tssci security

Archive for December, 2008

Happy New Year -- 2009

This is our last post for 2008, a year that has come and gone faster than I imagined. I've been told the years only go quicker the older you get, so I do my best to enjoy it to the very last bit. Anyways, both Dre and I would like to wish all of our [...]

bruteoptions.py -- Get allowed HTTP Methods for a list of directories

A recent email by Dave Aitel to the Dailydave mailing list on Pen testing web servers was an inspiration to publishing a short, but simple script. I like to keep things simple when I write scripts, taking the Unix philosophy of doing one thing and doing [...]

Writing a web services fuzzer in 5 minutes to SQL injection

This week, I was doing an internal penetration test for a client of a web service, which is used by applications loaded on kiosk machines around the country. I didn't have much time to do the test, so I had a couple advantages, like having network access [...]
blog comments powered by Disqus