For CA-signed ssh keys, how to see various attributes: principals, identity, serial number, options, validity time, etc

I am looking to implement access controls through CA-signed public ssh keys, as described in the article Scalable and secure access with SSH.

I am trying to conceive how our security team will manage this on the CA side. One thing I woul… Continue reading For CA-signed ssh keys, how to see various attributes: principals, identity, serial number, options, validity time, etc

Ghostwriting for Antivirus Evasion in 2018

One of the techniques we cover in the antivirus evasion section of the SANS SEC 504 course is ghost writing. The topic was covered brilliantly by Royce Davis on his blog back in 2012 (https://www.pentestgeek.com/penetration-testing/using-metasm-to-avoid-antivirus-detection-ghost-writing-asm). The workflow he laid out … Continue reading Continue reading Ghostwriting for Antivirus Evasion in 2018

Posted in Uncategorized

Using Burp Suite’s Collaborator to Find the True IP Address for a .Onion Hidden Service

On this Thanksgiving day I’m going to write about something near and dear to all our hearts: stuffing. I’m not talking about the delicious pile of bread you’ll have on your plate this afternoon, I’m talking about stuffing payloads into … Continue reading Continue reading Using Burp Suite’s Collaborator to Find the True IP Address for a .Onion Hidden Service

Posted in Uncategorized