These are the links/resources collected by one of my friends Sandeep for his research purposes, shared with me. Most of it is worth the read. Hope this helps someone somewhere gain some knowledge........ !!!
HTE -- File manipulator
http://hte.sourceforge.net/
Mach-O filetype and infection methods
http://felinemenace.org/~nemo/slides/mach-o_infection.ppt
Same idea, different author
http://vx.netlux.org/lib/vrg01.html
Method Swizzling (you can remap the function name pointer to binary code mapping on OS-X)
http://www.cocoadev.com/index.pl?MethodSwizzling
Class Posing!
http://www.cocoadev.com/index.pl?ClassPosing
http://www.stepwise.com/Articles/Technical/PosersAndCategories/index.html
OS-X Tools:
otool -- Object File Displaying Tool http://developer.apple.com/mac/library/documentation/Darwin/Reference/ManPages/man1/otool.1.html
gdb -- GNU Debugger (part of GCC)
http://developer.apple.com/tools/gcc_overview.html
gas -- host spoofing manager
http://www.apple.com/downloads/macosx/development_tools/gasmask.html
libtool -- Create Libraries
http://developer.apple.com/mac/library/documentation/Darwin/Reference/ManPages/man1/libtool.1.html
file -- File Typer
http://linux.die.net/man/1/file
ktrace -- Kernel Trace Logging for a process
System Calls, Name Translations, Signal Processing, I/O
dtrace -- Debugger/Tracer in 10.5+
http://www.mactech.com/articles/mactech/Vol.23/23.11/ExploringLeopardwithDTrace/index.html
http://www.macosxhints.com/article.php?story=20071031121823710
kdump -- Kernel Dump Reader
class-dump -- Examines Objective-C Runtime data for MachO files.
http://codethecode.com/projects/class-dump/
Summary of other useful tools:
http://osxbook.com/book/bonus/ancient/whatismacosx/tools.html
Other interesting links are most welcome. I can update the post if there are any interesting links.
Bit of Everything! Vulnerability Research, Reverse Engineering, Malware Analysis, Exploits etc...
Thursday, May 3, 2012
Tuesday, April 24, 2012
Certifications for IDS, IPS, FW, Web/Email Gateway Appliances and Endpoint Devices
This post might be helpful for Administrators, persons who are actively involved in making decisions to buy Perimeter/Endpoint security devices, CSO's etc.
This article explains about different security certifications for devices like VPN, Firewalls, Intrusion Detection and Prevention Systems (IDS/IPS), Email/Web Gateways etc.
This article explains about different security certifications for devices like VPN, Firewalls, Intrusion Detection and Prevention Systems (IDS/IPS), Email/Web Gateways etc.
BITS
BITS initially stood for "Banking Industry Technology Secretariat" which is not acronym anymore. BITS addresses emerging threats releted to cybersecurity, fraud reduction and infrastructure protection related to financial services.
Common Criteria (CC)
Common Criteria for Information Technology Security Evaluation is a framework for Computer Security Certification. Evaluations are performed in the US, UK, Australia,Canada, France and Germany.
CESG CCTM
From CSEG website "CESG protects the vital interests of the UK by providing policy and assistance on the security of communications and electronic data, working in partnership with industry and academia.The CESG Claims Tested Mark (CCTM) scheme provides a government quality mark for the public and private sectors based on accredited independent testing, designed to prove the functionality claims made by Vendors. Testing is carried out by commercial Test Houses".
EAL
Evaluation Assurance Level is a rating given to complete development of a product. Common Criteria lists seven levels with EAL1 being most basic and cheap and EAL 7 most stringent and expensive.
FIPS
Federal Information Processing Standards are US government computer security standards for Cryptographic modules.
ICSA Labs
ICSA Labs is part of Verizon, ICSA has been providing independent third party product testing say FW, IPS etc.
IPv6 Certification
Certifies that a product includes IPv6 mandatory core protocols and interoperability with other IPv6 products.
http://www.ipv6forum.com/ipv6_education/
http://en.wikipedia.org/wiki/DoD_IPv6_Product_Certification
http://www.ipv6forum.com/ipv6_education/
http://en.wikipedia.org/wiki/DoD_IPv6_Product_Certification
ISO/IEC 27001
International Organization for Standardization/International Electrotechnical Commission 27000 family of standards is an Information Security Management Systems standards.
ITSEC
Information Security Technology Evaluation Criteria is used to evaluate Products and Systems for Security weaknesses. ITSEC is followed in Australia, France, Germany and the UK.
http://www.ssi.gouv.fr/
http://www.ssi.gouv.fr/
NSS
Leading independent security products testing organization evaluating performance, security effectiveness and usability of Endpoint and Network Security (firewall, AV, browser, UTM, IDS/IPS, WAF, SWG, VPN, encryption, SIEM, VA/VM, virtualization) appliances.
Section 508
Section 508 of the US Rehabilitation Act of 1973 mandates that Federal agencies acquire products which enable people with disabilities to have access to information and data in a way that is comparable to the access and use experienced by people without disabilities.
TIC
Technology Integration Center is US Army's formal certification program.
TCSEC or Orange Book
Trusted Computer System Evaluation Criteria is a US governments DoD standards for computer security controls. Performed in US only.
http://www.fas.org/irp/nsa/rainbow/std001.htm
http://csrc.nist.gov/
http://www.fas.org/irp/nsa/rainbow/std001.htm
http://csrc.nist.gov/
VPNC
Virtual Private Network Consortium is the international trade association for manufacturers in the VPN market. VPNC does not create standards, it strongly supports the current and future IETF standards.
VPNC interoperability testing: VPNC issues logos for interoperability to VPNC member products which have successfully completed the testing. This testing is available to our IPsec and SSL members.
Anti Virus Certifications
AV's are certified by AV Comparatives, AV Test, Virus Bulletin, West Coast Labs, ICSA Labs, NSS Labs etc. Also AV's are tested against Wildlist.
http://www.av-comparatives.org/index.php
http://www.av-test.org/en/home/
http://www.virusbtn.com/index
http://www.wildlist.org/
http://www.opswat.com/
http://www.av-comparatives.org/index.php
http://www.av-test.org/en/home/
http://www.virusbtn.com/index
http://www.wildlist.org/
http://www.opswat.com/
Tools
Below tools may be used for testing different Perimeter Appliances or Endpoint product.
Below tools may be used for testing different Perimeter Appliances or Endpoint product.
nmap http://nmap.org/
Exploit DB http://www.exploit-db.com/
tcpreplay http://tcpreplay.synfin.net/
Metasploit http://www.metasploit.com/
CoreImpact http://www.coresecurity.com/
Canvas http://immunityinc.com/
Breaking Point http://www.breakingpointsystems.com/
MuDynamics http://www.mudynamics.com/
Stonesoft Predator http://stoneblog.stonesoft.com/tag/ips/
Please comment if I had missed out important Certification or Tool.
Following articles might be of your interest
http://darshanams.blogspot.in/2012/05/cain-and-abel-password-cracking.html
http://darshanams.blogspot.in/2011/09/portable-document-files.html
http://darshanams.blogspot.in/2010/09/forensics-1-extracting-image.html
http://darshanams.blogspot.in/2011/05/snort-logging-alerts-to-syslog-server.html
Following articles might be of your interest
http://darshanams.blogspot.in/2012/05/cain-and-abel-password-cracking.html
http://darshanams.blogspot.in/2011/09/portable-document-files.html
http://darshanams.blogspot.in/2010/09/forensics-1-extracting-image.html
http://darshanams.blogspot.in/2011/05/snort-logging-alerts-to-syslog-server.html
Tuesday, April 3, 2012
Supervisory Control And Data Acquisition (SCADA ) Terminology and Protocols
Useful Terminology, Acronyms and Links related to SCADA.
AC Alternate Current
CAN Control Area Networks
CIP Critical Infrastructure/Information Protection
Common Industrial Protocol
CRC Cyclic Redundancy Check
DC Direct Current
DCS Distributed Control system
DNP Distributed Network Protocol
GOMSFE Generic Object Models for Substation and Feeder Equipment
GOOSE Generic Object Oriented Substation Event
HCI Human-Computer Interface
HMI Human-Machine Interface
HVAC High Voltage Alternate Current
ICCP Inter-Control Center Communications Protocol
ICPS International Communications Protocol Standard
ICS Indistrial Control System
IEC International Electrochemical Commission
LAN Local Area Network
MTU Master Terminal Unit
NERC North American Electric Reliability Corporation
OLE Object Linking and Embedding
OPC OLE for Process Control
PLC Programmable Logic Controllers
PAC Programmable Automation Controllers
RTU Remote Terminal/Telemetry Units
SONET Synchronous Optical Networking
SDH Synchronous Digital Hierarchy
SCADA Supervisory Control And Data Acquisition
T& D Transmission and Distribution
UCA Universal Communications Adapter/ Utility Communications Architecture
SCADA Protocols
RTU's communicate with central SCADA station, other RTU's and networked devices.
CIP
CC-Link
DNP3
Ethernet/IP
ICCP
MODBUS(X)
Profibus/net
Fieldbus
BACnet
IEEE 60870 (IEC 60870-5-101 is an ICPS)
ASCII
S3/S5/S7
Other vendors like Allen Bradley, GE Fanuc, Siemens Sinaut, Mitsubishi, Omron, Toshiba, Westinghouse etc have proprietary SCADA Protocols
Useful Web Sites
http://en.wikipedia.org/wiki/SCADA
http://www.wurldtech.com/
http://www.plcs.net/contents.shtml
http://www.modbus.org/
http://www.cpni.gov.uk/advice/infosec/business-systems/scada/
http://www.dnp3.org/
http://www.iccp.org/
http://www.digitalbound.com/
Please leave a comment if I missed out an important acronym, protocol, link/site etc.
AC Alternate Current
CAN Control Area Networks
CIP Critical Infrastructure/Information Protection
Common Industrial Protocol
CRC Cyclic Redundancy Check
DC Direct Current
DCS Distributed Control system
DNP Distributed Network Protocol
GOMSFE Generic Object Models for Substation and Feeder Equipment
GOOSE Generic Object Oriented Substation Event
HCI Human-Computer Interface
HMI Human-Machine Interface
HVAC High Voltage Alternate Current
ICCP Inter-Control Center Communications Protocol
ICPS International Communications Protocol Standard
ICS Indistrial Control System
IEC International Electrochemical Commission
LAN Local Area Network
MTU Master Terminal Unit
NERC North American Electric Reliability Corporation
OLE Object Linking and Embedding
OPC OLE for Process Control
PLC Programmable Logic Controllers
PAC Programmable Automation Controllers
RTU Remote Terminal/Telemetry Units
SONET Synchronous Optical Networking
SDH Synchronous Digital Hierarchy
SCADA Supervisory Control And Data Acquisition
T& D Transmission and Distribution
UCA Universal Communications Adapter/ Utility Communications Architecture
SCADA Protocols
RTU's communicate with central SCADA station, other RTU's and networked devices.
CIP
CC-Link
DNP3
Ethernet/IP
ICCP
MODBUS(X)
Profibus/net
Fieldbus
BACnet
IEEE 60870 (IEC 60870-5-101 is an ICPS)
ASCII
S3/S5/S7
Other vendors like Allen Bradley, GE Fanuc, Siemens Sinaut, Mitsubishi, Omron, Toshiba, Westinghouse etc have proprietary SCADA Protocols
Useful Web Sites
http://en.wikipedia.org/wiki/SCADA
http://www.wurldtech.com/
http://www.plcs.net/contents.shtml
http://www.modbus.org/
http://www.cpni.gov.uk/advice/infosec/business-systems/scada/
http://www.dnp3.org/
http://www.iccp.org/
http://www.digitalbound.com/
Please leave a comment if I missed out an important acronym, protocol, link/site etc.
Thursday, February 23, 2012
URL's to Learn Malware Analysis, RCE
Following links will be pretty useful to learn Malware Analysis, Reverse Code Engineering(RCE) etc.
http://forum.tuts4you.com/index.php
http://www.woodmann.com/TiGa/idaseries.html
http://www.openrce.org/articles/
http://www.kernelmode.info/forum/index.php
http://crackmes.de/
Debugging Book
http://advancedwindowsdebugging.com/portal/portal_downloads.htm
Step 1: Learn C/C++/Delphi etc. You can't reverse engineer if you can't forward engineer.
Step 2: Learn x86 assembly - http://opensecuritytraining.info/IntroX86.html (includes videos)
Step 3: Learn x86 architecture - http://opensecuritytraining.info/IntermediateX86.html (includes videos)
Step 4: Learn PE binary format - http://opensecuritytraining.info/LifeOfBinaries.html (includes videos)
Step 5: Learn about IDA & general RE thought process - http://opensecuritytraining.info/IntroductionToReverseEngineering.html (video pending)
Step 6: Learn about some stealth malware techniques - http://opensecuritytraining.info/Rootkits.html (includes videos)
Step 7: Learn more by encouraging other people to submit their own class material - http://opensecuritytraining.info/Why.html
http://opensecuritytraining.info/Training.html
check it out: http://www.accessroot.com/arteam/site/news.php
another awesome tuts: http://portal.b-at-s.net/download.php
Some Sites
http://j00ru.vexillium.org/
http://www.analyze-v.com/
http://byteworm.com/
http://blog.zemana.com/2012/05/kaynaklar.html
http://fumalwareanalysis.blogspot.in/p/malware-analysis-tutorials-reverse.html
http://thelegendofrandom.com/blog/sample-page
http://beginners.re/
Live Malware Samples
http://www.offensivecomputing.net/
http://www.malwaredomainlist.com/
http://www.malc0de.org/database
http://www.virussign.com/index.html
http://www.vx.netlux.org/
http://openmalware.org/
http://virusshare.com/
https://twitter.com/MalwareChannel
http://www.vxheavens.com/
http://malshare.com/
https://avcaesar.malware.lu/
http://www.malwareblacklist.com/showMDL.php
https://malwr.com/
http://secuboxlabs.fr/
http://www.virusign.com/
http://virusshare.com/
Other useful sources
http://zeltser.com/combating-malicious-software/malware-sample-sources.html
http://reverseengineering.stackexchange.com/questions/206/where-can-i-as-an-individual-get-malware-samples-to-analyze
http://reverseengineering.stackexchange.com/questions/265/where-to-find-free-training-in-reverse-engineering
Suspicious files can be analyzed at
https://www.virustotal.com/
Malicious PDF Files
http://filex.jeek.org/archive_PDF.zip
Android Malware Samples
http://contagiodump.blogspot.in/
http://www.malgenomeproject.org/
For Mac OS X related resources, refer
http://darshanams.blogspot.in/2012/05/mac-os-x-infector-and-research.html
Tools
IDA/Olly/WinDBG
ImpREC
LordPE
Sysinternal's Tool Suite
Exeinfo PE/ PEiD
PEstudio
CFF Explorer
FileAlyzer
PEview
Let me know new sites, will update the same here :-) !!!
http://forum.tuts4you.com/index.php
http://www.woodmann.com/TiGa/idaseries.html
http://www.openrce.org/articles/
http://www.kernelmode.info/forum/index.php
http://crackmes.de/
Debugging Book
http://advancedwindowsdebugging.com/portal/portal_downloads.htm
Step 1: Learn C/C++/Delphi etc. You can't reverse engineer if you can't forward engineer.
Step 2: Learn x86 assembly - http://opensecuritytraining.info/IntroX86.html (includes videos)
Step 3: Learn x86 architecture - http://opensecuritytraining.info/IntermediateX86.html (includes videos)
Step 4: Learn PE binary format - http://opensecuritytraining.info/LifeOfBinaries.html (includes videos)
Step 5: Learn about IDA & general RE thought process - http://opensecuritytraining.info/IntroductionToReverseEngineering.html (video pending)
Step 6: Learn about some stealth malware techniques - http://opensecuritytraining.info/Rootkits.html (includes videos)
Step 7: Learn more by encouraging other people to submit their own class material - http://opensecuritytraining.info/Why.html
http://opensecuritytraining.info/Training.html
check it out: http://www.accessroot.com/arteam/site/news.php
another awesome tuts: http://portal.b-at-s.net/download.php
Some Sites
http://j00ru.vexillium.org/
http://www.analyze-v.com/
http://byteworm.com/
http://blog.zemana.com/2012/05/kaynaklar.html
http://fumalwareanalysis.blogspot.in/p/malware-analysis-tutorials-reverse.html
http://thelegendofrandom.com/blog/sample-page
http://beginners.re/
Live Malware Samples
http://www.offensivecomputing.net/
http://www.malwaredomainlist.com/
http://www.malc0de.org/database
http://www.virussign.com/index.html
http://www.vx.netlux.org/
http://openmalware.org/
http://virusshare.com/
https://twitter.com/MalwareChannel
http://www.vxheavens.com/
http://malshare.com/
https://avcaesar.malware.lu/
http://www.malwareblacklist.com/showMDL.php
https://malwr.com/
http://secuboxlabs.fr/
http://www.virusign.com/
http://virusshare.com/
Other useful sources
http://zeltser.com/combating-malicious-software/malware-sample-sources.html
http://reverseengineering.stackexchange.com/questions/206/where-can-i-as-an-individual-get-malware-samples-to-analyze
http://reverseengineering.stackexchange.com/questions/265/where-to-find-free-training-in-reverse-engineering
Suspicious files can be analyzed at
https://www.virustotal.com/
Malicious PDF Files
http://filex.jeek.org/archive_PDF.zip
Android Malware Samples
http://contagiodump.blogspot.in/
http://www.malgenomeproject.org/
For Mac OS X related resources, refer
http://darshanams.blogspot.in/2012/05/mac-os-x-infector-and-research.html
Tools
IDA/Olly/WinDBG
ImpREC
LordPE
Sysinternal's Tool Suite
Exeinfo PE/ PEiD
PEstudio
CFF Explorer
FileAlyzer
PEview
Let me know new sites, will update the same here :-) !!!
Tuesday, January 31, 2012
10 must-read Books for Developers
I liked the article so reposting it. Hope you will enjoy !!!
Blog site Stackoverflow posed an interesting question: "If you could go back in time and tell yourself to read a specific book at the beginning of your career as a developer, which book would it be?"
The accumulated wisdom of Stackoverflow readers posted over the past three years reads like a who's-who of the programming book industry, but several missing titles caught my eye.
Here's the Stackoverflow list:
"Code Complete" by Steve McConnell (2004)". Tackles every facet of programming, with tons of examples.
"The Pragmatic Programmer" by Andrew Hunt and David Thomas (1999). Concentrates on nitty-gritty real-world approaches to solving problems through code.
"Structure and Interpretation of Computer Programs" (2nd Edition, 1996) "by Harold Abelson, Gerald Sussman, and Julie Sussman. Concentrates on breaking big problems down into little ones, and ensuring the pieces come back to build the whole. The book is available under the Creative Commons Noncommercial License, for free on the Web.
"The C Programming Language" (2nd Edition, 1988) by Brian Kernighan and Dennis Richie. Not only offers the definitive guide to C, but shows you how to program in general. My personal choice for the most important first book.
"Introduction to Algorithms" by Thomas Cormen, Charles Leiserson, Ronald Rivest, and Clifford Stein (2009). Gives fast ways to solve complex problems, using the right data structures. Comprehensive and quintessentially useful.
"Refactoring: Improving the Design of Existing Code" by Martin Fowler, Kent Beck, John Brant, and William Opdyke (1999). Shows you how to rebend a programming pretzel, taking poorly designed code and turning it into something even humans can understand.
"Design Patterns: Elements of Reusable Object-Oriented Software" by Erich Gamma, Richard Helm, Ralph Johnson, and John Vlissides (1994). Serves as a reference of object oriented techniques. I'm surprised to see this on a list of "beginning of your career" books because it's much more suitable for people with a lot of OOP under their belts.
"The Mythical Man-Month" by Frederick Brooks (1995)". A management classic in the finest tradition. While not a programming book, a must-read for every developer.
"The Art of Computer Programming, Volume 1: Fundamental Algorithms" (3rd Edition, 1997) by Donald Knuth. For anyone with a mathematical predilection, Volumes 1 and 3 ("Sorting and Searching") stand out as true bibles of the industry. With Volumes 2 ("Seminumerical Algorithms") and 4A ("Combinatorial Algorithms, Enumeration and Backtracking") published, plans are still in place for Volume 4B ("Graph and Network Algorithms"), Volume 4C (maybe Volumes 4D and 4E, "Optimization and Recursion"), Volume 5 ("Syntactic Algorithms"), Volume 6 ("Context-Free Languages"), and Volume 7 ("Compiler Techniques").
"Compilers: Principles, Techniques and Tools" (2nd Edition, 2006) by Alfred Aho, Monica Lam, Ravi Sethi, and Jeffrey Ullman. The 1,000-page "dragon book" focuses on compilers, but in so doing covers topics every developer should understand.
What's missing? I mentioned Knuth's Volume 3, but several others pop out.
If you veer off the developer-centric track for a moment, many classics would broaden the horizons of any aspiring analyst. "Godel, Escher, Bach" by Douglas Hofstadter (1979) and "Zen and the Art of Motorcycle Maintenance" by Robert Pirsig (1974) always come up as manifestos of the developer class.
Sticking to developing, though, I'm surprised that these didn't make the top 10:
"Clean Code: A Handbook of Agile Software Craftsmanship" by Robert Martin (2008), emphasizes the importance of building code that can be digested, working through lots of real-world examples. It covers some of the same ground as Martin's earlier book, "Agile Software Development," and sets the stage for Martin's new book, "The Clean Coder."
"Code: The Hidden Language of Computer Hardware and Software" by Charles Petzold (2000) should be on the short list of everyone who's involved in the computer industry, developer or not. Petzold covers the basics -- number systems, high-level languages, comm protocols, hardware, GUIs -- and doesn't overwhelm with jargon.
For anyone destined to a corporate IT job, these three should be required reading:
"Patterns of Enterprise Application Architecture" by Martin Fowler (2002) helps corporate developers recognize common patterns in real-world problems, and digs into solution details for each pattern.
"Coders at Work" by Peter Seibel (2009) takes case histories -- which is to say, influential developers' real-life stories -- and weaves them into a powerful view of how 15 of the industry's best and brightest kicked some serious technical butt.
"Peopleware" (2nd edition. 1999)" by Tom DeMarco and Timothy Lister emphasizes the human element in software development and how to put together a project that actually gets work done.
I won't say that list is definitive, but if there's a nascent developer, developer wannabe, or burned-out developer seeking inspiration in your circle of friends, do them a favor and get them one of these books.
This story, "10 must-read books for developers" was originally published at InfoWorld.com. Get the first word on what the important tech news really means with the InfoWorld Tech Watch blog. For the latest developments in business technology news, follow InfoWorld.com on Twitter.
Web sites for Data Structures
http://www.geeksforgeeks.org/
http://www.topcoder.com/
http://openclassroom.stanford.edu/MainFolder/CoursePage.php?course=IntroToAlgorithms
http://courses.csail.mit.edu/6.006/spring11/notes.shtml
http://cslibrary.stanford.edu/
http://www.cs.sunysb.edu/~skiena/214/lectures/
http://courses.csail.mit.edu/6.851/spring12/lectures/
http://www.cs.berkeley.edu/~jrs/61b/
https://www.coursera.org/course/algs4partI
https://www.coursera.org/course/algs4partII
http://www.careercup.com/page?pid=algorithm-interview-questions
http://www.careercup.com/page?pid=data-structures-interview-questions
http://leetcode.com/
http://stackoverflow.com/questions/tagged/data-structures
http://stackoverflow.com/questions/tagged/algorithm
Happy Reading ;-) !!!
Wednesday, January 25, 2012
SOC Interview Questions 1
Below are the questions collected from friends who attended interviews related to Security Operations Center (SOC).
Difference between Probe vs Scan.
Difference between Security event and Security incident.
Wwhat is incident response (IR)?
How will you carry on Network forensics?
How will you carry on Memory forensics?
What is APT (Advanced Persistent Threat)?
What is IOC (related to APT)?
What is ROT13?
What is C2 (Command and Control)?
Difference between normal threat vs APT ?
Vulnerability vs Threat vs Exploit vs Risk.
Different Evasion techniques of Malware?
Different ways of compressing Malware?
What is threat agent?
Explain drive-by downloads.
Difference between Symmetric and Asymmetric encryption?
How do you collect image for Forensics without modifying the integrity of data on the PC/Laptop?
(http://darshanams.blogspot.com/2010/09/forensics-1-extracting-image.html)
Size of Registers in CPU? Are registers same for different CPU's?
How to change Linux root password?
Following articles might be of your interest
http://darshanams.blogspot.in/2012/05/cain-and-abel-password-cracking.html
http://darshanams.blogspot.in/2011/09/portable-document-files.html
http://darshanams.blogspot.in/2011/05/snort-logging-alerts-to-syslog-server.html
Will come up with more questions once I get in touch with other friends.
Difference between Probe vs Scan.
Difference between Security event and Security incident.
Wwhat is incident response (IR)?
How will you carry on Network forensics?
How will you carry on Memory forensics?
What is APT (Advanced Persistent Threat)?
What is IOC (related to APT)?
What is ROT13?
What is C2 (Command and Control)?
Difference between normal threat vs APT ?
Vulnerability vs Threat vs Exploit vs Risk.
Different Evasion techniques of Malware?
Different ways of compressing Malware?
What is threat agent?
Explain drive-by downloads.
Difference between Symmetric and Asymmetric encryption?
How do you collect image for Forensics without modifying the integrity of data on the PC/Laptop?
(http://darshanams.blogspot.com/2010/09/forensics-1-extracting-image.html)
Size of Registers in CPU? Are registers same for different CPU's?
How to change Linux root password?
Following articles might be of your interest
http://darshanams.blogspot.in/2012/05/cain-and-abel-password-cracking.html
http://darshanams.blogspot.in/2011/09/portable-document-files.html
http://darshanams.blogspot.in/2011/05/snort-logging-alerts-to-syslog-server.html
Will come up with more questions once I get in touch with other friends.
Subscribe to:
Posts (Atom)