Our blog
Here is a little tool which help finding and dumping any serialized Java objects in a binary stream. It accepts just one parameter -- the name of the file to load the binary stream.
First run:
$ java -jar jsersearch.jar /tmp/payload.dat
Found objectStream at offset 55, dumping ...
Caught exception…
November 10, 2011 | by abb
Well, maybe the title is a bit ambitions, but at least the script below is is an improvement comparing to these two approaches: 1 and 2:
* It validates server-side certificate instead of ignoring them
* Logs out to invalidate the session cookie and wipes the temporary file used to store it
* Does…
October 29, 2011 | by abb
Here are some notes about my attempt to install Ubuntu 11 on Kingston SV100S2/256G SSD (on Dell Latitude E6510 laptop). Just in case somebody else finds it useful.
I have Googled around for information about SSD disk optimization for Linux and found that there are two main things to consider:…
October 8, 2011 | by abb
We are happy to announce that MagicTree version 1.0 is released and available for download.
We would like to thank everybody who submitted bug reports, feature requests or just wrote to tell us that they love MagicTree. You helped a lot!
Version 1.0 includes a lot of bug fixes and a number of new…
September 30, 2011 | by alla
Introduction
From time to time I come across a web service that expects its input in some proprietary format, usually JSON distorted in one way or another. A vulnerability scanner knows nothing about that stuff and can't properly fuzz it. (At the time of this writing Acunetix and Burp Pro support…
September 29, 2011 | by abb
I've just uploaded MagicTree build 1559, which includes fixes for bugs we have found while working on the PenTest Magazine article.
We are working hard on the next release of MagicTree. We hope to have it out before the end of September.
September 16, 2011 | by alla
Update 2011/09/17: MagicTree build 1559 mentioned in the article is available for download.
PenTest Magazine has published our article Taming Vulnerability Data in its September extra issue along with a MagicTree review by Aby Rao.
In the article we explain how to use MagicTree to analyze Nessus…
September 15, 2011 | by alla
Belgian IT magazine Data News has published the interview with Filip Waeytens and me (Alla) today. It is about penetration testing, hacking and IT security in general. Here is the PDF in Dutch. The whole issue can be viewed here.
September 9, 2011 | by alla
Sometimes it is useful to run an intercepting proxy (running non-root user) on a privileged port. On debian-based systems it is possible using authbind facility.
The first step is to record the necessary port number in authbind config:
$ sudo touch /etc/authbind/byport/443
$ sudo chown abb:abb /etc…
September 8, 2011 | by abb
Our web server has temporarily succumbed to bit rot. Now it is migrated to a sparkling new virtual machine, DNS updated and everything seems to be ticking along as it should. Sorry for any inconvenience this might have caused.
July 20, 2011 | by alla
Contacts

+32 (0) 2 215 53 58

Gremwell BVBA
Sint-Katherinastraat 24
1742 Ternat
Belgium
VAT: BE 0821.897.133.