Research Papers

Camera Hacking: Hardware Lab Walk-Through

Published: January 1, 2025

Research by: Mickey Bayo August 26, 2025Download PDF Report Hardware Lab Walk-Through In this lab, we’ll go over all the steps involved in gaining root access on a Wi-Fi camera. The device in question is the Tapo C100 by TP-Link. We’ve provided all the tools necessary to complete the lab, which include the following: PCBite […]

Read More

Ethercombing: Finding Secrets in Popular Places

Published: January 1, 2018

Abstract: Blockchains are public ledgers of transactions verified through the use of public and private keys to sign and prove ownership of transaction data. Popular blockchains have hundreds of millions of transactions which include some of the most popular — Bitcoin, Waves, Ripple, ZCash, Monero and Ethereum. Currently, on the Ethereum blockchain there are 345 […]

Read More

The Not-So-Same-Origin Policy: Bypassing Web Security through Server Misconfiguration

Published: January 3, 2018 Authors: David Petty

The same-origin policy remains one of the most important security mechanisms of the web, protecting servers against malicious pages interacting with their APIs through cross-site requests. However, the subtle details of the policy can be overlooked, so we aim to show how limitations in the application of the same-origin policy can undermine security. We explain […]

Read More

Reverse Engineering iOS Apps

Published: January 7, 2017

This paper serves as an introduction to the tools and techniques available on the Mac OS X operating system for vulnerability analysis. It is particularly targeted for those security researchers already familiar with tools for Windows and/or Linux. It also reveals tools that are only found on Mac OS X and how they can be […]

Read More

The Enemy You Know

Published: January 7, 2017

Many organizations are already cognizant of the fact that there are security threats originating from the inside, beginning with their own trusted employees and partners. However, many organizations do not necessarily differentiate between the various types of internal adversaries, and may also be unaware that a uniform defense posture is not effective, as different defense […]

Read More

Our Link-Clicking CSRF Victim Robot

Published: January 7, 2017

OUR LINK-CLICKING CSRF VICTIM ROBOT Jacob Thompson, Independent Security Evaluators Over the past year, ISE has brought our SOHOpelessly Broken router hacking contest to DEF CON, DerbyCon, Toorcon, and BSides DC. ISE started the contest to shine light on the need for manufacturers to better secure small office/home office (SOHO) devices; our thought was that […]

Read More

Scanning IPS-Protected Networks with Nessus

Published: January 7, 2017

Jacob Thompson, Independent Security Evaluators A Nessus vulnerability scan is one component of an overall network-level security assessment. Frequently, networks are protected by an intrusion prevention system (IPS). IPS rules may block traffic when throughput, packet counts, or connection counts cross a predefined threshold, or when packets are sent to blacklisted ports. Nessus provides neither […]

Read More

Password Managers: Under the Hood of Secrets Management

Published: January 1, 2017

February 19, 2019 Also see associated blog FAQ Link to Washington Post Exclusive Abstract:  Password managers allow the storage and retrieval of sensitive information from an encrypted database. Users rely on them to provide better security guarantees against trivial exfiltration than alternative ways of storing passwords, such as an unsecured flat text file. In this paper […]

Read More

From FAR and NEAR: Exploiting Overflows on Windows 3.x

Published: January 7, 2017

In a way, Windows 3.x provided Data Execution Prevention and a crude form of Address Space Layout Randomization—security measures far beyond the expectations of any early-1990s enterprise. The segmented memory model that made 16-bit x86 code difficult to program also complicates building an exploit. This paper demonstrates what may be the first public writeup of […]

Read More

Demystifying Full-Disk Encryption

Published: January 7, 2017

Transparent full-disk encryption uses techniques found almost nowhere else in cryptography, such as ESSIV and XTS-AES. Why must designers resort to building a custom cryptosystem rather than relying on standard techniques with typical security guarantees? This paper explores the constraints under which a full-disk encryption must operate, questioning the performance reasons for avoiding more standard […]

Read More