Home

Internet Based Video Entertainment For Your Pleasure - Part 3 - FIN

As much as we would like to continue posting videos for your learning pleasure, we have reached the 3rd and final part of our adventure.

Here are the final 4 videos to gorge on....

In today's release:

Offensive Technology: Launch Nuclear Missiles
With A Whistle by Adam Boileau(Hamilton)

Forensic Computing by Campbell Mackenzie (Auckland)

Internet Based Video Entertainment For Your Pleasure - Part 2 - Video Harder

Continuing our video-tastic adventure, here is part 2 of the much anticipated in2securITy video release extravaganza!

Here are another 5 videos to tickle your learning bits....

In today's release:

Security Engineering by Simon Howard (Wellington)

Network Defence by Joh Pirie-Clarke (Hamilton)

Internet Based Video Entertainment For Your Pleasure - Part 1

Hello Possums

Remember us? Your friendly in2securITy team?

Thought we had been eaten by bears or perhaps gotten lost on the way back from the last tour event?

Never fear - we have returned.

After 2 weeks of video editing and fiddling with the voodoo that is YouTube we come bearing gifts.

All of the videos from the in2securITy national tour have been edited, uploaded and tweaked for your internet viewing pleasure.

While I know you would all like to gorge yourselves on bad camera work and questionable sound quality - we are going to spread this out.

Input Validation -- Black & White

This is an exploration of two approaches to input validation, black-listing and white-listing. It follows on from my now ancient first post
Validation -- Crunchy on the Outside

What is input anyway?

We can hardly discuss input validation techniques without understanding what input is, so here goes. At its most basic, input is a fluctuating electrical signal…. Hang on, our attackers don't control that, we write software.

[Event] In2securITy Tour - Auckland - 22/09/2012

The time has come ladies and gentlemen of Auckland for you to host and attend the final stop of the in2securITy national tour.

So without further ado, here are the much anticipated details of this event.

Auckland - Microsoft Building, Viaduct Harbour
Saturday 22nd September 2012 in2securITy is in you!

The Schedule and Talks

A printable version of the schedule (including speaker biographies and talk descriptions) can be downloaded here.

Radio coverage from Radio New Zealand

Just a quickie to say thank you to Radio New Zealand for covering in2securITy today on their New Technology programme.

If you want to check out the piece, an mp3 is available here. In2securITy is covered from 09.35 onwards!

Thanks Donald!

Seen/heard in2securITy mentioned somewhere?

Drop us an email with the time and place. The team are always keen to keep track of all publicity and feedback!

[Whitebox Vuln Research] Part 1 - Design Vulnerabilities

This post kicks off the first in a quick series about whitebox vulnerability research. For our purposes, whitebox refers to situations where vulnerabilities are identified by reviewing supplied architecture, system design, documentation or source code.

Design Vulnerabilities

As pointed out in The Art of Software Security Assessment:

"A design vulnerability is a problem that arises from a fundamental mistake or oversight in the software’s design"

[Event] In2securITy Tour - Wellington - 08/09/2012

The time has come ladies and gentlemen of Wellington for you to host and attend the next stop of the in2securITy national tour.

So without further ado, here are the much anticipated details of this event.

Wellington - Victoria University of Wellington
Saturday 8th September 2012 in2securITy is in you!

If you haven't signed up but want to do so - there is still time. Just visit the signup page (only 11 seats remaining) (http://www.regonline.com/in2securityisad12wellington).

The Schedule and Talks

[Hack-Along] Stripe Web CTF - Level Three - [SPOILERS]

Welcome back to our continued walkthrough of the Stripe Web CTF!

Warning

The Stripe CTF will finish TONIGHT (29/08/2012) at 1am NZ time. If you want to finish up and earn that awesome Stripe t-shirt... Get going! (You didn't think we would give you all the solutions in advance of the close down did you?)

Once again, only click read more if you want to see spoilers... you have been warned.

Tip

If you want some hints, rather than spoilers take a look at the OWASP sql injection page and the sqli command reference.

Pages