Independent Research

Here is a selection of some of the currently available presentations, publications and whitepapers by iSEC Partners. Please refer to the Speaking Engagements page to download presentations from talks and conferences.


Whitepapers

Command Injection in XML Signatures and Encryption

Brad Hill, Principal Security Consultant


Secure Session Management With Cookies for Web Applications

Chris Palmer, Senior Security Consultant


Exposing Vulnerabilities in Media Software

David Thiel, Senior Security Consultant


IAX Voice Over-IP Security

Himanshu Dwivedi, Principal Partner
Zane Lackey, Security Consultant


Breaking Forensics Software - Flaws in Critical Evidence Collection

Tim Newsham, Principal Security Consultant
Chris Palmer, Senior Security Consultant
Alex Stamos, Principal Partner
Jesse Burns, Principal Partner


Blind Security Testing - An Evolutionary Approach

Scott Stender, Principal Partner


Building Security In: Software Penetration Testing

Originally published in "IEEE Security and Privacy"
Scott Stender, Principal Partner


ProxMon: Automating Web Application Penetration Testing

Jonathan Wilkins, Principal Security Consultant


Books

Hacking VoIP

Himanshu Dwivedi, Principal Partner


Hacking Exposed Web 2.0

Rich Cannings, Himanshu Dwivedi and Zane Lackey
Contributing authors: Alex Stamos and Chris Clark


Hacker's Challenge 3

Himanshu Dwivedi, Principal Partner


Implementing SSH

Himanshu Dwivedi, Principal Partner


Presentations

"Mobile Phone Messaging Anti-Forensics"

Zane Lackey, Senior Security Consultant
Luis Miras, Independent Security Researcher


"Concurrency Attacks in Web Applications"

Scott Stender, Principal Partner
Alex Vidergar, Security Consultant


"Living in the RIA World: Blurring the Line Between Web and Desktop Security"

David Thiel, Principal Security Consultant
Justine Osborne, Security Consultant
Alex Stamos, Principal Partner


"Something Old (H.323), Something New (IAX), Something Hollow (Security), and Something Blue (VoIP Administrators)"

Himanshu Dwivedi, Principal Partner
Zane Lackey, Senior Security Consultant


"Exposing Vulnerabilities in Media Software"

David Thiel, Senior Security Consultant


"Point, Click, RTPInject"

Zane Lackey, Senior Security Consultant
Alex Garbutt, Security Consultant


"Blind Security Testing—An Evolutionary Approach"

Scott Stender, Principal Partner


"Breaking Forensics Software: Weaknesses in Critical Evidence Collection"

Chris Palmer, Senior Security Consultant
Tim Newsham, Principal Security Consultant
Alex Stamos, Principal Partner


"ProxMon: Automating Web Application Pentests"

Jonathan Wilkins, Principal Security Consultant


"NTLM Weaknesses Explored"

Jesse Burns, Principal Partner


"SAN and NAS Security"

Himanshu Dwivedi, Principal Partner


"Storage Security Threats- iSCSI, FC, IP, and NAS"

Himanshu Dwivedi, Principal Partner


"iSCSI Security - Insecure SCSI"

Himanshu Dwivedi, Principal Partner


"Cross Site Reference Forgery: An Introduction to a Common Web Application Weakness"

Jesse Burns, Principal Partner


"Web Services Security" or “Attacking Web Services”

Scott Stender, Principal Partner
Alex Stamos, Principal Partner


"I'm going to shoot the next person who says VLANs"

Himanshu Dwivedi, Principal Partner


"Attacking Applications by Fuzzing Win32 IPC"

Jesse Burns - Principal Partner


"Attacking Internationalized Software"

Scott Stender, Principal Partner


"Breaking AJAX Web Applications: Vulns 2.0 in Web 2.0”

Alex Stamos, Principal Partner
Zane Lackey, Security Consultant


"XML Digital Signature and Encryption: Use and Abuse"

Brad Hill, Senior Security Consultant