Resources: Whitepapers


White Papers are an excellent source for information gathering, problem-solving and learning. Below is a list of White Papers written by penetration testing practitioners seeking certification. SANS attempts to ensure the accuracy of information, but papers are published "as is".

Errors or inconsistencies may exist or may be introduced over time. If you suspect a serious error, please contact

Featured Papers

This featured paper includes some really useful techniques that penetration testers should master. Read it, learn it, and live it, as you extend your skills.

Penetration Testing Whitepapers
Paper Author Certification
Discovering Rogue Wireless Access Points Using Kismet and Disposable Hardware Pesce, Larry GAWN
Wireless Networks and the Windows Registry - Just where has your computer been? Risto, Jonathan GAWN
DICE and MUD Protocols for Securing IoT Devices Ayar, Muhammed GAWN
rLogin Buffer Overflow Vulnerability - Solaris Corredor, Juan GCIH
Lotus Notes Penetration Rademacher, Karl GCIH
Local Privilege Escalation in Solaris 8 and Solaris 9 via Buffer Overflow in passwd(1) McAdams, Shaun GCIH
WU-FTPD Heap Corruption Vulnerability - HONORS Allen, Jennifer GCIH
Incident Handler Case File: A New Twist to Social Engineering Hawkins, Ray GCIH
FTP Security and the WU-FTP File Globbing Heap Corruption Vulnerability Webb, Warwick GCIH
Windows Internet Naming Service - An Exploit Waiting to Happen Berger, Jeremy GCIH
Phone Phreaking and Social Engineering Tuey, Richard GCIH
Valentine's Surprise Firedragging in Action de Nie, Paula GCIH
What to do when you break WEP Wireless Security and the LAN Poer, Geoffrey GCIH
IBM AIX invscout Local Command Execution Vulnerability - HONORS Horwath, Jim GCIH
Incident Handling Without Guidelines McKellar, Neil GCIH
An Analysis of the Remote Code Execution Vulnerability as Described in Microsoft's MS05-002 Security Bulletin Rose, Jerome GCIH
Sub Seven: A Risk to Your Internet Security Ostrowski, Paul GCIH
0day targeted malware attack Villatte, Nicolas GCIH
Simple Network Management Protocol: Now More than a "Default" Vulnerability Fluharty, Daniel GCIH
Identity Theft Made Easy Huber, Eric GCIH
How to Gain Control of a Windows 2000 Server Using the In-Process Table Privilege Escalation Exploit Stidham, Jonathan GCIH
Exploiting BlackICE When a Security Product has a Security Flaw Gara-Tarnoczi, Peter GCIH
IIS 5 In-Process Table Privilege Escalation Vulnerability Fatnani, Kishin GCIH
Utilizing "AutoRuns" To Catch Malware McMillan, Jim GCIH
Tracking the Back Orifice Trojan on a University Network Knudsen, Kent GCIH
Network Covert Channels: Subversive Secrecy Sbrusch, Raymond GCIH
Sun snmpXdmi Overflow Miller, Kevin GCIH
Effectiveness of Antivirus in Detecting Metasploit Payloads Baggett, Mark GCIH
False Alarm...Or Was It? Lessons Learned from a Badly Handled Incident Graesser Williams, Dana GCIH
Cisco Security Agent and Incident Handling Farnham, Greg GCIH
The t0rn Rootkit Craveiro, Paulo GCIH
The December Storm of WMF: Preparation, Identification, and Containment of Exploits Voorhees, James GCIH
FTP Port 21 "Friend or Foe" Support for the Cyber Defense Initiative Karrick, Stephen GCIH
DNS Sinkhole Bruneau, Guy GCIH
Netscape Enterprise Server Denial of Service Exploit Smith, Tony GCIH
Inside-Out Vulnerabilities, Reverse Shells Hammer, Richard GCIH
Widespread SNMP Vulnerabilities Brooks, Greg GCIH
Pros and Cons of using Linux and Windows Live CDs in Incident Handling and Forensics Smith, Ricky GCIH
Identifying and Handling a PHP Exploit Edelson, Eve GCIH
Expanding Response: Deeper Analysis for Incident Handlers McRee, Russ GCIH
KaZaA Media Desktop Virus: W32/kwbot Will, Rita GCIH
Multi-Tool DVD Sets: An important addition to the Incident Handler/ Pen Tester's toolkit Bandukwala, Jamal GCIH
Linux NTPD Buffer Overflow Stadler, Philipp GCIH
Stack Based Overflows: Detect & Exploit Christiansen, Morton GCIH
Windows Shell Document Viewer shdocvw.dll Feature or Trojan Horse? Fenwick, Wynn GCIH
An Incident Handling Process for Small and Medium Businesses Pokladnik, Mason GCIH
Support for the Cyber Defense Initiative Fresen, Lars GCIH
Baselines and Incident Handling Christianson, Chris GCIH
Apache Web Server Chunk Handling Apache-nosejob.c Sarrazyn, Dieter GCIH
Preventing Incidents with a Hardened Web Browser Crowley, Chris GCIH
SQL Snake and Other Port 1433 Threats In Support of the Cyber Defense Initiative Short, Christopher GCIH
Computer Security Education The Tool for Today Burke, Ian GCIH
Port 443 and Openssl-too-open Lee, Chia-Ling GCIH
Virtual Rapid Response Systems Mohan, Chris GCIH
System infiltration through Mercur Mail Server 4.2 Ben Alluch Ben Amar, Jamil GCIH
An approach to the ultimate in-depth security event management framework Pachis, Nicolas GCIH
Solaris in.lpd Remote Command Execution Vulnerability Seah, Meng Kuang GCIH
Winquisitor: Windows Information Gathering Tool Cardosa, Michael GCIH
Port 1433 Vulnerability: Unchecked Buffer in Password Encryption Procedure Bryner, Jeff GCIH
Covering the Tracks on Mac OS X Leopard Scott, Charles GCIH
SMTP Loop Moderate Denial of Service: InterScan VirusWall NT & Lotus Domino Environment Roberts, Brian GCIH
Espionage - Utilizing Web 2.0, SSH Tunneling and a Trusted Insider Abdel-Aziz, Ahmed GCIH
SMBdie'em All - Kill That Server Kirby, Craig GCIH
Document Metadata, the Silent Killer... Pesce, Larry GCIH
Nimda - Surviving the Hydra Schmelzel, Paul GCIH
Using OSSEC with NETinVM Allen, Jon Mark GCIH
Attack of Slammer worm - A practical case study Huang, Dongmei GCIH
Using GUPI to Create A Null Box Comella, Robert GCIH
Network Printers: Whose friend are they? Hutcheson, Lorna GCIH
The SirEG Toolkit Begin, Francois GCIH
SQL Server Resolution Service Exploit in Action Hoover, James GCIH
A Guide to Encrypted Storage Incident Handling Shanks, Wylie GCIH
Traveling Through the OpenSSL Door Murphy, Keven GCIH
Investigative Tree Models Caudle, Rodney GCIH
The Microsoft IIS 5.0 Internet Printing ISAPI Extension Buffer Overflow Clemenson, Christopher GCIH
IOScat - a Port of Netcat's TCP functions to Cisco IOS Vandenbrink, Robert GCIH
SQL Slammer Worm Hayden, Chris GCIH
PCI DSS and Incident Handling: What is required before, during and after an incident Moldes, Christian GCIH
Incident Analysis in a Mid-Sized Company Garvin, Pete GCIH
Visualizing the Hosting Patterns of Modern Cybercriminals Hunt, Drew GCIH
Hijacked Server Serves Up Foreign Bootlegged Pornography Meyer, Russell GCIH
IOSTrojan: Who really owns your router? Santander Pelaez, Manuel Humberto GCIH
First Response: An incident handling team learns a few lessons the hard way Cragg, David GCIH
Pass-the-hash attacks: Tools and Mitigation Ewaida, Bashar GCIH
A Management Guide to Penetration Testing Shinberg, David GCIH
Animal Farm: Protection From Client-side Attacks by Rendering Content With Python and Squid. OConnor, Terrence GCIH
0x333hate.c: Samba Remote Root Exploit Embrich, Mark GCIH
GIAC GCIH Assignment - Pass Harrison, Daniel GCIH
SQL Slammer and Other UDP Port 1434 Threats In support of the Cyber Defense Initiative Ray, Edward GCIH
An Overview Of The Casper RFI Bot O'Connor, Dan GCIH
Back-Door'ed by the Slammer Hally, John GCIH
SMTP - Always a victim of a good time Lock, James GCIH
A Weak Password And A Windows Rootkit: A Recipe For Trouble Ives, John GCIH
Real World ARP Spoofing Siles, Raul GCIH
A J0k3r Takes Over Larrieu, Heather GCIH
Penetration Testing of a Secure Network Pakala, Sangita GCIH
Breaking Windows 2000 Passwords via LDAP Password Crackers Hamby, Charles GCIH
My First Incident Handling Experience Kohli, Karmendra GCIH
The Tactical Use of Rainbow Crack to Exploit Windows Authentication in a Hybrid Physical-Electronic Attack Mahurin, Mike GCIH
Relative Shell Path Vulnerability Evans, Earl GCIH
Hacker Techniques, Exploits, and Incident Handling Brooker, Denis GCIH
BIND 8.2 NXT Remote Buffer Overflow Exploit Mcmahon, Robert GCIH
Session stealing with WebMin Murdoch, Don GCIH
Buffer overflow in BIND 8.2 via NXT records Talianek, Chris GCIH
Windows Media Services NSIISLOG.DLL Remote Buffer Overflow Smith, Steve GCIH
Local Exploit: dtprintinfo for Solaris 2.6 and 7 Sipes, Steven GCIH
A Study of the o_wks.c Exploit for MS03-049 Arnoth, Eric GCIH
Dsniff and Switched Network Switching Bowers, Brad GCIH
Combating the Nachia Worm in Enterprise Environments Johnson, Brad GCIH
ICQ URL Remote Exploitable Buffer Overflow de Beaupre, Adrien GCIH
An Attacker On RPC Compromised Remote VPN Host Runs Arbitrary Code on Microsoft Exchange Server 2000 Ho, Wai-Kit GCIH
Incident Illustration - Corporate Compromise Hall, Russell GCIH
Catch the culprit! Perez, David GCIH
Cisco IOS Type 7 Password Vulnerability Massey, Lee GCIH
The enemy within: Handling the Insider Threat posed by Shatter Attacks Layton, Meg GCIH
Incident Illustration - Missing Files White, Scott GCIH
All Your Base Are Belong To Someone Else: An Analysis Of The Windows Messenger Service Buffer Overflow Vulnerability Hewitt, Peter GCIH
Testing Web Applications for Malicious Input Attack Vulnerabilities Grill, Robert GCIH
Microsoft RPC-DCOM Buffer Overflow Attack using Dcom.c Farrington, Dean GCIH
Jolt2 or "IP Fragment Re-assembly Beciragic, Jasmir GCIH
Stay Alert While Browsing the Internet LaValley, Jim GCIH
The Not-So Vicious Attacker Mossholder, Matt GCIH
Bad ESMTP Verb Usage Equals Bad Times for Exchange Smith, Aaron GCIH
Incident Illustration - Mstream Gallo, Kenneth GCIH
A Buffer Overflow Exploit Against the DameWare Remote Control Software Strubinger, Ray GCIH
Incident Illustration - Firewall Attack Reed, Bill GCIH
Robbing the Bank with ITS/MHTML Protocol Handler Balcik, James GCIH
Ramen Worm Ives, Millie GCIH
Real Network's Remote Server Remote Root Exploit Lastor, Michael GCIH
Incident Illustration - HTTP Services Vulnerabilities Modelo Howard, Gaspar GCIH
Discovering a Local SUID Exploit Pike, Jeff GCIH
Anna Kournikova Worm Ashworth, Robert GCIH
Eradicating the Masses & Round 1 with Phatbot? Fulton, Lora GCIH
Open Shares Vulnerability Hill, Siegfried GCIH
A Two Stage Attack Using One-Way Shellcode Mathezer, Stephen GCIH
Incident Illustration: Unauthorized LAN Access Szczepankiewicz, Peter GCIH
Phising Attack in Organizations: Incident Handlers Perspective Ong, Leonard GCIH
The Search for "Kozirog" Weaver, Greg GCIH
A Heap o' Trouble: Heap-based flag insertion buffer overflow in CVS Conrad, Eric GCIH
Illustration of VS.SST@mm Virus Incident Smith, Kevin GCIH
Incident Report for a Rootkit attack on a Fedora workstation Norman, Bonita GCIH
IP Masquerading Vulnerability for Linux 2.2.x - CVE-2000-0289 Baccam, Tanya GCIH
BruteSSH2 - 21st Century War Dialer Thompson, Bill GCIH
The fascinating tale of a lame hacker, a Linux Box, and how I received permission to deploy my IDS Markham, George GCIH
PHP-Nuke: From SQL Injection to System Compromise Paynter, Eric GCIH
Automated Execution of Arbitrary Code Using Forged MIME Headers in Microsoft Internet Explorer Winters, Scott GCIH
Exploiting the LSASS Buffer Overflow Wohlberg, Jon GCIH
MS IIS CGI Filename Decode Error Vulnerability Shenk, Jerry GCIH
DreamFTP - The Nightmare Begins! Sorensen, Robert Peter GCIH
Wireless LAN Honeypots to Catch IEEE 802.11 Intrusions Mitchell, Gordon GCIH
phpMyAdmin 2.5.7 - Input Validation Vulnerability Thurston, Tracy GCIH
Reverse Engineering Srvcp.exe Zeltser, Lenny GCIH
The Cisco IPv4 Blocked Interface Exploit Johnson, Cortez GCIH
FreeBSD 4.x local root vulnerability -- exec() of shared signal handler Durkee, Ralph GCIH
Exploiting the Microsoft Internet Explorer Malformed IFRAME Vulnerability Tu, Alan GCIH
Once Bitten Twice Sly - Common Exploits Fueled by Common Mishap Melvin, John GCIH
Exploiting Internet Explorer via IFRAME Becher, Jim GCIH
Revisiting the Code Red Worm White, Ravila GCIH
A Picture is Worth 500 Malicious Dwords Hall, Timothy GCIH
Mutated Code Kopczynski, Tyson GCIH
Freezing Icecast in its Tracks McLaren, Jared GCIH
M@STER@GENTS: Masters of "SPAM" Ashland, Joanne GCIH
Remote Exploitation of Icecast 2.0.1 Server Pittner, Jakub GCIH
Exploiting Vulnerabilities in Squirrelmail Bong, Kevin GCIH
Fun with Batch Files: The Muma Worm Mackey, David GCIH
Neptune.c the Birth of SYN Flood Attacks Cardinal, Steven GCIH
Analysis and Reporting improvements with Notebooks Knowles, Ben GCIH
Applying Data Analytics on Vulnerability Data Dhinwa, Yogesh GCIH
Enterprise Survival Guide for Ransomware Attacks Mehmood, Shafqat GCIH
Success Rates for Client Side Vulnerabilities Risto, Jonathan GCIH
Incident Handling Preparation: Learning Normal with the Kansa PowerShell Incident Response Framework Simsay, Jason GCIH
Demystifying Malware Traffic Saxena, Sourabh GCIH
Detecting Incidents Using McAfee Products Andrei, Lucian GCIH
The Information We Seek Ramos, Jose GCIH
BGP Hijinks and Hijacks - Incident Response When Your Backbone Is Your Enemy Collyer, Tim GCIH
Node Router Sensors: What just happened? Cary, Kim GCIH
Attack and Defend: Linux Privilege Escalation Techniques of 2016 Long II, Michael GCIH
Anomaly Detection, Alerting, and Incident Response for Containers Borhani, Roozbeh GCIH
Auto-Nuke It from Orbit: A Framework for Critical Security Control Automation Hainly, Jeremiah GCIH
Identifying Vulnerable Network Protocols with PowerShell Fletcher, David GCIH
Hunting through Log Data with Excel Lalla, Greg GCIH
Offensive Intrusion Analysis: Uncovering Insiders with Threat Hunting and Active Defense Hosburgh, Matthew GCIH
A Practical Example of Incident Response to a Network Based Attack Fraser, Gordon GCIH
The Conductor Role in Security Automation and Orchestration Cakir, Murat GCIH
Creating a Logging Infrastructure Todd, Brian GCIH
BYOD Security Implementation for Small Organizations Simmons, Raphael GCIH
High Assurance File Filtering, It's Not Magic Gould, Adam GCIH
Learning Cryptography by Doing It Wrong: Cryptanalysis of the Vigenere Cipher Druin, Jeremy GCIH
NOC/SOC Integration: Opportunities for Increased Efficiency in Incident Response within Cyber-Security Hernandez, Nelson GCIH
Agile Security Patching Hoehl, Michael GCIH
Extracting Timely Sign-in Data from Office 365 Logs Lucas, Mark GCIH
Content Security Policy in Practice Palathuruthil, Varghese GCIH
Times Change and Your Training Data Should Too: The Effect of Training Data Recency on Twitter Classifiers O'Grady, Ryan GCIH
All-Seeing Eye or Blind Man? Understanding the Linux Kernel Auditing System Kennel, David GCIH
Hardening OpenShift Containers to complement Incident Handling Holland, Kurtis GCIH
A Swipe and a Tap: Does Marketing Easier 2FA Increase Adoption? Ackerman, Preston GCIH
Don't Knock Bro Nafziger, Brian GCIH
Template Injection Attacks - Bypassing Security Controls by Living off the Land Wiltse, Brian GCIH
Cyber Threats to the Bioengineering Supply Chain Nawrocki, Scott GCIH
Security Monitoring of Windows Containers Di Giorgio, Peter GCIH
Finding Secrets in Source Code the DevOps Way Marlow, Phillip GCIH
Mobile A/V: Is it worth it? Dorris, Nicholas GCIH
Defending with Graphs: Create a Graph Data Map to Visualize Pivot Paths Fahey, Brianne GCIH
Container-Based Networks: Lowering the TCO of the Modern Cyber Range Scarbrough, Bryan GCIH
Pass-the-Hash in Windows 10 Cyra, Lukasz GCIH
The Value of Contemporaneous Notes and Why They Are a Requirement for Security Professionals Enoka, Seth GCIH
BITS Forensics Nardella, Roberto GCIH
Securing the Supply Chain - A Hybrid Approach to Effective SCRM Policies and Procedures Carbonaro, Daniel GCIH
Defense in Depth for a Small Office/Home Office Melton, Gregory GCIH
Are You Hitting the Mark with DMARC? Mavretich, Robert J. GCIH
60870-5-104 protocol snort rule customization Aron, Adrian GCIH
Incident Response in a Security Operation Center Higgason, Josh GCIH
Creating Your Own SIEM and Incident Response Toolkit Using Open Source Tools Sweeny, Jonny GCIH
You've Had the Power All Along: Process Forensics With Native Tools McAfee, Trevor GCIH
Practical OSSEC Robertson, Chad GCIH
How to use Kape for Fast and Flexible Incident Response Davis, John GCIH
Responding to Zero Day Threats Kliarsky, Adam GCIH
Security Incident Handling in High Availability Environments Kibirkstis, Algis GCIH
Securely deploying Android devices Alonso-Parrizas, Angel GCIH
Remote Access Point/IDS Kee, Jared GCIH
Shedding Light on Security Incidents Using Network Flows Gennuso, Kevin GCIH
Covert Channels Over Social Networks Selvi, Jose GCIH
Attributes of Malicious Files Yonts, Joel GCIH
Incident Handling in the Healthcare Cloud: Liquid Data and the Need for Adaptive Patient Consent Management Filkins, Barbara GCIH
InfiniBand Fabric and Userland Attacks Warren, Aron GCIH
Web Log Analysis and Defense with Mod-Rewrite Wanner, Rick GCIH
Event Monitoring and Incident Response Boyle, Ryan GCIH
Detecting Security Incidents Using Windows Workstation Event Logs Anthony, Russell GCIH
Using DomainKeys Identified Mail (DKIM) to Protect your Email Reputation Murphy, Christopher GCIH
SMS, iMessage and FaceTime security Khalil, George GCIH
Talking Out Both Sides of Your Mouth: Streamlining Communication via Metaphor More, Josh GCIH
Home Field Advantage: Employing Active Detection Techniques Jackson, Benjamin GCIH
War Pi Christie, Scott GCIH
Using Open Source Reconnaissance Tools for Business Partner Vulnerability Assessment Young, Sue GCIH
Incident Handling Annual Testing and Training Holland, Kurtis GCIH
Securing Aviation Avionics Panet-Raymond, Marc GCIH
Digital Certificate Revocation Vandeven, Sally GCIH
Are there novel ways to mitigate credential theft attacks in Windows? Foster, James GCIH
Small devices needs a large Firewall Mastad, Paul GCIH
H.O.T. | Security Rocha, Luis GCIH
A Qradar Log Source Extension Walkthrough Stanton, Michael GCIH
An Analysis of Meterpreter during Post-Exploitation Wadner, Kiel GCIH
Secure Design with Exploit Infusion Yew, Wen Chinn GCIH
Cyber Breach Coaching Hoehl, Michael GCIH
Automated Defense - Using Threat Intelligence to Augment Poputa-Clean, Paul GCIH
Detecting Crypto Currency Mining in Corporate Environments D'Herdt, Jan GCIH
The Integration of Information Security to FDA and GAMP 5 Validation Processes Young, Jason GCIH
Correctly Implementing Forward Secrecy Schum, Chris GCIH
Practical El Jefe Vedaa, Charles GCIH
Using Software Defined Radio to attack "Smart Home" systems Eichelberger, Florian GCIH
Knitting SOCs Imbert, Courtney GCIH
Using windows crash dumps for remote incident identification Chua, Zong Fu GCIH
Accessing the inaccessible: Incident investigation in a world of embedded devices Jodoin, Eric GCIH
Psychology and the hacker - Psychological Incident Handling Atkinson, Sean GCIH
Forensic Analysis On Android: A Practical Case Alonso-Parrizas, Angel GMOB
Bypassing Malware Defenses Christiansen, Morton GPEN
One Admin's Documentation is their Hacker's Pentest Vandenbrink, Robert GPEN
Penetration Testing in the Financial Services Industry Olson, Christopher GPEN
Malicious Android Applications: Risks and Exploitation Boutet, Joany GPEN
Solution Architecture for Cyber Deterrence Mowbray, Thomas GPEN
iPhone Backup Files. A Penetration Tester's Treasure Manners, Darren GPEN
Post Exploitation using Metasploit pivot & port forward Dodd, David GPEN
PDF Obfuscation - A Primer Robertson, Chad GPEN
iPwn Apps: Pentesting iOS Applications Kliarsky, Adam GPEN
Let's face it, you are probably compromised. What next? Thyer, Jonathan GPEN
AIX for penetration testers Panczel, Zoltan GPEN
Penetration Testing: Alternative to Password Cracking Catanoi, Maxim GPEN
Cracking Active Directory Passwords or "How to Cook AD Crack" Boller, Martin GPEN
Tackling DoD Cyber Red Team Deficiencies Through Systems Engineering Schab, John GPEN
Hacking Humans: The Evolving Paradigm with Virtual Reality Andrasik, Andrew GPEN
Preventing Living off the Land Attacks Brown, David GPEN
Cyber Range The future of Cyber Security training Perez Gonzalez, Carlos GPEN
Ebb and Flow: Network Flow Logging as a Staple of Public Cloud Visibility or a Waning Imperative? Taggart, Dennis GPEN
PDF Metadata Extraction with Python Plaisance, Christopher GPYC
Chaining Vulnerability Scans inTenable IO Using Python Holland, Jeff GPYC
Uninitialized Memory Disclosures in Web Applications Varga-Perke, Balint GWAPT
Unix-style approach to web application testing Veres-Szentkiralyi, Andras GWAPT
How to identify malicious HTTP Requests Sarokaari, Niklas GWAPT
Website Security for Mobile Ho, Alan GWAPT
Web Application Injection Vulnerabilities: A Web App's Security Nemesis? Couture, Erik GWAPT
Introduction to the OWASP Mutillidae II Web Pen-Test Training Environment Druin, Jeremy GWAPT
Getting Started with the Internet Storm Center Webhoneypot Pokladnik, Mason GWAPT
Getting Started with the Internet Storm Center Webhoneypot Pokladnik, Mason GWAPT
Web Application Penetration Testing for PCI Hoehl, Michael GWAPT
Differences between HTML5 or AJAX web applications Thomassin, Sven GWAPT
Automated Security Testing of Oracle Forms Applications Varga-Perke, Balint GWAPT
Tunneling, Pivoting, and Web Application Penetration Testing Fraser, Gordon GWAPT
Web Application File Upload Vulnerabilities Koch, Matthew GWAPT
Burp Suite(up) with fancy scanning mechanisms Panczel, Zoltan GWAPT
Testing stateful web application workflows Veres-Szentkiralyi, Andras GWAPT
Polymorphic, multi-lingual websites: A theoretical approach for improved website security Risto, Jonathan GWAPT
From Security Perspective, the Quickest Way to Assess Your Web Application Alduhaymi, Mohammed GWAPT
Runtime Application Self-Protection (RASP), Investigation of the Effectiveness of a RASP Solution in Protecting Known Vulnerable Target Applications Fry, Alexander GWAPT
Tips and Scripts for Reconnaissance and Scanning Panczel, Zoltan GWAPT
Using Sulley to Protocol Fuzz for Linux Software Vulnerabilities Warren, Aron GXPN
Using Docker to Create Multi-Container Environments for Research and Sharing Lateral Movement McCullough, Shaun GXPN
Learning CBC Bit-flipping Through Gamification Druin, Jeremy GXPN