Header
5 results were found... happy reading.

Wed, 28 Oct 2009

Fasm2009 - Videos online..
@

The "Fasm conference is an informal meeting of coders interested in x86 assembly programming."

Some of the videos can be grabbed [sp_local|Other]

/mh

Tue, 29 Sep 2009

SensePost again accredited as a PCI ASV
@

SensePost is proud to announce that they have retained their status as an Approved Scanning Vendor for PCI DSS purposes.

This letter of acknowledgement was gladly received:

Truth be told, we did pop the bubbly for this one.

Tue, 22 Sep 2009

MS Threat Modeller
@

Just arbitrary coolness regarding Microsoft's Threat Modeller. It's XSS-ible...

Since this all works in file:///, not overly sure what the benefits of these things will be, but I suppose since different folks may have different privilege levels for different protocol handlers (ie: file:// http:// etc), one might be able to instantiate previously unusable OCX'es, or even redirect to site for exploiting browser vulnerabilities.

Never happened unless there are pictures, so refer below...

XSS strings in MS Threat Modeller

Cute alert()

Redirect to www.sensepost.com

A little further playing, along with some vulnerable ActiveX controls, and we find ourselves with a nice mechanism for getting remote code execution... :)

CALC.EXE

Finally, a little update. After reporting the issue to secure@microsoft.com, we get a response from Nate mentioning the following:

"Thank you again for bringing this to our attention. Given that this product has been deprecated, the MSRC won't open a case to investigate the issue. I am however going to contact the Download Center and see if we can get the download removed since new tools/versions are available. If you find the same or other issues in the current version/tool please let us know. If you have any questions or concerns please let me know."

A subsequent Google for the Microsoft Threat Modeling (sic) Tool this morning, provides the following...

Googling for Threat Modeling Tool

The first link is the package we're looking for. Clicking on the Cached page, we get:

Google Cached page

Clicking on the "really-real" link, we get the following...

Page Not Found

/ian

Fri, 11 Sep 2009

2 pieces of coolness...
@

a) was the politely dropped kaminsky firefox bug [http://lists.grok.org.uk/pipermail/full-disclosure/2009-September/070620.html]

It still requires a click for command execution, but considering its multi platform firefox ownage sans shellcode, i think its cool.. i think its even cooler that dan dropped it sans any fanfare..

b) has to be Pusscat's attack on the SMBv2 Remote bug published on [the VRT blog..]

From the post:

"we get lucky here as well in that there is a pointer srv!pSrvStatistics which also points to srvnet!SrvNetStatistics, and counts the number of requests that have been made to a specific call (as well as other things).

So the technique here is to firstly increment srvnet!SrvNetStatistics to be ffe6, ffd6, or 56c3 (jmp esi, call esi, push esi -> ret). Then we set ProcessHighID to a value that when multiplied by four and added to the base address of ValidateRoutines pushes us outside of srv2.sys and into srvnet.sys where we then end up dereferencing the pointer to srvnet!SrvNetStatistics. This now transfers control to the data in our packet which we can massage to gain execution.

"

Awesome++

Wed, 2 Sep 2009

About:SnowLeopard
@

Sure it only cost $29, but when you consider the number of people bowing down and thanking our Cupertino overlords you have to consider the following:

If the Emperor was given his new clothes today, #emperors_clothes would be trending on twitter (with ppl thanking the tailors for reduced closet space requirements)

/mh

Blog
Video
Research
QotW
Categories
about:us (31)
blackhat (5)
blog (10)
broadview (2)
build-it (1)
cloud (12)
community (15)
conferences (60)
crypto (3)
fail (3)
foos (1)
fun (51)
goodbye (1)
hackrack (2)
Hope? (2)
howto (8)
imsojaded (2)
infosec-soapies (25)
infrastructure (3)
local (5)
mac (15)
management (7)
materials (3)
memcached (2)
mindless-politics (4)
mindmaps (1)
PCI (2)
post-it (1)
privacy (6)
product (2)
programming (5)
public (275)
qo[w|m|?] (5)
README (1)
real-world (14)
research (37)
reversing (4)
security-fyi (8)
security-news (6)
silly-yammerings (19)
tech-toys (3)
time-waster (6)
tin-foil-hat (6)
tools (46)
training (18)
travel (1)
tricks (1)
Uncategorized (3)
vendors (6)
videos (6)
vulnerability (7)
wasc (1)
webapps (6)
web_x.0 (2)
writing-advice (1)
zen-hacking (6)
Archives
August 2010 (4)
July 2010 (1)
June 2010 (4)
May 2010 (3)
April 2010 (3)
March 2010 (7)
Feburary 2010 (2)
January 2010 (3)
December 2009 (4)
November 2009 (4)
October 2009 (3)
September 2009 (5)
August 2009 (9)
July 2009 (1)
June 2009 (5)
May 2009 (4)
April 2009 (10)
March 2009 (13)
Feburary 2009 (12)
January 2009 (11)
December 2008 (9)
November 2008 (8)
October 2008 (5)
September 2008 (5)
August 2008 (6)
July 2008 (6)
June 2008 (6)
May 2008 (2)
April 2008 (3)
March 2008 (7)
Feburary 2008 (12)
January 2008 (9)
December 2007 (8)
November 2007 (4)
October 2007 (9)
September 2007 (14)
August 2007 (18)
July 2007 (13)
June 2007 (17)
May 2007 (2)
July 2006 (1)
April 2006 (1)
August 2005 (1)
June 2005 (1)
May 2005 (2)
Archives
Conditions of use Privacy statement
Top of Page Legal stuff