Trend Micro published a report last week on a spear-phishing emails campaign that contain a ma ...(more)...
We're looking for any info or packets that target port 51616. After witnessing a sp ...(more)...
I put together a simple .deb package to install our DShield iptables client on Ubuntu ...(more)...
----------- Guy Bruneau ISC StormCast for Monday, May 20th 2013 http://isc.sans.edu/podcastdetail.html?id=3317, (Mon, May 20th) Mon, 20 May 2013 01:37:30 GMT
...(more)...
Currently, many public web sites that allow access via IPv6 do so via proxies. This is seen as ...(more)...
Like with .biz, I sometimes have the impression that ...(more)...
By any computer I mean: let's say I do not have my own device and I have to check my email at a friend's house on their computer. Are there any managers out there that will allow me to retrieve my passes as a one off thing, and without having to download any software etc.
Thanks for your help.
We are writing as the first week of the second installment of the Month of Volatility Plugins is now posted. Volatility 2.3 is currently in beta, and the blog posts are focusing on new features in this version. This week's posts discussed a number of new address spaces we have added to support new hardware architectures and file formats.
The first one is the MachO address space used to support Mac Memory Reader:
http://volatility-labs.blogspot.com/2013/05/movp-ii-11-mach-o-address-space.html
The second is an address space used to support VirtualBox:
http://volatility-labs.blogspot.com/2013/05/movp-ii-12-virtualbox-elf64-core-dumps.html
The third address space allows for analysis of VMware snapshot files (.vmss and .vmsn):
http://volatility-labs.blogspot.com/2013/05/movp-ii-13-vmware-snapshot-and-saved.html
The fourth address space supports the hpak format of the HBGary Fast Dump acquisition tool:
http://volatility-labs.blogspot.com/2013/05/movp-ii-14-new-hpak-address-space.html
The final address space discussed adds support for the ARM architecture. This is leveraged by Volatility's Android support:
http://volatility-labs.blogspot.com/2013/05/movp-ii-15-arm-address-space-volatility.html
We hope you enjoy the posts, and the second installment of posts will begin tomorrow and cover a number of new plugins to help analyzing Windows samples.
If you have any questions or comments please comment on an individual blog post or leave a comment here.









