Get your servers tested and protected against Denial of Service attacks.
This service consists of a series of tests with the objective of verifying that the servers aren't susceptible to a denial of service attack. A window of time is defined during which, under complete supervision of the processes and resources, a wide range of different DoS attacks are performed.
The tests consist of the following:
1. Saturate the servers by sending a vast amount of requests to the web application.
2. DoS through the use of commercial tools.
3. DoS through the use of several public and private tools.
4. Testing for DoS based on the software and services running on the server.
Some of our tests include the same attacks and tools used by hacktivist group Anonymous. By using clients with connections to the Internet backbone, our Distributed Denial of Service (DDoS) tests can be performed with up to 50,000 virtual users (200,000 virtual browsers), in which we show a visual geographic distribution of each unique connection made by the virtual users.
We additionally use other tools (both public and private), which in many cases can be more effective than the tools used by Anonymous.
Furthermore, we analyze the version of the software installed on the server to verify that there aren't any known vulnerabilities or faulty configurations that could result in a denial of service. In the event that a vulnerability of this kind was found on the server, it would be tested using the available proof of concept.
Bypassing Web Application Firewalls with SQLMap Tamper Scripts
An introduction to SQLMap's new tamper scripts and how the can be used to bypass Web Application Firewalls and Intrusion Detection Systems.
Posted in SQL Injection WAF SQLMap Tamper Scripts Firewall
Optimized Blind MySQL Injection Data Retrieval
Demonstrates a method to extract data from a MySQL database using blind injection in fewer requests than currently known techniques such as the Bisection and Bit Shift method.
Posted in Blind Injection MySQL SQL Injection Database
mac2wepkey - Huawei default WEP generator
Huawei HG520 and HG530 routers are vulnerable to weak cipher attacks. It is possible to generate the default WEP/WPA key. The purpose of this post is to explain the process of developing a key generator for these devices.
Posted in mac2wepkey home gateway wep generator echolife hg530 huawei hg520
Apr 30, 2012
GuadalajaraCON 2012 by Websec
Mar 21, 2012
Conference on Cyberbulling at Westhill Institute
Websec had the opportunity to speak with students at the Westhill Institute about Cyberbulling and the threat it brings to young adults.