Low Hanging Fruits: The Top Five Easiest Ways to Hack or Get Hacked (English)
How familiar are you with low-hanging fruit — the easiest ways for attackers to gain entry to your network and potentially run off with your valuable data? This white paper explores penetration tests that you can perform at your organization to gain an understanding of how to apply the proper defenses to prevent exploitation of the top five low-hanging fruit.
Achieving Security through Compliance (English)
This paper will illustrate how a well-structured security governance program with fully developed and implemented policies, plans, and procedures will strengthen an organization’s security posture.
A Pentester's Guide to Hacking ActiveMQ-Based JMS Applications (English)
Enterprise messaging systems (EMS) are highly reliable, flexible, and scalable systems that allow asynchronous message processing between two or more applications. This paper provides guidance on penetration testing techniques to assess the security of ActiveMQ-based EMS written using the Java Message Service API.
Building and Maintaining a Business Continuity Program (English)
Business continuity planning is a critical function that involves many different personnel and departments over multiple phases. As with many business continuity programs, an iterative process is most effective in developing a refined set of procedures and plans.
McAfee ePolicy Orchestrator: Creating an Apache HTTP Repository (English)
This document describes how to configure Apache and Samba running on a Linux operating systems (OS) platform for the purpose of creating an Apache HTTP Repository for McAfee ePolicy Orchestrator. The Apache repository will allow customers to meet the requirement to have a Linux repository.
주제: Foundstone, 보안 관리
Detecting Botnet Propagation (English)
This paper explains botnet propagation techniques uncovered during a recent investigation along with the tools and techniques used to quickly evaluate two separate events.
PCI Guidance: Microsoft Windows Logging (English)
Logging is normally something that is done to help troubleshoot system availability issues. This paper helps system administrators meet PCI logging requirements by capturing who did what and when, establishing alerts to detect issues that could indicate a system breach and exposure of credit card data.
A Pentester’s Guide to Hacking OData (English)
The Open Data Protocol (OData ) is an open web based RESTful protocol for querying and updating data. This paper discusses OData penetration testing methodology and techniques.
Bypassing CAPTCHAs by Impersonating CAPTCHA Providers (English)
CAPTCHA providers allow websites to integrate anti-automation mechanisms by offering CAPTCHA generation and verification services along with the libraries to consume those services.
Emergency Incident Response: 10 Common Mistakes of Incident Responders (English)
This paper summarizes the top 10 incident response mistakes in the field, highlights issues so you can review your incident response practices, and determines whether you suffer from these shortcomings.