SecureState Presents Exploit Training 101
Join us for a half day of FREE, hands-on technical training presentations facilitated by John Melvin of SecureState.The seminar will feature Melvin’s most popular presentations combined into one...
View ArticleCisco’s Security Strategy: Cisco Devices Becoming End-of-Sale & What...
Dealing with Cisco’s end-of-sale cycle is a stressful experience. This is an issue for companies maintaining PCI compliance. With a lot of companies, when their product reaches its end of sale cycle...
View ArticleBurp Suite Series: Using Burp Proxy with Client-Side Certificates and...
Burp’s functionality extends well beyond the usefulness of the tools included within the suite. One such way in which we have used Burp Suite here at SecureState is to use it as a HTTP Proxy for other...
View ArticleAnalysis of the Microsoft MS12-081 Vulnerability
On December 11, 2012 Microsoft released a Critical Security Bulletin describing a vulnerability in the Windows file handling component that could result in remote code execution. In typical Microsoft...
View ArticleStop Using Default Credentials!
For a recent engagement, SecureState performed an external penetration assessment. While the attack described in this blog was not particularly challenging, it was unique with the steps involved to...
View ArticleThreat Watch: Internet Explorer 6-8 Zero Day
Microsoft has recently issued a security advisory for a remote code execution vulnerability with Internet Explorer 6-8. As stated by Microsoft, this vulnerability may corrupt memory in a way that...
View ArticleDon’t Be Caught Playing the Fool (A Lesson in Why Change Control is Important)
Summary This is a real world story around the dangers of not following proper change control processes when placing new systems in production. In this blog I will discuss how one person’s actions could...
View ArticleIncident Response Testing: Your plan is in place – but does it work?
Attack and Penetration tests are required by many organizations for compliance reasons, as well as highly sought after to better understand how an attacker could exploit vulnerabilities on the systems....
View ArticleFinding Peter Gibbons’ Incentive
In the movie Office Space, Peter Gibbons finds himself in front of “The Bobs” talking about the lack of incentive for coming to work. It’s easy to point a finger at government inefficiency because of...
View ArticleDon’t Let Your Guard Down
The events that happened during the Boston Marathon yesterday were tragic, scary, and unnerving. As technology improves, the amount and quality of evidence and content that is produced during these...
View ArticleZuckerberg Pwned
A story broke earlier today regarding Mark Zuckerberg’s Facebook timeline getting hacked through a previously undisclosed vulnerability. Protect your Privacy when using Social Media The security...
View ArticleGet Hired
SecureState is a great place to work, we offer a fun and challenging environment, and we’re often asked what we look for in potential employees. It’s not a huge secret, we look for a lot of the same...
View ArticleBridging the Education Gap in Information Security (with Zombies)
The security industry is booming! The Bureau of Labor Statistics predicts 53% growth through 2018, but many young people aren’t interested in the field, or are simply unaware that cybersecurity can be...
View ArticleState of Security – December 2013
Every month, SecureState CEO Ken Stasiak addresses the hottest topics in information security, providing his unique spin on all the issues. Click the image Holiday “Critical Warning” Why...
View ArticleAnalysis of the Microsoft MS12-081 Vulnerability
On December 11, 2012 Microsoft released a Critical Security Bulletin describing a vulnerability in the Windows file handling component that could result in remote code execution. In typical Microsoft...
View ArticleBuilding an Enterprise Open Source Intelligence (OSINT) Program
“Information is power. Do you know what the Internet says about your company?” Back in 2009 I gave a well-received talk called “Enterprise Open Source Intelligence (OSINT) Gathering” to several...
View ArticleSecurity Advisory: OpenSSL Heartbeat Extension Vulnerability
Within the last few days, a critical vulnerability has been discovered within OpenSSL, dubbed “Heartbleed,” which can enable an attacker to extract information from the vulnerable server’s memory....
View ArticlePersistent Threat Management
If you don’t think your systems are compromised, you’re not looking hard enough. Persistent Threats are becoming more mainstream as threat actors are changing tactics from the quick exploitation of an...
View ArticleVerizon DBIR Report
Understanding the Verizon DBIR This blog is intended to give the reader a concise version of the Verizon Data Breach Investigations Report (DBIR), providing key takeaways and understanding of the...
View ArticleeBay Hacked, Change your eBay Account Password Immediately
Social media is abuzz today about eBay’s massive account breach. From news reports and press releases, this breach potentially affects 145 million of its customers which means many of you reading this...
View Article