News
Marcus Evans NZ CIO Summit
12 Apr 2010
Paul Blowers will be presenting on the security considerations of "cloud-computing" at the Marcus Evans NZ CIO Summit in Auckland.



Brighstar 15th Annual IT Security Summit
30 Mar 2010
Andy Prow and Paul Blowers are presenting on the security issues of social-networking at Brighstar 15th Annual IT Security Summit in Auckland.



Welcome Paul Blowers
Mar 2010
We are very pleased to welcome Paul Blowers to the Aura team. Paul will be heading up our fast-expanding IT Security Architecture practice.



Troopers 10 - Heidelberg, Germany
8-12 Mar 2010
Graeme Neilson is continuing his world tour with Troopers 10 in Heidelberg, Germany.



Winner of Electra Awards New Thinking 2009
10 Nov 2009
We are very proud to be the winners of the Electra Business Awards 2009 - New Thinking and Innovation category! Putting "Silicon Gorge" on the map




Help Sponsor our Southern Crossing
January 2010
In loving memory of Betty Nicholson and Helen Palmer, Andy Prow and family (Diane, Josh and Autumn) are walking the Southern Crossing - 3 day hike over the top of the Tararua Range!
Please help support us in raising funds for the Neurological Foundation.
Find out how...




Day-Con III - Dayton Security Summit
15 Oct 2009
The now world-famous and highly sought after Graeme Neilson is off to present at Day-Con III in Ohio, USA, and Aura is proud to be a Gold Sponsor of this excellent IT security event.


Microsoft TechEd
14-16 Sept 2009
Microsoft's TechEd NZ was another HUGE event this year, all the more so of course because Andy Prow presented with Kirk Jackson - check out "SEC313: Hack-Ed, Teaching the Good-Guys Bad-Tricks"


Microsoft Code Camp 09
13 Sept 2009
If you're heading to TechEd this year and need to scratch up on your Secure Coding Practices then definately come along to the .Net Code Camp. Andy Prow will be presenting with Kirk Jackson of Xero on Secure Coding Practices.


BlackHat Vegas
25-30 July 2009
Aura's Graeme Neilson gave an EXCELLENT presentation at BlackHat USA 09. Graeme presented his now world famous "NetScreen of the Dead" (sorry Juniper). BlackHat is "the World's Premier Technical Security Conference", so we're very proud to have Graeme invited to speak!

Read more...

CIO Summit
21-22 July 2009
The NZ CIO Summit 2009 was an excellent event! Almost twice the size of last year it was buzzing.
Thanks to Paul Blowers, Enterprise Security Architect from the NZ Police for an excellent talk. Read more...



OWASP DAY 2009
13 July 2009
Look out for the OWASP NZ Day 2009 on July 13th in Auckland.
Andy Prow is presenting with Kirk Jackson from Xero - "XSS The Gloves are Off". Andy's hacking, Kirk's defending... hopefully not too much blood spilt!


.Net User Group
29 Apr 2009
Andy Prow presented at the .Net User Group talk at Xero, Wellington. Find out more... If you couldn't be there - download the presso


IT Security Summit 09
14-15 April 2009
Mark Keegan again gave an excellent presentation at this year's Brightstar Annual IT Security Summit
Mark presented "Hacks and Demos: Securing Web Applications" - see our presentations


ISACA
Dec 2008
Andy Prow presented at the ISACA Computer Security Day on the 2nd Dec 2008 in Wellington. Andy's presentation focussed on the "SANS Defensive Wall 1 - Proactive Software Assurance". Read more...


RUXCON
Nov 2008
Great conference - Graeme Neilson presented at RUXCON in Sydney this year - 29th,30th Nov 08. Graeme presented on how to hack Juniper firewalls, rebuilding and reloading the OS, to create an untraceable "zombied" firewall - you run it, we own it, what more could you ask for? This preso was certainly one of the best of the whole conference (totally unbiased opinion of course!). Read more...


CIO Summit
July 2008
We showcased our services at the BrightStar/IDC CIO Summit on July 22nd & 23rd in Auckland, especially our new RedEye.
If you were there you'd have heard an excellent presention by Craig Walker the CTO of Xero casestudying our services with them.


QualIT Partnership
May 2008
We're excited to accounce our partnership with QualIT through which we're providing our PRODUCTION STRENGTH testing service, combining security testing and performance testing services.


IT Security Summit
April 2008
Our very own Mark Keegan presented at this year's Brightstar Annual IT Security Summit
A good 2 days session - well worth attending if you haven't before.


Graeme on IT Radio - Australia
Feb 2008
A great interview with Graeme Neilson on Ausy's IT Radio all about BlackBerry hacking and Aura's "RedBerry" security tool. IT Radio #46


Microsoft Certified Partners
January 2008
We're very proud to announce that Aura Software has just become a Microsoft Certified Partner.


Research & Development
December 2007
We are extremely happy to have been granted a TBG grant from the Foundation of Research, Science and Technology - see www.FRST.govt.nz for more info.

The fruits of this project will be seen in the next versions of our RedEye service.


Kiwicon 2k7
November 2007
Mark Keegan and Graeme Neilson both gave presentations at the inaugral Kiwicon Event - NZ's own Security Conference.

Check out www.Kiwicon.org for info on the conference, and our publications page to have a look yourself


Over the Ditch
October 2007
This Kiwi Security consulting company engaged in our first penetration test across the ditch in Australia, testing the Managed Accounts website owned and operated by Investment Administration Services Pty.

Read the full case study here


Latest Publications
 
     
  All presentations are Copyright Aura Software Security Ltd 2008, All Rights Reserved. You may download these presentations for research purposes only. Any re-use or reproduction of these presentation may only be peformed with express permission from Aura Software Security Ltd.

     
     
Netscreen of the Dead   Graeme Neilson presented at the RuxCon IT Security conference in Sydney (Nov 2008). The presentation covered Graeme's research on how he's developed a trojan ScreenOS operating system that when loaded onto any Juniper Firewall turns it into a ZOMBIE, giving Graeme full access to the underlying firewall, bypassing all rules and passwords.
We must of cause mention Juniper at this point - "we express our appreciation for your pragmatic and careful handling of this case" (Juniper, 28 Nov 08). They also released a tech bulletin: PSN-2008-11-111, "ScreenOS Firmware Image Authenticity Notification" which states: "All Juniper ScreenOS Firewall Platforms are susceptible to circumstances in which a maliciously modified ScreenOS image can be installed."
Listen in to Graeme's interview on IT Radio download (18MB mp3 file)
Download "Netscreen of the Dead"

     
     
Proactive Software Assurance   Andy Prow presented at the ISACA Computer Security Day on the 2nd Dec 2008 in Wellington. Andy's presentation focussed on the "SANS Defensive Wall 1 - Proactive Software Assurance", covering the steps you should take as an organisation to proactively protect your systems against attack.
Download "Proactive Software Assurance"
     
     
Better than the regular script kiddie: w3af   The w3af framework project is the up-and-coming MetaSploit of Web application security. It's flexible design allows new attack vectors to be easily written and includes many features which are only available in the grossly expensive commercial tools. Mark's presentation will discuss why we need webapp scanners and demo the w3af framework and how to automate the Discovery, Audit and Attack of web applications.
Download "w3af"
   
     
Scanberry: Advanced Attacks via a Trojaned Blackberry   Building on the Blackjacking tools presented at DefCon, Graeme will present some advanced tools for attacking internal networks via Blackberrys. For example how to use TicTacTrojan on a Blackberry to port scan an internal network from the comfort of your external host.
Download "Scanberry"
     
     
Quality Software - Designed to be Hacked   Andy will focus on how software quality MUST include security considerations during the requirements, design, implementation, testing, roll-out and maintenance phases. He will also include some examples of real-world security issues that "make you think..."
Download "Designed to be Hacked"
     
     
It Only Takes a PinPrick to Burst Your Enterprise Security Bubble   The presentation highlights the need for an organisation to have there own "trusted in-house hacker" who thinks like a hacker would.
Some of the other topics covered are:
Some of the latest tools hackers use.
A sample of common vulnerabilities and how they can be exploited.
How to protect your network against these exploits.
Please feel free to contact Aura Software for more detailed information and to request a security assessment.

Download "Burst your Bubble"