Resources
Checkmate

Blog on Digital Forensics and Incident Response

Innovations
Web War CTF advisories articles presentations snort signatures security tools

We are at the forefront of security research in the region. Our research activities encompass

finding security vulnerabilities in mission-critical software and releasing advisories
developing and releasing free security tools
writing papers, articles
making presentations on various aspects of security

Results from our vulnerability research also go into various products and services as inputs, which contain actionable and accurate information about the latest security issues.
The outputs from our research also go into updating our proprietary suite of auditing software - AuditPro.

Capture the Flag Event (CTF)

We were happy to organize this year’s successful event Web War CTF IV at the SecurityByte Conference 2011.

Learn More..

Advisories

Our penetration testing team find security bugs in various mission-critical software from vendors such as Microsoft, Oracle, Nortel, Macromedia, etc. We also believe in responsible disclosure and co-ordinate with the vendors before releasing information about these bugs.

Latest Advisories

Excel File Format Parsing Vulnerability (CVE-2010-3232)
Real Networks RealPlayer RealMedia Memory (CVE-2010-4386) Heap Corruption Vulnerability

Learn More..

Papers and Articles

Our research initiatives shape into papers and articles published at various security-related and IT audit-related sites. Some of the latest papers and articles are listed below

Latest Articles

IT Audit: Key Strategies for Implementing ISO 27001
Security Focus: IDS Evasion, Revisited

Learn More..

Presentations

Our consultants have presented at various international conferences including BlackHat, Networld+Interop and IT Underground. Our presentations and ideas have been well-received by information security experts across the world

Latest Presentations

IT Underground, Prague, 2006
Corporate IT Security Conference, Mumbai

Learn More..

Snort signatures

Our team also writes Snort signatures for attacks.

Sample Signatures

Snort SACK TCP Option Handling Remote Denial of Service Issue
Microsoft ASN.1 Buffer Overflow Exploit

Learn More..

Security Tools

We have also written tools for enforcing password complexity in SQL server, brute-force attacks on SQL server accounts, dumping Windows security information, etc.

Sample Tools

EnforcePass
ForceSQL v2.0

Learn More..