- 28 August 2012 10:40
Pure Hacking to present at Hack in the Box Security Conference
The two day training course will provide attendees with a “Virtual Shellcode Development Environment” that is designed to enable shellcode development across multiple platforms including Linux, Mac 64-bit OSX and Windows. Students are instructed in the development of simple to complex shellcode and Metasploit Exploit Framework (MSF) integration to successfully execute your own shellcode within all MSF exploits.
Targeted at Penetration Testers, Security Officers, Security Auditors and System Administrators, “The Shellcode Lab” is ideal for attendees interested in shellcoding, exploitation, vulnerabilities or Metasploit. It is also suitable for developers interested in gaining low-level security development skills with shellcoding and assembly, plus management staff needing to better understand how Information Technology Systems are compromised.
The training course focuses on writing shellcode to bypass security controls to increase the exploitation success rate. Students are taught how to encode their shellcode using the Metasploit Exploit Framework (MSF), and insert it into exploits that will be used to show that their shellcode was successfully executed. "The Shellcode Lab" has been held at Black Hat USA in 2011 and 2012.
For Miller attendance at The Shellcode Lab has multiple benefits. "It is crucial for security experts to understand the underlying assembly language to be able to understand shellcode exploits. This is the primary method for identifying how to improve security for the enterprise," he recommended.
Concurrent to his role as CTO at Pure Hacking, Miller performs independent security research and is co-author of the book Hacking Exposed Linux 3rd edition. He runs the shellcoding site ‘Project Shellcode’ (www.projectshellcode.com) and was involved in the design of the bootable CHAOS Linux cluster distribution.
Interested participants can visit http://conference.hitb.org/hitbsecconf2012kul/tech-training-5-shellcode-lab/
About Pure Hacking Pure Hacking is Australia’s leading specialist information security consultancy. As the authoritative source in strategic, application, infrastructure and operational services, Pure Hacking has set the standard for ethical hacking and security consulting since 2002. Simply put, Pure Hacking saves companies from devastating attacks by enabling secure business. www.purehacking.com
- 1
Dell targets ANZ security opportunities as SecureWorks debuts locally
- 2
Bank trojan targets users of Bitcoin exchange Mt Gox
- 3
Australian Information Security Association issues blunt warning as National Cyber Security Awareness Week begins
- 4
ACMA database keeps finger on Australia’s malware pulse
- 5
Review: Mobile Device Management
-
HID Global Awarded Intergraf’s Prestigious “Security Printer” Certification
-
Blue Coat unveils strategy for securely empowering businesses
-
A10 Networks and Brocade reach settlement of legal disputes
-
PR Deadlines scores two more ICT accounts
-
AVG Technologies Acquires Leading Online Privacy Firm PrivacyChoice
- FTJob Title: Mac Systems/ Enterprise Systems EngineerNZ
- FTQuality ManagerSA
- FT.NET - Sitecore Developer - Melbourne - PermNSW
- FTTest EngineerVIC
- FTTest Analyst (MS Environment) .netNSW
- FTSenior Python DeveloperNSW
- FTFlash / ActionScript Developer - ContractNSW
- FTTest Analyst (MS Environment) .netNSW
- FTLead Software EngineerSA
- FTR&D EngineerSA
- FTOS Web Applications DeveloperNSW
Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).
- Have an incident response plan.
- Pre-define your incident response team
- Define your approach: watch and learn or contain and recover.
- Pre-distribute call cards.
- Forensic and incident response data capture.
- Get your users on-side.
- Know how to report crimes and engage law enforcement.
- Practice makes perfect.
Warning: Tips for secure mobile holiday shopping
I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.









