Your Ad Here
Showing posts with label Ed Skoudis. Show all posts
Showing posts with label Ed Skoudis. Show all posts

Thursday, June 5, 2008

WINDOWS REGISTRY FORENSICS GUIDE: INVESTIGATING HACKER ACTIVITIES

WINDOWS REGISTRY FORENSICS GUIDE: INVESTIGATING HACKER ACTIVITIES
Ed Skoudis, Contributor

When analyzing a compromised Windows system, investigators and system
administrators can glean enormously useful information about
attackers' actions by looking through the Windows registry, a
hierarchical database storing tens of thousands of settings on a
modern Windows box. Whether an outside attacker compromised the box,
an inside employee engaged in nefarious activities, or malware
inexplicably infected the machine, the Windows registry contains
wonderful gems of information for investigators. In this tip, we'll
look at what information investigators can gather about user activity
via the registry.

Interacting with the registry
While there are several ways for investigators to interact with the
registry, two of the most useful are the built-in regedit GUI-based
tool and the reg command-line tool. Regedit has been included in
Windows for over a decade, while the reg command is only included in
more modern Windows machines, such XP Pro, 2003 Server, Vista and
2008 Server.
Read this tip:
http://go.techtarget.com/r/3788298/5749008
Listen to this tip on your PC or favorite MP3 player:
http://go.techtarget.com/r/3788299/5749008
Subscribe to Threat Monitor and our other security podcasts:
http://feeds.feedburner.com/techtarget/fHup

Friday, May 16, 2008

SECURITY TESTING WEBCAST with Ed Skoudis

---------------------------------------------------------------------------------
SECURITY TESTING WEBCAST

Ed Skoudis of SANS presents: “Penetration Testing Ninjitsu Part II: Crouching Netcat, Hidden Vulnerabilities”

Date: Tuesday, May 20

Time: 2pm EDT / 11am PDT (GMT - 4:00, New York)

Register: http://www.coresecurity.com/index.php5module=Form&action=webinar&campaign=ninjitsu2

All registrants will receive a recording of the webcast after the live event, so please be sure to register even if you can’t attend!
---------------------------------------------------------------------------------
Please join Core Security Technologies and Ed Skoudis, SANS instructor and co-founder of Intelguardians, for the second in a series of webcasts intended to stock your IT security testing arsenal with new tips and tricks:

Free webcast: “Penetration Testing Ninjitsu Part II: Crouching Netcat, Hidden Vulnerabilities” Register here:
http://www.coresecurity.com/index.php5?module=Form&action=webinar&campaign=ninjitsu2

(Register today, and you also get access to an on-demand version of “Penetration Testing Ninjitsu Part I!”)

During this webcast, Ed Skoudis will continue his look at the art and science of using penetration testing to gain visibility into your organization’s security posture.

We’ll begin by presenting useful tips for assembling the infrastructure required for effective pen testing. The webcast will then shift to a discussion of Netcat, a useful tool in many security testers’ kits – but one that can raise issues around installing software on target file systems. Ed will therefore present techniques for performing the functions of Netcat – such as moving files, scanning ports and creating backdoors – without using Netcat. You’ll learn:

*how to use Windows command-line tricks to make a port scanner
*how to implement backdoors on Linux using only /dev/tcp
*how commercial tools allow you to focus on analysis and action by automating testing tasks

That's just the start of the tips and tricks we'll cover that will help penetration testers, auditors and other IT security pros do their jobs better. We hope to see you there!

Register here:
http://www.coresecurity.com/index.php5?module=Form&action=webinar&campaign=ninjitsu2