As a cybersecurity engineer and an unapologetically enthusiastic “web guy,” I have both a personal and professional interest in finding new exploitation methods. Recently, I found an interesting and creative way to control a browser by exploiting a cross-site scripting (XSS) vulnerability. I learn by doing, so I executed the concept to see it work in practice. Without spoiling too much, I was very pleased with the results! This attack uses nothing more than Netcat and some clever XSS injection code. For those unfamiliar with Netcat, it’s a networking utility that reads and writes data across network connections.
Topics: Data Protection & Privacy, Penetration Testing, Monitoring & Detection
#Zoombombing, Nazi's, Kids, and Cybersecurity 2020
Zoom has been a big name in the headlines lately, mainly due to the world’s newfound dependence on, and perhaps obsession with, the platform. As global business is forced to move online, Zoom has become one of the most commonly chosen video conferencing platforms. It’s easy to use, simple to roll out, and the company has provided free and low-cost licenses to both public and private organizations.
How things stand: a cybersecurity recap of 2019
Topics: Vulnerabilities, Penetration Testing, Incident Response, Monitoring & Detection, Security Advisory
Imagine for a moment your favorite spy movie, maybe a James Bond movie for example. It’s cast of characters likely consists of five or so core archetypical personas. In this cast you likely have a cunning spy, a love interest, the shrouded head of the spy agency, the maniacal bad guy, and a clever hacker sitting in the background. Swooping in seemingly at a moment’s notice to disarm a security system or provide intel about a target’s movements, the hacker always seems to be a mysterious figure with deus ex machina powers. In the following article, we’ll dive into this archetypical figure, breaking down the driving factors behind hacking and the overall ideas behind what makes a hacker ‘tick’.
Topics: Penetration Testing
ProCircular CEO, Aaron Warner supports the cyber community
ProCircular founder and Chief Executive Officer, Aaron Warner is slated to speak at the first annual Awareness Con, an information security conference hosted by Black Hills Information Security (BHIS). The event will be hosted on Wednesday, November 20th in Adel, Iowa at the Adel Public Library. The purpose of Awareness Con is to draw attention to the profession of ethical hacking, commonly referred to as Penetration Testing, and the benefits this practice can have for organizations of all types. Penetration Testing is a simulated attack on an organization's computer and physical security systems to ensure that existing security measures in place are effective.
Topics: Penetration Testing, Company News
