28 January 2018

Considerations before using keybase.io

Keybase.io is a service that according to their website “maps your identity to your public keys, and vice versa.”. It is also doing other optional things such as an encrypted filesystem and synchronized key management.

28 January 2018

How We Bypassed NOD32 and Hacked a Paranoid Customer

During penetration testing for a big customer, we hacked a number of Microsoft Windows servers. At one point, part of our attack was thwarted by ESET’s NOD32 system.

28 January 2018

From Firewalls to Honeypots: Citadelo’s Vision for Cybersecurity

Perimeter security is broken. Industrial systems are exposed. And attackers are always one step ahead. At Citadelo, we’ve crafted a masterplan to flip the odds — from honeypots to bug bounties to real-time traps.

26 January 2018

ExtendedMacro – BurpSuite plugin

BurpSuite Proxy is one of the most used HTTP proxy application for web penetration testers. This tool is one of the best in its category, but sometimes we encounter a situation requiring additional functionality which is not provided by Burp itself.

26 January 2018

We found vulnerability of CMS Made Simple

CMS Made Simple is a free, open source CMS to provide developers, programmers and site owners a web-based development and administration area. In 2010 it won the Packt Publishing annual award for open source content management.

20 October 2015

The Critical State of Industrial Control Systems Security

"Finally we are beginning to address the problem that we have already had in years.” This laconic sentence can sum up the conclusions of the first conference focused on security of industrial control systems (ICS).