• Double Kill – Hacker’s Dome CTF Walk Through Part 1

    Double Kill – Hacker’s Dome CTF Walk Through Part 1

    This past weekend our Quantum Security CTF Team (consisting of Kamil @vavkamil and myself @jamesbower ) competed on the Hacker’s Dome – Double Kill CTF.  The competition consisted of two vulnerable machines with each containing both a user flag and a super user (root) flag.  We were able to capture both flags on the first
    Read More…

  • My Favorite New Toy – Nokia 770

    My Favorite New Toy – Nokia 770

    So I’ve had my Nokia 770 for awhile now and I love this thing. I recently upgraded the memory in mine to 2Gigs which really improved it’s performance. I generally use it to check my email and check on quotes for various stocks and such. It’s pretty sweet. http://amzn.to/2lbKDYa

  • Defeating Tr0ll – Infosec Challenge Walkthrough

    Defeating Tr0ll – Infosec Challenge Walkthrough

    This is my walkthrough for defeating Tr0ll infosec challenge.  This is another great “boot2root” VM  that kept my guessing quite a few times.  It also made me focus more on fully utilizing some of the scripts and programs I generally use during a penetration test.  I also really liked the fact that Wireshark played a
    Read More…

  • Creative Structure is Key by Haruki Murakami

    Creative Structure is Key by Haruki Murakami

    There is a quote I read today by Haruki Murakami that really made me sit back and think about how I handle all my daily task and projects.  Especially with my obsession lately for absolute peak performance in my life. “When I’m in writing mode for a novel, I get up at four a.m. and
    Read More…

  • WORKOUT

    WORKOUT

    So I’ve been getting up @ 5am to workout and I must say that I’m pretty psyched about it. Well not the getting up at 5 part. But I’m pretty happy that I’ve been consistently going to the gym lately. My six-pack is just a few short months away from finally arriving!! I’m working on
    Read More…

  • Quick and Dirty: Installing Htop on FreeBSD 10.x

    Quick and Dirty: Installing Htop on FreeBSD 10.x

    Htop is an interactive system-monitor process-viewer written for Linux. On most of my servers I have it up and running continually if I’m not actively on the box. It’s great to be able to quickly glance up and see the current state of a particular server or to see if something I’m running has gotten
    Read More…

  • Threat Profile: Killer Swag

    Threat Profile: Killer Swag

    Introduction I’ve been monitoring an interesting threat for the past several days, a group I’m referring to as “Killer Swag”. Mainly because the initial dropper is called “Swag.sh” and “Killer Swag” just sounds cool. In another life I think I would have been a marketing genius, but I digress. This post will cover my research
    Read More…

  • Threat Hunting with Bro IDS

    Threat Hunting with Bro IDS

    This post is a quick look at how I personally use Bro IDS for threat hunting. Specifically some of the queries I run when I start a hunt by data set. A quick note on Bro. Bro IDS is a pretty amazing piece of software for threat hunting and my go to tool of choice.
    Read More…

  • Stopping FTP Brute Force Attacks in FreeBSD and OpenBSD

    Stopping FTP Brute Force Attacks in FreeBSD and OpenBSD

    This is a great little article that I came across talking about stopping FTP brute force attacks in OpenBSD or FreeBSD (both of my favorite OS’s). It assumes that your using PF as your firewall (which you should!). You can easily stop bruteforce attacks by limiting connections per IP using pf firewall under FreeBSD or
    Read More…

  • Own Windows with PowerShell using Nishang

    Own Windows with PowerShell using Nishang

    Nishang is a framework and collection of scripts and payloads which enables usage of Windows PowerShell for offensive security and post exploitation during Penetraion Tests.  The scripts are written on the basis of requirement by the author during real Penetration Tests. PAYLOADS It contains many interesting scripts like download and execute, keylogger, dns txt pwnage,
    Read More…