POSTS

Creating Mayhem: Crashing MP3gain for Fun and CVEs

September 3, 2020

Creating Mayhem: Crashing for Fun and Profit The team at VDA Labs has been involved with hunting for vulnerabilities in software using a variety of methods for over 20 years. We use manual review, automated dynamic, and static analysis. One of our favorite ways to dig for really interesting flaws is fuzzing (we literally helped…

Read More

All of Your Data are Belong To Us: The Art of Imaging and Analysis

July 27, 2020

All of Your Data are Belong To Us: The Art of Imaging and Analysis VDA labs is brought into many different types of situation where a client may want imaging and analysis. From diagnosing patient zero during a malware outbreaks to employee espionage taking system images and doing analysis is a important part of the…

Read More

Why Business Email Compromise will Ruin your Business

June 12, 2020

Introduction: In the digital age, businesses are increasingly reliant on email communication for their daily operations. However, this dependence comes with significant risks, especially from a pervasive threat known as Business Email Compromise (BEC). This post delves into the reasons why BEC is not just a minor inconvenience but a serious threat that can ruin…

Read More

BurpSuite Pro Extensions: Some Favorites

May 8, 2020

Part of our internal mentoring and training culture at VDA includes Lunch and Learn events where engineers share helpful information about a relevant security topic. This past week, several of us discussed our favorite BurpSuite extensions, which are helpful additions during our various AppSec or IoT assessments. Extensions can be added to BurpSuite Pro by…

Read More

No More Secrets: Logging Made Easy Through Graylog Part 4

February 20, 2020

Logging is a important but often overlooked part of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This a continuation of a longer series that VDA Labs is writing on Graylog. This is part 4 of a multi-part series covering a variety of topics, including the following items:…

Read More

No More Secrets: Logging Made Easy Through Graylog Part 3

February 20, 2020

Logging is a important but often overlooked part of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This a continuation of a longer series that VDA Labs is writing on Graylog. This is part 3 of a multi-part series covering a variety of topics, including the following items:…

Read More

No More Secrets: Logging Made Easy Through Graylog Part 5

February 20, 2020

Logging is a important but often overlooked part of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This a continuation of a longer series that VDA Labs is writing on Graylog. This is part 5 of a multi-part series covering a variety of topics, including the following items:…

Read More

No More Secrets: Logging Made Easy Through Graylog Part 6

February 20, 2020

Logging is a important but often overlooked part of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This a continuation of a longer series that VDA Labs is writing on Graylog. This is part 6 of a multi-part series covering a variety of topics, including the following items:…

Read More

No More Secrets: Logging Made Easy Through Graylog Part 7

February 20, 2020

No More Secrets: Logging Made Easy Through Graylog Part 7 Logging is a important but often overlooked part of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This a continuation of a longer series that VDA Labs is writing on Graylog. This is part 7 of a multi-part…

Read More

No More Secrets: Logging Made Easy Through Graylog Part 2

February 20, 2020

Logging is a important but often overlooked part of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This a continuation of a longer series that VDA Labs is writing on Graylog. This is part 2 of a multi-part series covering a variety of topics, including the following items:…

Read More

No More Secrets: Logging Made Easy Through Graylog Part 1

February 20, 2020

Logging Made Easy Through Graylog Part 1 Logging is an important piece of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This is the start of a long series that VDA Labs is writing on Graylog. This will be a multi-part series covering a variety of topics including…

Read More

Low-Hanging Fruit Series: Permissions

November 7, 2019

At VDA Labs we work with a variety of companies both large and small. During our engagements, we see many of the same reoccurring issues that allow us access to systems. To help combat these threats VDA is starting a blog series we are calling “Low-Hanging Fruit”. Throughout this series we will be talking about…

Read More