Tuesday, March 28, 2017

Tech Tip Tuesday - Network Penetration Testing Checklist

There are many ways to perform a network penetration test. This checklist gets you started and even suggests some popular tools. Are these in your toolbox?

https://gbhackers.com/network-penetration-testing-checklist-examples/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, March 21, 2017

Tech Tip Tuesday – Cheat Sheet for Windows Machine Intrusion Detection

Is your Windows machine pwned? How do you know? Where do you start? This cheat sheet identifies seven areas to look at as a jumping off point. Happy hunting! https://gbhackers.com/penetration-testing-cheat-sheet-windows-machine-intrusion-detection/ If you have a #CyberPatriot Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, March 14, 2017

Tech Tip Tuesday – Vuln Hub

Vuln Hub is a repository of vulnerable virtual machines for you to download and get your hacking on. There are varying levels of difficulty and some even have walkthroughs. The resources page is a great place to get started.

https://www.vulnhub.com/resources/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, March 7, 2017

Tech Tip Tuesday – Web Penetration Testing (XSS and XSRF)

Here’s a preview to the SANS SEC642: Advanced Web App Penetration Testing, Ethical Hacking, and Exploitation Techniques course. The on demand virtual course goes for $5,910, so it’s nice to get a sneak peek for you sign up. The author goes over the techniques, tools and procedures (TTPs) to combine exploits in cross-site scripting (XSS) and cross-site request forgery (XSRF) for greater effects.

https://pen-testing.sans.org/blog/2017/03/02/modern-web-application-penetration-testing-part-1-xss-and-xsrf-together/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, February 28, 2017

Tech Tip Tuesday – PacketTotal

Analyzing gigs of network packets isn’t your thing? Give PacketTotal a try. Simply upload you PCAP and PacketTotal will run your captured traffic against Bro and Suricata and then index your data with Elasticsearch to make searching easier. PacketTotal will extract artifacts, reconstruct connections and give you drill-down analysis to help you understand your traffic. This is a website on the Internet so be careful not to release any company secrets, PII, HIPPA, PCI, etc. You can also search through other PCAP submissions to get more comfortable with network packet analysis.

https://packettotal.com/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, February 21, 2017

Tech Tip Tuesday – Do It Yourself Online Safety

CHAYN is an open-source project that leverages technology to empower women against violence and oppression so they can live happier and healthier lives but the information in their online safety guide is useful for everyone. They highlight the many digital traces you leave behind from different technologies and provide instructions to minimize that digital footprint.

http://chayn.co/safety/

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.

Tuesday, February 14, 2017

Tech Tip Tuesday – Microsoft Patch Tues… wait

Microsoft hit the pause button on Patch Tuesday. This is a big deal if you were hoping to patch the SMB version 3 vulnerability which allows attackers to “blue screen” fully patched Windows 10 and 8.1 machines. For now you should block SMB v3 traffic from leaving your network. This at least limits the attack surface to your local network.

https://www.kb.cert.org/vuls/id/867968

If you have a Tech Tip you want to share, send them to info@cyberhui.org and we'll get them out next #TechTipTuesday.