Find out what's on our minds these days

Downloading an Application's Entire Source Code Through an Exposed GIT Directory

Website administrators sometimes inadvertently leave an exposed .git directory, from which it is possible to download the entire source code of the web application using just wget and a common server misconfiguration.

Posted on Feb 19, 2016 by Roberto Salgado  |  tags:Git Directory Listing Misconfiguration source code dirb dirbuster

Read full story»

credmap: The Credential Mapper

An overview of credmap, an open source penetration testing tool that automates the process of testing for credential reuse. It does so by testing supplied user credentials on known websites and verifies if the password has been reused on any of these.

Posted on Nov 26, 2015 by Roberto Salgado  |  tags:blackhat tool python credmap credentials mapper

Read full story»

New publication: Mastering the Nmap Scripting Engine

We invite you to learn more about the latest publication from our team, "Mastering the Nmap Scripting Engine".

Posted on Feb 21, 2015 by Roberto Salgado  |  tags:Nmap Scripting Engine Paulino Calderon book NSE Nmap Publication LUA

Read full story»

Presentation on Optimization and Obfuscation Techniques for SQL Injections

A couple years ago Roberto Salgado had the honor of presenting his research on SQL Injections at several conferences. Just recently, Blackhat released the video of his presentation. This post contains the link to Roberto's slides and video.

Backdoors in Zhone GPON 2520 and Alcatel Lucent I240Q

While examining the "dropbear" binary for the Zhone GPON 2520 and Alcatel Lucent I240Q, we found that both routers have backdoors that allow users with SSH access to connect to these devices with maximum privileges.

Posted on Jan 08, 2015 by Roberto Salgado  |  tags:alcatel lucent backdoor gpon i240q zhone ssh 2520

Read full story»

Latest Blog Entries

Downloading an Application's Entire Source Code Through an Exposed GIT Directory
Website administrators sometimes inadvertently leave an exposed .git directory, from which it is possible to download the entire source code of the web application using just wget and a common server misconfiguration.

credmap: The Credential Mapper
An overview of credmap, an open source penetration testing tool that automates the process of testing for credential reuse. It does so by testing supplied user credentials on known websites and verifies if the password has been reused on any of these.

New publication: Mastering the Nmap Scripting Engine
We invite you to learn more about the latest publication from our team, "Mastering the Nmap Scripting Engine".

Latest News

Blackhat EU 2015
Websec participated with two tools at the Blackhat, EU Arsenal held in Amsterdam, NL from the 10-13 of November, 2015. During this event, we introduced our brand new tool "credmap: The Credential Mapper" and also presented an amped-up version of Panoptic.

BSides Vancouver 2015
Websec is proud to announce that we will be attending the 3rd annual edition of BSides Vancouver, a local non-profit information security conference held in the heart of Vancouver, BC on March 16 and 17.