dr.chaos

~/blog

Articles

Every transmission from the lab — adversarial AI research, offensive security tutorials, threat analysis, and the legacy Dr. Chaos archive.

231 articles

The Security profession: Offense vs. Defense

Lately there has been some articles and conversations around the security profession, particularly the ‘how to get started’ aspect. My good friend, Aamir Lakhani wrote a great article on getting started in cyber security (https://www.doctorchaos.com/getting-started-with-a-career-in-cyber-security-an

Anthony Giandomenico10 min read

Getting started with a career in Cyber Security and Information Security

The Information Security Profession – Where do I Start? I am often asked by individuals to provide advice or guidance on how to get started in the field of information security. Many college students tell me they want to be a hacker, an IT systems penetration tester, or other type of cyber security

Aamir Lakhani12 min read

Breaking SSH, VNC, and other passwords with Kali Linux and Hydra

Hydra is a very fast and effective network login cracker. It will help you perform brute force attacks against SSH servers, VNC, and other services. When you launch Hydra it will launch the GUI in Kali, however in this tutorial we will use xHydra, which is the command line version of the tool. The c

Aamir Lakhani2 min read

The Imminent Demise of Bitcoin

Bitcoin is a faith-based currency. That means its value is derived from what people think its worth and are willing to pay for it. It is very similar to a natural resource because it (1) is reasonably difficult to produce, (2) it has a limited finite supply, and (3) it is recognized to have value.Th

Aamir Lakhani5 min read

Cybersecurity and Big Data trends in Retail Industries

The retail and service industry is costly in terms of demands due to the difficulty of managing inventory and precious shelf space. Retailers must carefully plan when to put an item on sale, where to place the item, when to restock the item, and balance understand the potential for opportunity when

Aamir Lakhani11 min read

Covert Operations: Kill Chain Actions using Security Analytics

By Aman DiwakarIn Special Operations, there are multiple actors on either side of the battlefield, at any point in time, attempting to achieve tactical leverage over the enemy. This leverage comes in multiple forms, at different stages of combat and the entire process is referred to as the “Kill Cha

Aamir Lakhani6 min read

njRAT Malware – remote control malware

Warning: The ideas, concepts and opinions expressed in this blog are intended to be used for educational purposes only. The misuse of the information from this article can result in criminal charges brought against the persons in question. Refer to the laws in your province/country before accessing,

Aamir Lakhani4 min read

Understanding Rainbow Tables

On the topic of breaking passwords, I often hear security professionals and a few other folks mention Rainbow Tables. I used to think a Rainbow Table was a set of pre-computed (pre-calculated) hashes from passwords…essentially a lookup table where a plaintext’s unencrypted password corresponds to a

Aamir Lakhani4 min read

Arachni Web Application Security Framework

Arachni Web Application Security Framework is an open-source Web application scanner and vulnerability penetration testing tool. Unlike many other system scanners, Aracni specializes in finding Web application vulnerabilities. Steps for Installing Arachni on Kali Linux SystemsFirst we will download

Aamir Lakhani2 min read

The Art of Ransomware

Ransomware may potentially be the biggest threat in 2016. Criminal organizations are making big money from ransomware. According to a Geek.com article by Lee Mathews, Cryptowall, a ransomware application, generated over $30 million USD for criminals. People simply pay to get their data back, a syste

Aamir Lakhani4 min read