-
Rafael Dominguez Vega - 31 Jul 2008
Behind Enemy Lines: Administrative Application Attacks White Paper released
A white paper by MWR InfoSecurity explores security vulnerabilities in administrative web applications. The research details how alternative network protocols like DHCP and 802.11 can be leveraged to conduct web-based attacks. The paper provides insights into practical exploitation techniques for testing and compromising administrative web applications.
-
Martyn Ruks - 6 May 2008
IBM WebSphere MQ Security Part 1
This whitepaper examines security vulnerabilities in IBM WebSphere MQ middleware, a widely used enterprise messaging system. It highlights the complexity of securing middleware environments and introduces a penetration testing methodology for assessing WebSphere MQ security. The research aims to provide insights for security professionals responsible for protecting complex messaging infrastructure.
-
Luke Jennings - 16 Apr 2008
Security Implications of Windows Access Tokens
A whitepaper by Luke Jennings explores the security implications of Windows access tokens in enterprise environments. The document details how access token design can be exploited during penetration testing, highlighting systemic vulnerabilities in corporate security controls. The paper discusses the technical mechanisms of Windows access tokens and provides insights into potential post-exploitation techniques.
-
Rafael Dominguez Vega - 26 Oct 2007
FIST 2007 - Inspect a Gadget
A presentation by Rafael Dominguez Vega explores security vulnerabilities in Windows Vista Sidebar Gadgets. The research investigates potential attack vectors targeting these gadgets. Best practice recommendations are provided for mitigating security risks associated with sidebar gadget implementations.
-
Rafael Dominguez Vega - 27 Sep 2007
Considerations for the Secure Rollout of Sidebar Gadgets on Windows Vista
This white paper analyzes the security implications of Windows Vista's Sidebar Gadgets feature. It explores potential attack vectors and risks associated with the new technology. The document provides recommendations for a secure implementation of Sidebar Gadgets.
-
Martyn Ruks - 3 Aug 2007
DefCon 15 - Websphere MQ
A presentation about IBM Websphere MQ software security was delivered at DefCon 15 in Las Vegas on August 3rd, 2007. The presentation was given by MWR InfoSecurity and the slides are available for download from their website.
-
Martyn Ruks - 5 Aug 2006
DefCon 14 - IBM Networking
A presentation by Martyn Ruks at DefCon 14 in 2006 explored IBM network security testing methodologies. The talk focused on identifying potential vulnerabilities in IBM network infrastructure. Specific network security assessment techniques for IBM systems were discussed during the presentation.