Talos discovered four in Ichitaro, a popular word processing software in Japan, that could lead to code execution. Details on the patch and a breakdown of the potential exploits here blog.talosintelligence.com/vul

#CyberSecurity #InfoSec #vulndev #vulnerabilities

Last updated 1 year ago

Anvbis · @anvbis
1 followers · 5 posts · Server infosec.exchange

Wrote a fun little tool for javascript engine vulnerability proof-of-concept minimization.

(built on top of the REPRL code from Fuzzilli)

github.com/anvbis/trivialize

#chrome #chromium #v8 #fuzzing #fuzzilli #vulndev #security

Last updated 1 year ago

hexnomad · @hexnomad
77 followers · 49 posts · Server infosec.exchange

Two vulnerabilities O disclosed to @msftsecresponse got patched today. msrc.microsoft.com/update-guid and msrc.microsoft.com/update-guid. Both are are RCE and given critical severity. The first is a pre-auth vuln in ICMP.

From the bulletin:

How could an attacker exploit this vulnerability?

An attacker could send a low-level protocol error containing a fragmented IP packet inside another ICMP packet in its header to the target machine. To trigger the vulnerable code path, an application on the target must be bound to a raw socket.

#patchtuesday #vulndev #rce

Last updated 1 year ago

Anvbis · @anvbis
1 followers · 4 posts · Server infosec.exchange

Exploring Historical V8 Heap Sandbox Escapes I

In anticipation of the future implementation of CFI on `code_entry_point` fields within function objects, I wanted to explore some patched sandbox escapes that have been found in the past.

anvbis.au/posts/exploring-hist

#chrome #chromium #v8 #vulndev #security #infosec

Last updated 1 year ago

hexnomad · @hexnomad
70 followers · 44 posts · Server infosec.exchange

A privilege elevation bug I reported to just got fixed: msrc.microsoft.com/update-guid

Will give a few more details once people have enough time to patch, but it allows LPE from any process.

#msrc #cve202321688 #patchtuesday #vulndev

Last updated 1 year ago

hexnomad · @hexnomad
70 followers · 40 posts · Server infosec.exchange

Binder VMA bug from projectzero just unrestricted: bugs.chromium.org/p/project-ze
CVE-2023-20928

#binder #android #vulndev #exploitdev

Last updated 2 years ago

Anvbis · @anvbis
0 followers · 1 posts · Server infosec.exchange
Anvbis · @anvbis
1 followers · 4 posts · Server infosec.exchange

Root Cause Analysis of CVE-2021-21224

An incorrect optimization in TurboFan’s representation changer results in Int64 values being erroneously truncated to Int32 values.

anvbis.au/posts/root-cause-ana

#chrome #chromium #v8 #vulndev #vulnerability #security #infosec

Last updated 2 years ago

Tim Brown :donor: · @timb_machine
459 followers · 662 posts · Server infosec.exchange

AIX rather helpfully sticks all your function parameters into registers so I've just ported grace.sh to AIX for better bug hunting. Writing up my notes as I go, but hoping to drop a write up of CVE-2022-36768 out this evening, fingers crossed.

#vulndev

Last updated 2 years ago

Knomfr · @stuartdi
4 followers · 16 posts · Server ioc.exchange

I'm struggling to find time to learn IDA, (I have a 70hr wk job) . Great list of tools for i'd like to explore if I ever get ... laid off? idk
sentinelone.com/labs/top-15-es

#vulndev

Last updated 2 years ago

richinseattle · @richinseattle
276 followers · 25 posts · Server infosec.exchange

Google Project Zero discloses 5 exploitable vulns in Androids Mali GPU driver leading to LPE and mitigation bypasses found by @jann. Most phones with Mali GPU including Pixel, Samsung, etc still vuln ..

Current issue seems to be that most phone vendors have not shipped drivers AMD patched months ago. Hopefully the public exposure will pressure the vendors to ship updates since any attackers/spyware shops monitoring AMD patches would already have knowledge of these vulnerabilities.

For researchers, this is a nice way to get full system access for further

googleprojectzero.blogspot.com

#vulndev

Last updated 2 years ago

Ellie · @nilokuma
143 followers · 178 posts · Server infosec.exchange

@richinseattle There was a thread somewhere about hashtags on mastodon, and how camel case is better for screen readers. Can we make it ? The hashtag itself is not case sensitive I think.

#vulndev

Last updated 2 years ago

lolmtt · @lolmtt
0 followers · 1 posts · Server infosec.exchange

Hello World of Mastodon.
Putting my tags out there in case you want to follow, hopefully rebuilding a list of contacts from the bird app.

#gaming #infosec #appsec #redteam #blueteam #dfir #devsecops #vulndev

Last updated 2 years ago

Jesse D'Aguanno :emacs: · @x30n
215 followers · 75 posts · Server infosec.exchange

I made an account on here for Blackwing Intelligence: @Blackwing

We’ll use it to post research, announcements, etc. Stay tuned! 😊

#vulndev

Last updated 2 years ago

richinseattle · @richinseattle
249 followers · 19 posts · Server infosec.exchange

re: mastodon tags .. I use the term as an all encompassing label for vuln research, exploit dev, offsec tool dev, reverse engineering, etc.

For those unfamiliar, this is short for "Vulnerability Development" comes from the old vuln-dev mailing list.

Give this post a like if you also use or would use or comment if there are preferred alternatives.

#vulndev

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: Multiple vulnerabilities in Synology SRM (Synology Router Manager) -  

Claudio Bozzato of Cisco Talos discovered these vulnerabilities. Blog by Claudio Bozzato and Jo... feedproxy.google.com/~r/feedbu

#iot #vulndev #snortrules #vulnspotlight

Last updated 4 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: Two buffer overflow vulnerabilities in OpenCV - Dave McDaniel of Cisco Talos discovered these vulnerabilities.Cisco Talos recently discovered two bu... more: feedproxy.google.com/~r/feedbu -2019-0852 -2019-0853 -2019-5063 -2019-5064

#xml #json #opencv #vulndev #cve #vulnerabilities #talos #vulnerabilityreport #vulnerabilityresearch

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: Apple Safari SVG marker element baseVal remote code execution vulnerability - Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.Apple’s Safari web... more: feedproxy.google.com/~r/feedbu

#bugs #apple #webkit #safari #vulndev #applebugs #vulnerabilities #vulnerabilityresearch #vulnerabilityspotlight

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: Kakadu Software SDK ATK marker code execution vulnerability - Aleksandar Nikolic and Emmanuel Tacheau of Cisco Talos discovered this vulnerability. Blog by Jon Mu... more: feedproxy.google.com/~r/feedbu

#kakadu #vulndev #kakadusoftware #vulnerabilityreport #vulnerabilityresearch #vulnerabilityspotlight #vulnerabilityadvisories

Last updated 5 years ago