2025-01-13 | Johannes Ullrich | Hikvision Password Reset Brute Forcing |
2024-10-31 | Guy Bruneau | October 2024 Activity with Username chenzilong |
2024-10-16 | Johannes Ullrich | The Top 10 Not So Common SSH Usernames and Passwords |
2024-08-07 | Guy Bruneau | Same Scripts, Different Day: What My DShield Honeypot Taught Me About the Importance of Security Fundamentals [Guest Diary] |
2024-07-13 | Didier Stevens | 16-bit Hash Collisions in .xls Spreadsheets |
2024-06-26 | Guy Bruneau | What Setting Live Traps for Cybercriminals Taught Me About Security [Guest Diary] |
2024-02-28 | Johannes Ullrich | Exploit Attempts for Unknown Password Reset Vulnerability |
2024-01-17 | Jesse La Grew | Number Usage in Passwords |
2024-01-06 | Xavier Mertens | Are you sure of your password? |
2023-10-29 | Guy Bruneau | Spam or Phishing? Looking for Credentials & Passwords |
2023-10-15 | Guy Bruneau | Domain Name Used as Password Captured by DShield Sensor |
2023-09-29 | Xavier Mertens | Are You Still Storing Passwords In Plain Text Files? |
2023-09-05 | Jesse La Grew | Common usernames submitted to honeypots |
2023-09-02 | Jesse La Grew | What is the origin of passwords submitted to honeypots? |
2023-08-10 | Bojan Zdrnja | Some things never change ? such as SQL Authentication ?encryption? |
2023-08-04 | Xavier Mertens | Are Leaked Credentials Dumps Used by Attackers? |
2023-06-05 | Johannes Ullrich | Brute Forcing Simple Archive Passwords |
2023-04-19 | Rob VandenBrink | Taking a Bite Out of Password Expiry Helpdesk Calls |
2023-02-18 | Guy Bruneau | Spear Phishing Handlers for Username/Password |
2022-08-13 | Guy Bruneau | Phishing HTML Attachment as Voicemail Audio Transcription |
2022-05-17 | Xavier Mertens | Use Your Browser Internal Password Vault... or Not? |
2022-03-10 | Xavier Mertens | Credentials Leaks on VirusTotal |
2022-02-13 | Guy Bruneau | DHL Spear Phishing to Capture Username/Password |
2021-11-15 | Rob VandenBrink | Changing your AD Password Using the Clipboard - Not as Easy as You'd Think! |
2021-05-14 | Xavier Mertens | "Open" Access to Industrial Systems Interface is Also Far From Zero |
2021-04-24 | Guy Bruneau | Base64 Hashes Used in Web Scanning |
2021-01-06 | Johannes Ullrich | Scans for Zyxel Backdoors are Commencing. |
2020-07-26 | Didier Stevens | Cracking Maldoc VBA Project Passwords |
2020-07-13 | Didier Stevens | VBA Project Passwords |
2020-06-10 | Brad Duncan | Job application-themed malspam pushes ZLoader |
2020-04-06 | Didier Stevens | Password Protected Malicious Excel Files |
2019-11-01 | Didier Stevens | Tip: Password Managers and 2FA |
2018-12-17 | Didier Stevens | Password Protected ZIP with Maldoc |
2018-08-22 | Deborah Hale | Email/password Frustration |
2018-07-12 | Johannes Ullrich | New Extortion Tricks: Now Including Your Password! |
2017-11-28 | Xavier Mertens | Apple High Sierra Uses a Passwordless Root Account |
2017-05-17 | Richard Porter | Wait What? We don?t have to change passwords every 90 days? |
2017-04-26 | Johannes Ullrich | If there are some unexploited MSSQL Servers With Weak Passwords Left: They got you now (again) |
2017-04-10 | Didier Stevens | Password History: Insights Shared by a Reader |
2017-02-07 | Johannes Ullrich | My Password is [taco] Using Emojis for Stronger Passwords |
2016-12-07 | Xavier Mertens | The Passwords You Should Never Use |
2016-09-15 | Xavier Mertens | In Need of a OTP Manager Soon? |
2016-07-21 | Didier Stevens | Practice ntds.dit File |
2016-06-20 | Xavier Mertens | Using Your Password Manager to Monitor Data Leaks |
2015-06-26 | Daniel Wesemann | Cisco default credentials - again! |
2014-09-19 | Guy Bruneau | Added today in oclhashcat 131 Django [Default Auth] (PBKDF2 SHA256 Rounds Salt) Support - http://hashcat.net/hashcat/ |
2014-08-22 | Richard Porter | OCLHashCat 1.30 Released |
2014-08-06 | Johannes Ullrich | All Passwords have been lost: What's next? |
2014-05-22 | Rob VandenBrink | Another Site Breached - Time to Change your Passwords! (If you can that is) |
2013-11-22 | Rick Wanner | Tales of Password Reuse |
2013-07-21 | Guy Bruneau | Ubuntu Forums Security Breach |
2013-06-11 | Swa Frantzen | Store passwords the right way in your application |
2013-05-14 | Jim Clausing | So what passwords are those ssh scanners trying? |
2013-03-18 | Kevin Shortt | Cisco IOS Type 4 Password Issue: http://tools.cisco.com/security/center/content/CiscoSecurityResponse/cisco-sr-20130318-type4 |
2013-01-18 | Russ McRee | Interesting reads for Friday 18 JAN 2013 |
2013-01-04 | Daniel Wesemann | Blue for Reset? |
2012-11-15 | Jim Clausing | Another month another password disclosure breach |
2012-07-16 | Jim Clausing | An analysis of the Yahoo! passwords |
2012-06-06 | Jim Clausing | Potential leak of 6.5+ million LinkedIn password hashes |
2012-05-22 | Johannes Ullrich | nmap 6 released |
2012-01-03 | Rick Wanner | Analysis of the Stratfor Password List |
2011-10-10 | Tom Liston | What's In A Name? |
2011-08-10 | Johannes Ullrich | Theoretical and Practical Password Entropy |
2011-06-28 | Johannes Ullrich | Hashing Passwords |
2011-05-30 | Johannes Ullrich | Allied Telesis Passwords Leaked |
2010-12-28 | John Bambenek | Mozilla Notifies of Relatively Minor Security Breach |
2010-12-15 | Manuel Humberto Santander Pelaez | HP StorageWorks P2000 G3 MSA hardcoded user |
2010-12-13 | Deborah Hale | Gawker Media Breach of Security |
2010-11-26 | Mark Hofman | Using password cracking as metric/indicator for the organisation's security posture |
2010-08-27 | Mark Hofman | FTP Brute Password guessing attacks |
2010-02-25 | Chris Carboni | Pass The Hash |
2010-02-02 | Johannes Ullrich | Twitter Mass Password Reset due to Phishing |
2009-12-04 | Daniel Wesemann | The economics of security advice (MSFT research paper) |
2009-11-02 | Daniel Wesemann | Password rules: Change them every 25 years |
2009-10-23 | Johannes Ullrich | Little new tool: reversing md5/sha1 hashes http://isc.sans.org/tools/reversehash.html |
2008-09-22 | Jim Clausing | Lessons learned from the Palin (and other) account hijacks |