StationX : IT Security for Home or Business StationX : IT Security for Home or Business StationX : IT Security for Home or Business
Security Home IT Security Services IT Security Research Free Security Software Secure Hosting StationX Contacts IT security Support Hotline
IT Security News and  Vulnerabilities
IT Security News Services: Penetration Testing Service
StationX is an industry leader in penetration testing services. We have both highly experienced consultants plus a comprehensive set of penetration testing tool kits
IT Security News Advisory: Transcript of Social Engineering
This is an example of a previous job I performed for a client. See how what seem like insignificant information enables me to build trust with people and achieve ...
IT Security News Magazine: PC Extreme Interviews Nathan House
Penetration Testers; who are these people, what do they do and how do they do it? Join PC Extreme as we talk to top consultant Nathan House about modern network security.
IT Security News New Tool: Windows Permission Identifier v1.0
This tool enables administrators and penetration testers to review File ACLs, Folder ACLs, Registry ACLs, Services, Shares, Installation rights, Internet Access and and so on.
IT Security News Advisory: Statcounter Script Injection User Session Hijack
Identifies a vulnerability that can disclose the authentication and session information of the all registered users of statcounter. More than 1/2 million website's link to it.
IT Security News Advisory: Gossamer Threads Links SQL login XSS Vulnerability
Identifies a XSS vulnerability in Gossamer Threads Links SQL login page. Covers examples of how to exploit the application and the solution provided by Gossamer Threads.
 News: FTC persuades court to shutter rogue ISP
FTC persuades court to shutter rogue ISP
 News: Obama launches cybersecurity initiative
Obama launches cybersecurity initiative
 News: Experts: U.S. needs to defend its "cyber turf"
Experts: U.S. needs to defend its "cyber turf"
 Brief: Researcher aims to tweet Month of Bugs
Researcher aims to tweet Month of Bugs
 Brief: Juniper pulls talk on ATM vulnerabilities
Juniper pulls talk on ATM vulnerabilities
 Brief: Jackson searches resemble attack to Google
Jackson searches resemble attack to Google
Security News
IT Security News and  Vulnerabilities
   
Prof Andrew Gordon
Computer Sciences
Oxford University
 
  StationX has the absolute best name in security professional services. Their core competency is security, and they understand... read more  
IT Security Support Line
IT Security White Papers and Advisories
   

Security Best-Practice Principles :



StationX believe in a transparent approach to knowledge sharing. We invest our time and effort in writing white papers in order to further help the security community in understanding best-practice principles and proven information security techniques. This section includes a selection of our latest published white papers

 
 

Latest Published Whites Papers & Advisories :



Tile:

Social Engineering Example (Transcript from actual compromise)

Date:

11th Jan 2006

Author:

Nathan House

Abstract:

Social Engineering uses influence and persuasion to deceive people by convincing them that the social engineer is someone he is not, or by manipulation. As a result, the social engineer is able to take advantage of people to obtain information with or without the use of technology.

This is an example of a previous job I performed for a client. See how what seem like insignificant information enables me to build trust with people and achieve my successful compromise of the company.

 

Tile:

PC Extreme Interviews our very own Nathan House

Date:

3rd Jan 2006

Author:

Ed Baldwin and Nathan House, PC Extreme

Abstract:

"Ed Baldwin talks to a man on the edge of computer security - Nathan House"

"What would you be left with if you took a hacker then removed his personality and his malicious interests? The fact is you'd end up with somebody who not only knew a lot about computers, but was also extremely talented. You'd also have somebody who was quite literally an expert when it came to computer and network security."

"But who are these people, what do they do and how do they do it? Join PC Extreme as we talk to top consultant Nathan House about modern network security"

 

Tile:

Dilbert on Data Security [Gif]

Date:

14th Sep 2005

Author:

dilbert.com

Abstract:

Some data security humor from Dilbert.

 

Tile:

VISAs Payment Card Industry Data Security Standard [HTML]

Date:

19th May 2005

Author:

Nathan House

Abstract:

Information to help merchants and service providers processing VISA, MasterCard and other credit cards understand the requirements of the new security standard. Failure to comply can result in permanent prohibition of the merchants or service providers participation in credit card processing programs, and a fine of up to $500,000 per incident.

 

Tile:

Statcounter Script Injection User Session Hijack [PDF 82K]

Date:

4th May 2005

Bugtraq:

http://www.securityfocus.com/xxx

CVE:

xxx

Author:

Nathan House

Abstract:

This advisory identifies a vulnerability that can disclose the authentication and session information of the all registered users of statcounter. Statcounter.com is one of the best and most well known website monitoring applications on the Internet. More than 1/2 million website's link to it according to google.

   
Tile:

Gossamer Threads Links SQL login XSS Vulnerability [PDF 57K]

Date:

4th May 2005

Bugtraq:

http://www.securityfocus.com/bid/13484/

Secunia:

Secunia Advisory: SA15253

CVE:

xxx

Author:

Nathan House

Abstract:

This advisory identifies a XSS vulnerability in Gossamer Threads database application "Links SQL" login page. This document covers examples of how to exploit the application and the solution provided by Gossamer Threads.

   
Tile:

Home PC User Security Check List [PDF 17K]

Date:

30th March 2005

Author:

Nathan House

Abstract:

This simple checklist helps the home user maintain security on their home computer system and home network.

   
Tile:

Default Password List [CSV 92K]
Default Password List [XML 930K]

Date:

15th March 2005

Author:

Nathan House

Abstract:

A list of the default passwords for standard installations. Used for pen testing and includes 3COM, Cisco, Bay Networks, Compaq, and many others

   
Tile:

How in Windows NT/2000/XP is information enumerated through NULL session access, Remote Procedure Calls and IPC$? [TXT 16K]

Date:

19th November 2002

Author:

Nathan House

Abstract:

Details how hackers gather information through NULL session access, Remote Procedure Calls and IPC$ on Windows NT/2000/XP.

   
Tile:

Love Letter (ILOVEYOU) Virus Fix - DIVORCE [ZIP 3K]

Date:

4th May 2000

URL:

http://www.securityfocus.com/tools/1441

Author:

Nathan House, Parv Suleman

Abstract:

This is here for nostalgia only. Do you remember the Love Letter virus? Most people do. It was the very first outlook virus that propagated by sending emails to your contacts list. Many copy cat viruses have followed it. We wrote this quick fix to the virus 2 hours after the virus hit the Internet and it proved to be the first available fix. The virus companies were a litter slower back in 2000. We comically named the fix divorce and it even got a mention on the BBC news at 10.

   
Tile:

iPlanet Directory Server 4.11 on Solaris Security Baseline [DOC 1.17MB]

Date:

20th April 2000

Author:

Nathan House

Abstract:

Details the security actions and considerations to be taken and considered when using iPlanet 4.11 on Solaris 2.6.

   
Tile:

BEA Web Logic 4.5.1 on Solaris - Security. As applied to company X. [DOC 672KB]

Date:

17th April 2000

Author:

Nathan House

Abstract:

This document details the security actions and considerations for BEA Weblogic 4.5.1 on Solaris 2.6 as applied to the Company X web site within Phase I delivery.

   
Tile:

The Windows 2000/NT SID (Security ID) explained [TXT 6K]

Date:

22nd December 1999

Author:

Nathan House

Abstract:

A brief on how the Windows 2000/NT SID (Security ID) works

   
Tile:

NTSA v1.0 - NT4 Manual Security Audit [ZIP 373K]

Date:

24th May 1999

Author:

Nathan House

Abstract:

Defines a manual method for auditing an NT based network for it's security configuration. Updated up until Windows NT4 SP4

   
Tile:

Computer Crime & Misuse - Computer Misuse Act 1990 (CMA1990) [DOC 271K]

Date:

3rd December 1998

Author:

Nathan House

Abstract:

A report on understanding the effectiveness of UK computing legislation, how it effects your organisation, and what your organisation can do to complement the legislation.

   
   




 
Home | Services | Research | Sales | Hosting | Contacts | Hot line | Site map | Adult | Links | Penetration Testing
Copyright © 2009. Station X Ltd. All rights reserved. Legal Notices Privacy Policy
seduction sex tips