Exploiting HP SiteScope From Zero to Compromise!

Introduction While on an assessment I came across HP SiteScope installed on a server. Having never heard of SiteScope before I started with a Google search. According to Wikipedia, HPE SiteScope is agentless monitoring software focused on monitoring the availability...

Harvesting Passwords from Aruba Configs

UPDATE: I actually received a very nice email from an Aruba Security Architect regarding this post. They are actively engaged in making their products more secure and addressing these issues. Could not ask for a better response from a vendor....

Twitter features I actually want

This is a somewhat off topic post about Twitter. Twitter is where the InfoSec community currently “lives”. If you’re trying to get into this field then one of the first easy things you can do is get a Twitter account...

Yes, someone will look there – EventSentry Info Exposure – CVE-2015-2911

Intro Information disclosure vulnerabilities are not the most exciting bugs in the business, and some bug hunters don’t even consider them worthy of note. I’m not going to weigh into that debate, but we recently came across such a bug...

Know your tools – CVE-2015-2342 IOC and Metasploit

[This is a cross post from my article on graytier.com published on 18 Jan 16] Intro As penetration testers and security professionals we now have a myriad of tools at our disposal. It seems like everyday a new product, program,...