BTB logo

PA: (484) 223-2598
IL: (630) 809-3725
CA: (415) 651-7498
info@btbsecurity.com


BTB logo

Author Archives: Steven Gill

How to make custom exes for deployment via psexec in Metasploit

If you do as much pen testing as we do, then you’ll notice that there is a high probability you will get blocked by antivirus or endpoint protection if you use Metasploit with default Meterpreter payloads. There are already articles out … Continue reading

Posted in Uncategorized | Tagged , , , , , , | Comments Off


Do you really read all of your reports?

When we write assessment reports, there’s a line before the list of vulnerabilities: The findings detailed in the following sections are a “snapshot in time” and do not landscape all potential vulnerabilities within the environment.  I’ve personally been writing a … Continue reading

Posted in Uncategorized | Comments Off


How do I know the web site I am using is secure?

Shopping online is as strong as ever. For me, I shop at a few popular places. One of those is Zappos. My wife and I have both bought items from there, and are very happy with their customer service. Needless … Continue reading

Posted in Uncategorized | Comments Off


Defense in Depth (and Breadth)

I wanted to take a moment to comment on the recent security breaches at RSA and Epsilon.  Both are a very big deal.  Both have a major thing in common: the danger of social engineering. As more details regarding the … Continue reading

Posted in Uncategorized | Comments Off


Ha! I caught you!

We’ve done a lot of penetration tests over the years. The wide array of places we have worked with is astounding: varying industries, multinationals along with local small businesses. There are varying degrees of success in gaining unauthorized access to … Continue reading

Posted in Uncategorized | Comments Off


Impressions from DefCon 18

I recently came back from DefCon 18. I wanted to take a moment and jot down some thoughts regarding the conference. I do feel like that I came back very encouraged and excited about the community of which I consider … Continue reading

Posted in Uncategorized | Comments Off


Tricks to Data Recovery – Part IV: Raid Reconstruction (continued)

In the previous article, tools and tips were discussed regarding reconstructing a RAID array. This time, we are going to take a look at an actual RAID reconstruction for a data recovery project. In this instance, a customer came to … Continue reading

Posted in Uncategorized | Comments Off


Tricks to Data Recovery – Part III: Raid Reconstruction

Back in the previous articles (Part 1, Part 2), we showed techniques of finding the partition table. In this section, we’ll be discussing how to reconstruct RAID volumes. We’ll start the first part with some background information on RAID, and … Continue reading

Posted in Uncategorized | Comments Off


Beware of Social Network Phishing

Social networking has had an amazing impact in recent years; think of Facebook and Twitter. Facebook is a great site for reconnecting with old friends, sharing stories, posting pictures and “hanging out” online.  Twitter is great for posting information about … Continue reading

Posted in Uncategorized | Comments Off


Password Frustrations and Misconceptions

Ok, so I was observing a presentation at a conference the other day, where another security professional was discussing basic security principles. Towards the end of his presentation, a member of the audience raised his hand and identified himself as a … Continue reading

Posted in Uncategorized | Comments Off




  • Thanks for the most informative and thorough assessment we have had!

    Fred, Manager of Security