SECFORCE will be presenting at OWASP

imagensecforcepost.png

SECFORCE will present Tunna framework and a number of techniques penetration testers can benefit from to bypass network firewalls.

The presentation will include common scenarios in which HTTP tunnels can be use to bridge the gap between web application testing and infrastructure testing.

Please find information about the conference here.

You may also be interested in...

imagensecforcepost.png
Aug. 9, 2013

Tunna Framework

Tunna is a HTTP tunnel framework to aid penetration testing for web applications protected by a firewall. Tunna is integrated with Metasploit.

See more
imagensecforcepost.png
Feb. 18, 2014

From CSV import to cmd.exe – via SQL injection

This blog post explains the process that we followed in a recent penetration test to gain command execution from a CSV import feature. One of the most challenging issues was that we had to escape commas during the SQL injection attack, as it would break the CSV structure.

See more