TorryCrass.com

  • About
  • Gallery

Exploit

Security

Flash Malware Propagating via CDN

Final Update: I thought I would post one more update to this, as of the middle of April 2015 an analysis of the same malware indicated almost all AV instances picking it up and identifying it as a Cryptowall variant. In addition, it should be noted that after I contact Read more…

By Torry Crass, 10 years10 years ago
Security

Locate PHP Web Shells on a Linux Web Server

A while ago I had put together a quick script to check files in a web directory for possible web shells. I was in a training class and looking for my information on this last week and it seems I've lost it. As such, it's time to put it up again Read more…

By Torry Crass, 11 years11 years ago
Scripting

Log Parsing Script for Shell Shock

The released script will take a given log directory, normally your website log directory, and search it for attempts to exploit the server using the recently released GNU Bourne Again Shell (bash) vulnerability also known as Shell Shock.  Once it identifies these entries, it will output them into a separate Read more…

By Torry Crass, 11 years ago
Security

Bash and Shell Shock Today, The Good, But Mostly Just Bad

A few days ago I posted about a nasty vulnerability pertaining to GNU Bourne Again Shell, otherwise known as bash,  The vulnerabilities still exist in unpatched systems and the scope of what could be affected is still expanding. The good news is a few vendors have provided updates clarifying that Read more…

By Torry Crass, 11 years11 years ago
Security

Holey Bash Batman! No Really, It Has Holes (CVE-2014-6271)

UPDATED: 09/26/2014 – 01:14 EST – Added vulnerability validation code This exploit may have bigger holes than even the Bat Cave.  CVE-2014-6271 (Credit to Stephane Chazelas for discovery) was publicly announced yesterday, September, 24th and some articles are already calling this bug a larger security hole than the recent Heartbleed SSL Read more…

By Torry Crass, 11 years11 years ago
Security

TimThumb Strikes Again 0-day WordPress

This is sadly not the first time this library has caused significant grief for WordPress CMS sites.  The last was back in the fall of 2011 and this latest 0-day is much the same, allowing server based, file level access across sites; possibly even servers depending on configuration. The specific Read more…

By Torry Crass, 11 years11 years ago
Categories
  • Business (1)
  • Helpful Commands (23)
  • Notes (2)
  • Poetry (38)
  • Quips (3)
  • Scripting (6)
  • Security (19)
  • Technical (73)
  • Updates & News (9)
Valuable Products

Affordable Linode VPS

Help Others With Kiva

0.5GB Extra Storage with OneDrive

2GB Free Storage With Dropbox

 

Copyright & Image Usage
Content and images on this site are property of Torry Crass or their respective owners where cited or referenced.
Some images used through public domain licensing and obtained via http://www.publicdomainpictures.net/

© 2010 - 2018 TorryCrass.com

  • Gallery
  • NMP License v1.0
Hestia | Developed by ThemeIsle