ways to Get Rid of Blind Dates."
|
|
contact |