Blog: SANS Penetration Testing

Blog: SANS Penetration Testing

Bypassing iOS Lock Screens: A Comprehensive Arsenal of Vulns

[Editor's Note: With last week's release of iOS 8, we enter a new era of security fixes and issues for Apple's flagship mobile operating system. But, even this latest version faces an issue that comes up regularly with iOS and other mobile operating systems: Lock Screen Bypass. In fact, there are dozens of different ways to bypass the Lock Screen on a device, each applicable to different versions and subversions of iOS. Thankfully, Raul Siles has inventoried a whole bunch of them in this article, providing a useful reference for penetration testers who need to show the risks associated with a given iOS feature or version number. Raul also offers tips for hardening iPhones and iPads against these kinds of attacks. Nifty stuff! --Ed.]

By Raul Siles

The iOS mobile platform has been subject to numerous lock screen bypass vulnerabilities across multiple versions. Although Apple strives to fix these vulnerabilities in various updates to iOS (

...

How Not to Fail at a Pen Test: Slides and Stream

Earlier this week, John Strand presented a fantastic webcast that was chock full of pen test tips. This post contains the slides as well as a link to the streaming slides and webcast audio.

Here's the description of the talk:

In this presentation, John and Ed will cover some key components that many penetration tests lack, including why it is important to get caught, why it is important to learn from real attackers, and how to gain access to organizations without sending a single exploit.

One of my favorite slides in the presentation is John's concluding Code of Ethics. Click on the image below to download all of John's slides.

Demanding MOAR From Your Vulnerability Assessments and Pen Tests - Slides and Link

A few weeks ago, I did a presentation on Demanding MOAR from Your Vulnerability Assessments & Pen Tests. I'd like to share the slides with you now. The presentation is full of tips, some easy and others more complex, for providing extra value in vuln assessment and pen test work.

Here's the official description of the talk:

You pay good money for your vulnerability assessments and penetration tests, right? But are you getting real business value from these projects? Do you ever get the sense that your assessors and pen testers are just phoning it in, checking off boxes, and not really properly helping you improve your security stance? In this lively presentation, Ed Skoudis will provide hugely valuable tips for getting the maximum business value out of your vulnerability assessments and pen tests. With specific recommendations for people procuring such projects as well as for testers themselves, this webcast is chock full of insights for effective scoping,

...

Winner Announcement: SANS Pen Test Hackfest Twitter Contest

Over the past couple of weeks, we've been running the SANS Pen Test Hackfest Twitter Contest. I'm delighted to announce the winner. The contest was simple and fun -- just submit a picture of yourself via Twitter with SANS coins, SANS books, or other SANS shwag, and we'll choose a winner at ramdom. We've had some great entries... you guys are a creative group! If you want to see them all, just do a Twitter search for the hashtag #SANSHackfest.

The winner will receive free entry to the 2-Day Summit associated with our November 13 through 20 Pen Test Hackfest training event in Washington DC. We throw everything we've got into this extra special event, including:


  • Two days of amazing, in-depth talks by leading minds of the industry, including the authors of some of the best pen test tools on the planet, including SET,
...

SANS Pen Test Hackfest Twitter Contest

We're delighted to announce a new Twitter-based contest here with a fantastic prize. And, participating in this one is really easy. Check it out.

On November 13 through 20, SANS will be running our second annual Pen Test Hackfest training eventin Washington DC. We throw everything we've got into this extra special event, including:

...