One of the common behaviors of Malware is to infect system processes in order to preserve access to the Machine or to run malicious actions ...
Como llegue a uno de los equipos de Seguridad mas reconocidos en el Mundo.
Definitivamente, el hecho de llegar al equipo de Seguridad (Security Response Team) de Symantec encargado en combatir los virus y todo tipo ...
Bypassing WAF via HTTP Parameter Pollution
Last week I was invited to join a team to participate in a CTF (Capture The Flag) contest organized by CSAW Team. With my wife and kids ar...
Post/Get Parameter's Name Injection
When testing Web Applications, usually a security analyst will try to identify all the inputs to be injected like Cookies, POST/GET paramete...
Dumping Plymorphic Malware in seconds!
Nowadays Polymorphic Malware is created to try to bypass AV detection, but there are ways to easily dump the malicious binary from memory an...
Dissecting Joomla Malware
By the time of this post being written, there is a malicious site: botstatisticupdate.com serving obfuscated JavaScript code using the wel...
Wassenaar arrangement could be the cause of Legacy systems encryption weakness.
Recently, while doing a secure code review in a Delphi Legacy application, I found a function named: InitialiseString() used by the Blowfis...