«
Expand/Collapse
523 items tagged "Software"
Related tags:
sql injection [+],
remote buffer overflow [+],
chaos communication congress [+],
black hat [+],
apple security [+],
ios [+],
apple [+],
cisco security [+],
advisory [+],
cisco security advisory [+],
vulnerabilities [+],
security [+],
ip version 4 [+],
cisco unified [+],
cisco telepresence [+],
vulnerability [+],
viscom [+],
usa [+],
tool [+],
stack buffer [+],
software movie player [+],
ricoh [+],
remote buffer overflow vulnerability [+],
network address translation [+],
desk [+],
code execution [+],
cisco ios device [+],
Hardware [+],
cisco ios [+],
tv software [+],
tracker [+],
token [+],
ssh [+],
session initiation protocol [+],
service [+],
server [+],
rsa [+],
read [+],
radio [+],
ipv [+],
cdpi [+],
apple tv [+],
antivirus [+],
activex [+],
zbfw [+],
wes faler [+],
video [+],
unix specialists [+],
translation [+],
train customers [+],
time scientists [+],
talk [+],
synergy software [+],
synergy [+],
sunset software [+],
sunset [+],
starmoney [+],
ssl check [+],
ssh login [+],
software versions [+],
software version [+],
software shell [+],
software services [+],
software server [+],
software patch [+],
software dl [+],
software defined radio [+],
software co [+],
sip [+],
server version [+],
security fixes [+],
security division [+],
security advisory [+],
script injection [+],
san [+],
router [+],
root [+],
remote shell [+],
protocol sip [+],
proof of concept [+],
project [+],
phone [+],
pdfsaver [+],
patch [+],
paper [+],
nat [+],
mxe [+],
microsoft windows [+],
malware [+],
mace [+],
lynis [+],
library software [+],
library [+],
lan management solution [+],
koha [+],
jamf [+],
ip phones [+],
intrusion prevention system [+],
interface processor [+],
input validation vulnerabilities [+],
information disclosure [+],
identification [+],
hillstone [+],
help desk software [+],
genetic [+],
ftp [+],
forcal [+],
felix grbert [+],
exploits [+],
experience engine [+],
execution [+],
executable file [+],
epractize [+],
endpoints [+],
drawtext method [+],
dos vulnerability [+],
discovery protocol [+],
dc software [+],
cryptographic primitives [+],
cross site scripting [+],
control flow graphs [+],
computer [+],
cms [+],
classifieds software [+],
classifieds [+],
ciscoworks [+],
cisco unified communications manager [+],
cisco telepresence video [+],
cisco cius [+],
cisco catalyst [+],
cisco carrier [+],
cisco callmanager [+],
cisco asr [+],
chaos communication camp [+],
calendar issues [+],
c series [+],
bypass [+],
building [+],
based buffer overflow [+],
banking software [+],
banking [+],
backdoor [+],
auto [+],
auditing software [+],
attacker [+],
algopars [+],
aggregation services [+],
account [+],
Programming [+],
3d cameras [+],
free software updates [+],
windows [+],
webapps [+],
web [+],
virtualization [+],
usb [+],
unified [+],
tmp filesystem [+],
technical underpinnings [+],
standing on the shoulders [+],
software vulnerabilities [+],
software technologies [+],
software authors [+],
software architects [+],
smart [+],
sensitive [+],
security community [+],
sdk [+],
safer use [+],
poc [+],
physical artifacts [+],
packet [+],
nx os [+],
network [+],
movie [+],
little bit [+],
lindner [+],
libprngwrap [+],
libc [+],
kinect [+],
karl [+],
iphone [+],
internet [+],
hat europe [+],
hardware security [+],
greg newby [+],
google [+],
felix [+],
europe [+],
efs [+],
easy [+],
dlsw cisco [+],
dlsw [+],
disclosure [+],
different leadership styles [+],
desk software [+],
design [+],
dep [+],
cusm [+],
control [+],
computer security vulnerabilities [+],
company [+],
cisco nx os [+],
cisco nexus [+],
bing tags [+],
arduino [+],
Community [+],
cisco ios software [+],
sql [+],
zenworks [+],
zebes [+],
x snow [+],
world of computers [+],
webpage [+],
webcam software [+],
web proxy [+],
web giant [+],
web game [+],
web developer [+],
vit [+],
visual diff [+],
virus [+],
victor [+],
version [+],
verilog [+],
vector graphics [+],
usb tv tuner [+],
usb keyboards [+],
tv capture card [+],
troy wright [+],
trawl [+],
traffic light [+],
traffic [+],
tracker software [+],
tor [+],
tom sawyer software [+],
tom sawyer [+],
time depth [+],
ti nspire [+],
thumb drives [+],
third party [+],
thieves [+],
tftp server software [+],
tftp [+],
temperature display [+],
tcp ip protocol [+],
stream software [+],
steve markgraf [+],
steve christey [+],
stender [+],
steam software [+],
steam [+],
stanford [+],
sshv [+],
spider [+],
space [+],
software tutorials [+],
software tests [+],
software solutions [+],
software maker [+],
software lifecycle [+],
software interface [+],
software index [+],
software errors [+],
software eagle [+],
software developers [+],
software bug [+],
smudges [+],
slides [+],
sketchup [+],
signal generator [+],
siggraph [+],
session [+],
serial port [+],
serial interface [+],
security software [+],
security response [+],
security initiatives [+],
securid [+],
secret [+],
sdr [+],
scott stender [+],
science [+],
sarah gordon tags [+],
sarah gordon [+],
russell spitler [+],
rsvp [+],
rootkits [+],
robert a. martin sean barnum [+],
robert a martin [+],
richard [+],
reverse engineering [+],
revealed [+],
response [+],
rental software [+],
rental [+],
reconstructme [+],
recognition [+],
real time [+],
radius authentication [+],
radio scene [+],
r software [+],
python [+],
proxy [+],
protocol designs [+],
protocol [+],
pros and cons [+],
programming problem [+],
programming challenge [+],
program [+],
printer software [+],
printer [+],
player space [+],
player [+],
pirated [+],
pic [+],
philosophy [+],
peter [+],
peripherals [+],
pda software [+],
pda [+],
pcb layout software [+],
pcb designs [+],
paper software [+],
paper pdf [+],
open source hardware [+],
oisc [+],
object initialization [+],
obfuscated c code [+],
obfuscated [+],
novell zenworks [+],
novell [+],
news [+],
new programming technology [+],
multitasker [+],
multiple [+],
mother brain [+],
monster [+],
monitoring software [+],
monitoring [+],
mobile apps [+],
mobile [+],
mit opencourseware [+],
misc [+],
mini stream [+],
mike field [+],
microsoft software [+],
microsoft [+],
microcontrollers [+],
microcontroller [+],
memory corruption [+],
mascot [+],
marius ciepluch [+],
margin notes [+],
marco morana [+],
mandelbrot fractal [+],
mandelbrot [+],
maker [+],
mac users [+],
mac os x [+],
mac os [+],
mac antivirus [+],
mac [+],
logic analyzer [+],
logic [+],
lifecycle [+],
level languages [+],
legacy software [+],
latex [+],
laptops [+],
l. patterson [+],
jeri ellsworth [+],
jeremy [+],
jason [+],
irregularity [+],
ioccc [+],
invaders [+],
internet key exchange [+],
internationalized [+],
international obfuscated c code contest [+],
international [+],
intelligence [+],
instruction computer [+],
instruction [+],
insecurity [+],
impossible objects [+],
image processing software [+],
ike [+],
html files [+],
html [+],
home automation devices [+],
holes [+],
high score [+],
hide [+],
hasith [+],
hardware version [+],
hardware keylogger [+],
harddrive [+],
harald welte [+],
gsm [+],
greek city states [+],
gps satellites [+],
free software implementation [+],
fractal [+],
fpga [+],
font [+],
flake [+],
flair [+],
fingered [+],
fake [+],
factory [+],
facial recognition software [+],
facial [+],
facebook [+],
face detection [+],
face [+],
fabian mihailowitsch [+],
eye candy [+],
extension [+],
explicit [+],
errors [+],
engineering [+],
eagleup [+],
eagle cad [+],
eagle [+],
doom port [+],
doom [+],
dont be [+],
document [+],
digital [+],
detection software [+],
detection [+],
detecting [+],
depth image [+],
depth [+],
denial [+],
dell webcam [+],
dell axim [+],
deep sleep [+],
database archiving [+],
database [+],
darpa [+],
dangerous software [+],
dan [+],
curiosity [+],
crowd [+],
contest [+],
computer science concepts [+],
computer keyboard [+],
commodore vic20 [+],
commodore vic [+],
commodityrentals [+],
color [+],
cnc [+],
cluster computing [+],
closed source [+],
classic space [+],
class [+],
cisco network [+],
cisco [+],
chaos congress [+],
cart software [+],
cart [+],
cameras [+],
cadsoft [+],
c code [+],
business software alliance [+],
business [+],
bundled [+],
building security [+],
bug [+],
bridge [+],
bot [+],
book [+],
blitz [+],
black and white [+],
bit operating system [+],
bit [+],
big g [+],
beta testing [+],
beta [+],
bejeweled [+],
barnum [+],
baremetal [+],
avira [+],
average [+],
authentication software [+],
attacking [+],
assembly programming [+],
assembly [+],
ascii art [+],
ascii [+],
artificial intelligence [+],
artificial [+],
art [+],
archiving [+],
arbitrary code execution [+],
antonio [+],
anti virus software [+],
ancient greek city [+],
analyzer [+],
alton brown [+],
alliance [+],
air traffic control [+],
aim [+],
admission control [+],
admission [+],
adam obeng [+],
accurate copy [+],
abu dhabi [+],
12 year olds [+],
hacks [+],
service vulnerability [+],
update [+],
development [+],
denial of service [+],
bugtraq [+],
software update [+],
software sql [+],
day [+],
buffer overflow vulnerability [+],
xss,
x. making,
wpa supplicant,
wpa,
world applications,
world,
wordlist,
wlan,
wireshark,
wireplay,
wireless radio,
wireless chip,
wing commander,
wing,
windows computers,
willy,
wifi,
wicd,
wi fi access,
whitepaper,
wep key,
wep,
webmanager,
wazzum,
way,
wave of the future,
vulnerable version,
volta,
voipong,
vncinject,
vnc,
vmware,
visual studio,
visual,
virtualisation,
video analysis,
value,
use,
usda,
usb wireless,
usb dongle,
usb charger,
usb anschluss,
unidata,
und,
unacceptable levels,
unacceptable,
una,
un abrazo,
ubuntu,
typical consumer,
txt software,
txt,
tutto,
tutorial series,
tutorial,
tutor,
tshark,
true,
trouble ticket,
trouble,
trojaner,
transmission rates,
tranado,
traffik,
tping,
toolbox,
took,
tmp,
tls,
tipard,
timer circuit,
timeclock software,
timeclock,
tightvnc,
tiempo compartido,
ticket software,
ticket,
thread,
theharvester,
tcp segment,
tcp,
tavis ormandy,
tar xf,
tar gz,
tar,
sunbelt software,
sunbelt,
sun ray server software,
sun,
sulley,
sul,
sudoglove,
sudo,
studio,
storage options,
sto,
steven wittens,
stem,
static address,
sslstrip,
ssl,
sql server express,
speicher,
spectrum software,
spectrum,
sony vaio,
something,
software windows,
software v1,
software toolkit,
software techniques,
software security,
software sector,
software radio,
software product,
software producers,
software packages,
software ltd,
software list,
software link,
software installer,
software id,
software hackers,
software giants,
software distributor,
software crashes,
software component,
software backup,
softap,
social engineering,
snmp,
snafu,
sms,
sketchchair,
sito,
simulation,
simple software,
simple hello,
simple,
sijio,
signal interface,
sia,
shopping cart software,
shell,
shared object,
settings,
server versions,
server v2,
server down,
server address,
serp,
series switches,
series,
security vulnerabilities,
security guru,
security flaws,
security co,
security clearance,
security authors,
sebastian,
search,
sdk version,
script,
scrib,
salve,
rx packets,
running software,
rugged,
rocket software,
rocket,
rm mp,
ripper,
ricerca,
rfi,
rete wireless,
resolution,
replay attack,
remote,
refresh,
red,
reading package,
react,
ray server,
ramaas,
ram space,
ram,
raknet,
rachel fee,
quote,
quot quot,
quot,
questo,
question,
queria,
que es un hacker,
quake ii,
quake,
python script,
python language,
pwlist,
protocol igmp,
promoting,
programming style,
programming environment,
programmer,
prog,
production servers,
problema,
problem,
privilege escalation vulnerability,
portable,
point,
png,
placa,
pipeline,
piece,
pidgin,
php,
pentest,
penetration test,
pdi,
pdf,
pc.after,
password list,
password,
passport,
partition,
parameter,
para,
palm fiber,
pagina di login,
outlines,
orchestration,
oracle,
open source,
open environment,
open,
old software,
object oriented programming,
notebook,
nome,
no prob,
nmea data,
nexus,
nexpose,
newest software,
new,
network interfaces,
net resource,
nessus,
nbsp nbsp nbsp nbsp nbsp,
nbsp,
nat skinny,
napster,
nancy france,
nancy,
nac,
music controller,
multiple buffer overflow,
msfpayload,
mp3 file,
mp3 decoder,
mozilla,
mouse work,
mouse,
module,
modual,
modern infrastructure,
modern computer,
mode,
minor improvements,
mini stream ripper,
minecraft,
milw0rm,
milw,
mike,
microtouch,
microsoft acquisition,
microprocessor,
micro code,
michael ossmann,
mia,
meterpreter,
metasploit,
metagoofil,
message code,
memory issue,
memory,
medussa,
medusa,
market,
mano,
malaysia,
mal,
make,
mailboy,
mail client,
mail,
magnetosoftnfc universal,
magneto,
mac computer users,
mac address filters,
mac address,
ltd,
low disk space,
lost,
login credentials,
login,
loco,
locazioni,
list,
linux wireless,
linux windows,
linux source,
linux,
link,
linear technology,
limelight,
lifehacker,
libwiretap,
lib,
liado,
len,
leasing software,
leasing,
ldp,
layout manager,
laser light show,
laser assembly,
laser,
las herramientas,
laptop,
lancio,
lan,
label distribution protocol,
krakow,
komppa,
knowledge,
kismet,
keyworks,
keylogger,
keyhelp,
kernel extensions,
kde,
k javascript,
josh corman,
joomla,
jonathan brossard,
john,
joey,
joe grand,
joe,
job,
jewelry cart,
jewelry,
jeremy blum,
jenkins,
jdk java,
jdk,
java,
jari komppa,
jacob nahin,
iwl,
iwconfig,
ivs,
issue,
ipwraw,
ipsec,
ios software,
introductions,
introduction to databases,
internet group management protocol,
internet group management,
interface,
intel pro wireless 3945 abg,
intel pro,
intel graphics media accelerator,
integrated development,
integrated,
installer,
installazione,
insight software,
insight,
injection,
initiation,
iniciar,
information,
inet addr,
inet,
indie,
index,
inconveniente,
inclusion,
inalambrica,
implicit declaration of function,
immagine,
igmp,
ieee,
hxxp,
hpediag,
hp ux,
hp software,
howtos,
hostfriendz,
host machine,
honggfuzz,
home,
hola,
hobbyist electronics,
hijacking,
hello world,
header error,
hardware hacking,
hardware hack,
hard disk,
hard,
handhelds,
half,
hak,
hacking,
hackers de software,
hacker,
hack in the box,
guida,
gui techniques,
gui,
grub,
group,
gross body,
greg jacobs,
graphics demo,
graphical user interface gui,
graphical user interface,
graphical elements,
goolge,
gia,
gerix,
gcc version,
gateway,
fuzzing,
furniture,
function,
funciona,
free,
france,
framework,
found,
forensics,
fnet,
firesheep,
firefox,
finishing touch,
fingerprint software,
fingerprint,
fine,
filter,
fileden,
file upload,
file password,
file,
ferrati,
fence,
fast track,
f shopping,
express,
exploit,
existe,
everyday tasks,
ettercap,
ethical hacker,
ethercap,
etc network,
esyndicat directory software,
esyndicat,
estimados,
error while loading shared libraries,
error array,
error,
eric butler,
environments,
entertainment,
engine crawler,
energizer,
employee timeclock,
employee,
elf,
electrical engineer,
eio,
edge,
ecosystem,
eclipse,
easy language,
dvd,
dumber,
droiddraw,
dramatic effect,
dorkmaster,
dopo,
dont blame,
don,
distributor,
disk,
disclosure of information,
directory traversal vulnerability,
directory software,
directory,
direcciones mac,
digital infrastructure,
dhcpd,
device,
development environments,
designer,
design decisions,
denke,
denial of service dos,
demonio,
demo code,
demo,
decoding,
decoder,
ddms,
dave king,
dating software,
dating,
dati,
database code,
danke schon,
daniel dietrich,
d cad,
critical security,
creative software,
creative,
creare,
cpu mode,
correct ip,
core module,
controls,
control protocol,
contests,
consola,
conference,
conexion adsl,
conexion,
conclusion,
compliance system,
compatibility,
compaq presario,
compaq,
community software,
commander,
command line interface,
collin mulliner,
code coverage,
code,
classpath,
classified ads software,
classified,
cisco industrial,
circuit simulation software,
circuit,
cid,
ciao a tutti,
ciao,
chipset,
chilkatftp,
chilkat software,
chilkat,
chiavetta,
che,
chat server,
change,
ch10,
castripper,
carpeta,
card,
camera software,
camera,
call,
c application,
busy working,
buongiorno,
buon giorno a tutti,
buffer overflow vulnerabilities,
buffer overflow,
buenas,
buen dia,
budget,
bt4,
bt3,
brutessh,
browsing,
brackets,
boston,
border gateway protocol,
border,
bootloader,
boot,
body movements,
board software,
board,
blum,
bleeding edge,
black art,
bing,
billy rios,
best friend,
battery,
basic linux books,
base question,
base interface,
base,
avtech,
avc,
autoupdate,
automaticamente,
authors,
authentication request,
authentication,
audio,
auction software,
auction,
atomization,
ath,
asp,
artologics,
array type,
arp,
archive,
application,
anton,
anomalia,
android,
analysis,
analog oscilloscope,
analog,
amigos,
alu,
algn,
alfa,
alex miller,
alex,
alejandro,
alambrica,
airpwn,
airodump,
aireplay ng,
aircrack,
agn,
advanced software engineering,
advanced,
adsl,
address,
adam,
actualizar kde,
actualizar,
activex controls,
activex control buffer overflow,
activex control,
active x control,
actionscript,
accomplease,
access point,
Tutorials,
Supporto,
Support,
Soporte,
Related,
Newbie,
NON,
Learn,
Issues,
General,
ExploitsVulnerabilities,
Discusion,
BackTrack,
Area,
3d shutter glasses,
3d mouse,
2 gb
-
-
14:59
»
SecDocs
Authors:
Greg Newby Tags:
management Event:
Chaos Communication Camp 2011 Abstract: What motivates people to create and freely distribute their works? This presentation will draw on personal experience, research literature, and existing communities of those who build and give away. Open source software, hardware, community building. The presenter will draw upon over 20 years experience with Project Gutenberg, as well as numerous other activities in which the focus is on building (things, software, communities, infrastructure) and giving them away (free and open source software, free literature, and physical artifacts). What motivates individuals to spend thousands of hours -- often in detriment to time spent with family, work, or other endeavors -- on activity which is primarily devoted to the well being of other people? Often, other people who are not personally known. Is there overlap in motivations for online communities versus volunteerism at the local level? Can such behaviors be learned? What motivates people to create and freely distribute their works? This presentation will draw on personal experience, research literature, and existing communities of those who build and give away. Open source software, hardware, community building. Characterizations of different types of motivations, levels and types of involvement, and outcomes will be made. Anomalies will be identified between individual values and targeted community outcomes, along with their sometimes disastrous impact on community identity-building or planning. Different leadership styles, and their impacts on emerging communities of contributors, will be compared. The presentation will draw some conclusions about how it might be possible to foster altruism in such communities, and to encourage increased interests in their outcomes. The audience will be asked to contribute their own experiences, especially advice about what works and what doesn't work to foster new member involvement. What are impediments to personal time investment, to sharing common goals, and to taking leadership roles? What lifecycles, governance structures, and other characteristics of successful projects (both large and small scale) can we learn from? We have seen hugely beneficial projects of all types where communities sprung up to support the building of things, software and ideas; we also have many examples of projects which did not seem to achieve their goals. How might future builders learn from these past experiences?
-
14:37
»
SecDocs
Authors:
Greg Newby Tags:
management Event:
Chaos Communication Camp 2011 Abstract: What motivates people to create and freely distribute their works? This presentation will draw on personal experience, research literature, and existing communities of those who build and give away. Open source software, hardware, community building. The presenter will draw upon over 20 years experience with Project Gutenberg, as well as numerous other activities in which the focus is on building (things, software, communities, infrastructure) and giving them away (free and open source software, free literature, and physical artifacts). What motivates individuals to spend thousands of hours -- often in detriment to time spent with family, work, or other endeavors -- on activity which is primarily devoted to the well being of other people? Often, other people who are not personally known. Is there overlap in motivations for online communities versus volunteerism at the local level? Can such behaviors be learned? What motivates people to create and freely distribute their works? This presentation will draw on personal experience, research literature, and existing communities of those who build and give away. Open source software, hardware, community building. Characterizations of different types of motivations, levels and types of involvement, and outcomes will be made. Anomalies will be identified between individual values and targeted community outcomes, along with their sometimes disastrous impact on community identity-building or planning. Different leadership styles, and their impacts on emerging communities of contributors, will be compared. The presentation will draw some conclusions about how it might be possible to foster altruism in such communities, and to encourage increased interests in their outcomes. The audience will be asked to contribute their own experiences, especially advice about what works and what doesn't work to foster new member involvement. What are impediments to personal time investment, to sharing common goals, and to taking leadership roles? What lifecycles, governance structures, and other characteristics of successful projects (both large and small scale) can we learn from? We have seen hugely beneficial projects of all types where communities sprung up to support the building of things, software and ideas; we also have many examples of projects which did not seem to achieve their goals. How might future builders learn from these past experiences?
-
-
13:36
»
SecDocs
Authors:
Marius Ciepluch Tags:
radio Event:
Chaos Communication Camp 2011 Abstract: Software Defined Radio defines a new approach to analyze signals with software. With the flexibility of software SDR literally opened a new spectrum of hacking. However the internals of Digital Signal Processing, especially from the perspective of informatics and computer science, are hard to explore. The lecture delivers a case-study on how to analyze 802.15.4 (alias Zigbee, as an easy protocol) with USRPs (modular popular hardware for SDR) on a real-time protocol (for send time verification, sniffing etc.). Furthermore internals on DSP will be explained - as simple as possible. The intent is to also give a non-academic start point and to seed motivation to explore more advanced projects (like osmocom*). So practically the lecture explains what a Software Spectrum Analyzer or a Software Oscilloscope does: from a Hacker's perspective. It gives insight into a USRP(2) internals and goes into programming C++ and Python with GNU Radio. All demo-analysis will remain within the ISM band. - No GSM/Tetra will be captured. It's about the SDR technology and its use-cases - for a clear and constructive adaption by the Hacker's community to assist interesting making projects (of home-automation devices using 802.15.4 e.g.). In many media articles - especially from last Chaos Congress - a misunderstanding can arise to reduce SDR to (GSM) attack scenarios while this is not the only/general use-case. The lecture however clearly aims to assist any intended understanding how the osmocom* implementations work - for example.
-
-
8:01
»
Hack a Day
Impressed by the recent advances in the software defined radio scene, [Jason] picked up a $20 USB TV tuner dongle to check out his local airwaves. Unfortunately, the antenna included with the little USB dongle is terrible at receiving any signal other than broadcast TV. [Jason] wanted to improve his reception, so he got some [...]
-
-
12:01
»
Hack a Day
A few months ago [Antti Palosaari] discovered cheap USB TV tuners could be used as a software-defined radio. Since then, we’ve seen these TV tuners receive signals from GPS satellites and even the signals between air traffic control and passenger aircraft. Like everything cool, Mac support for these drivers is slightly terrible so [hpux735] wrote his own [...]
-
-
21:50
»
SecDocs
Authors:
Adam Obeng Tags:
Tor privacy Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: The Internet began as state-sponsored anarchy, but it is now the tool of first resort for dissidents and propagandists alike. The poster-child project of the Free Software Movement runs on the authority of a single person; the rest clash over the very definition of the word 'free'. A company which pictured itself as smashing Big Brother is now seen as one of the perceived secretive and authoritarian in the industry; and for another, 'Don't Be Evil' is proving to be a challenging motto to live by. This talk aims to present a view of the societies of Internet from the perspective of political philosophy. Political philosophy is not politics, in the same way that computer science is not programming. It's not the politics about the Internet, but the politics *of* the Internet. Even so, events at any particular place or time just provide examples to be studied. Political philosophy is meta-politics, it's about the trends in politics and the theories we use to understand them. Real-world political systems have striking parallels in the evolution of the Internet: there was primitive anarchy before Eternal September, the era of walled gardens resembled that of Ancient Greek city-states, which were succeeded by more-or-less liberal regimes following the geographical territories of real-world governments. Because of its rapid evolution, mass participation, and highly complex human interaction, the Internet should be subjected to the sorts of questions that political philosophers ask. On the Internet, what is freedom? Do we have obligations to those in control? To each other? What rights do we have? What can we own? Once we know the way it is, we can ask how it should be...
-
-
21:36
»
SecDocs
Authors:
Harald Welte Steve Markgraf Tags:
GSM phone Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: In recent years, we have seen several Free Software projects implementing the network side of the GSM protocol. In 2010, OsmocomBB was started to create a free software implementation of the telephone-side. The OsmocomBB project is a Free Software implementation of the GSM protocol stack running on a mobile phone. For decades, the cellular industry comprised by cellphone chipset makers and network operators keep their hardware and system-level software as well as GSM protocol stack implementations closed. As a result, it was never possible to send arbitrary data at the lower levels of the GSM protocol stack. Existing phones only allow application-level data to be specified, such as SMS messages, IP over GPRS or circuit-switched data (CSD). Using OsmocomBB, the security researcher finally has a tool equivalent to an Ethernet card in the TCP/IP protocol world: A simple transceiver that will send arbitrary protocol messages to a GSM network.
-
-
5:01
»
Hack a Day
As a web developer and designer, [Victor] has a habit of putting a very nice ASCII signature in an HTML comment at the top of every web page he designs. He was inspired by seeing others do this, and this piqued his curiosity to see who else was doing this. His idea was to scan [...]
-
-
5:01
»
Hack a Day
An old book – the smell, the texture of the slowly rotting paper, and the smudges and margin notes accrued over decades – is one of the finer points in life taken for granted much too often. We’re bombarded with high precision vector typefaces all day, but [Dan]‘s Avería font is beautiful in its irregularity. [Dan] [...]
-
-
21:33
»
SecDocs
Authors:
Felix Gröbert Tags:
cryptography Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: In this talk I demonstrate our research and the implementation of methods to detect cryptographic algorithms and their parameters in software. Based on our observations on cryptographic code, I will point out several inherent characteristics to design signature-based and generic identification methods. Using dynamic binary instrumentation, we record instructions of a program during runtime and create a fine-grained trace. We implement a trace analysis tool, which also provides methods to reconstruct high-level information from a trace, for example control flow graphs or loops, to detect cryptographic algorithms and their parameters. With the results of this work, encrypted data, sent by a malicious program for example, may be decrypted and used by an analyst to gain further insight on the behavior of the analyzed binary executable. Applications include de-DRM'ing, security auditing, and malware C&C analysis. After the talk we will demonstrate the functionality with a ransomware which uses cryptographic primitives and release the implementation to the public.
-
21:33
»
SecDocs
Authors:
Felix Gröbert Tags:
cryptography Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: In this talk I demonstrate our research and the implementation of methods to detect cryptographic algorithms and their parameters in software. Based on our observations on cryptographic code, I will point out several inherent characteristics to design signature-based and generic identification methods. Using dynamic binary instrumentation, we record instructions of a program during runtime and create a fine-grained trace. We implement a trace analysis tool, which also provides methods to reconstruct high-level information from a trace, for example control flow graphs or loops, to detect cryptographic algorithms and their parameters. With the results of this work, encrypted data, sent by a malicious program for example, may be decrypted and used by an analyst to gain further insight on the behavior of the analyzed binary executable. Applications include de-DRM'ing, security auditing, and malware C&C analysis. After the talk we will demonstrate the functionality with a ransomware which uses cryptographic primitives and release the implementation to the public.
-
21:33
»
SecDocs
Authors:
Felix Gröbert Tags:
cryptography Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: In this talk I demonstrate our research and the implementation of methods to detect cryptographic algorithms and their parameters in software. Based on our observations on cryptographic code, I will point out several inherent characteristics to design signature-based and generic identification methods. Using dynamic binary instrumentation, we record instructions of a program during runtime and create a fine-grained trace. We implement a trace analysis tool, which also provides methods to reconstruct high-level information from a trace, for example control flow graphs or loops, to detect cryptographic algorithms and their parameters. With the results of this work, encrypted data, sent by a malicious program for example, may be decrypted and used by an analyst to gain further insight on the behavior of the analyzed binary executable. Applications include de-DRM'ing, security auditing, and malware C&C analysis. After the talk we will demonstrate the functionality with a ransomware which uses cryptographic primitives and release the implementation to the public.
-
-
13:01
»
Hack a Day
[notch], the mastermind behind Minecraft, is working on a new game. It’s called 0x10c (pronounced ‘trillek’, we think) and promises to teach an entire new generation the joys of assembly programming on a 1980s-era computer. The setup for the game is nerdy/awesome enough to make [Douglas Adams] blush; a ‘deep sleep core’ was invented in 1988 [...]
-
-
13:05
»
Hack a Day
Most of us have been faced with the anguish of being shot in the head repeatedly by 12-year-olds. There are also the times when we’re overjoyed by defeating the Mother Brain and making it out of the caverns of Zebes. If we wanted to scientifically quantify how happy, sad, or angry we are while playing video [...]
-
-
22:01
»
Packet Storm Security Advisories
Cisco Security Advisory - A vulnerability exists in the Cisco IOS Software that may allow a remote application or device to exceed its authorization level when authentication, authorization, and accounting (AAA) authorization is used. This vulnerability requires that the HTTP or HTTPS server is enabled on the Cisco IOS device. Products that are not running Cisco IOS Software are not vulnerable. Cisco has released free software updates that address these vulnerabilities. The HTTP server may be disabled as a workaround for the vulnerability described in this advisory.
-
22:01
»
Packet Storm Security Recent Files
Cisco Security Advisory - A vulnerability exists in the Cisco IOS Software that may allow a remote application or device to exceed its authorization level when authentication, authorization, and accounting (AAA) authorization is used. This vulnerability requires that the HTTP or HTTPS server is enabled on the Cisco IOS device. Products that are not running Cisco IOS Software are not vulnerable. Cisco has released free software updates that address these vulnerabilities. The HTTP server may be disabled as a workaround for the vulnerability described in this advisory.
-
22:01
»
Packet Storm Security Misc. Files
Cisco Security Advisory - A vulnerability exists in the Cisco IOS Software that may allow a remote application or device to exceed its authorization level when authentication, authorization, and accounting (AAA) authorization is used. This vulnerability requires that the HTTP or HTTPS server is enabled on the Cisco IOS device. Products that are not running Cisco IOS Software are not vulnerable. Cisco has released free software updates that address these vulnerabilities. The HTTP server may be disabled as a workaround for the vulnerability described in this advisory.
-
22:01
»
Packet Storm Security Advisories
Cisco Security Advisory - The Secure Shell (SSH) server implementation in Cisco IOS Software and Cisco IOS XE Software contains a denial of service (DoS) vulnerability in the SSH version 2 (SSHv2) feature. An unauthenticated, remote attacker could exploit this vulnerability by attempting a reverse SSH login with a crafted username. Successful exploitation of this vulnerability could allow an attacker to create a DoS condition by causing the device to reload. Repeated exploits could create a sustained DoS condition. The SSH server in Cisco IOS Software and Cisco IOS XE Software is an optional service, but its use is highly recommended as a security best practice for the management of Cisco IOS devices. Devices that are not configured to accept SSHv2 connections are not affected by this vulnerability. Cisco has released free software updates that address this vulnerability.
-
22:01
»
Packet Storm Security Recent Files
Cisco Security Advisory - The Secure Shell (SSH) server implementation in Cisco IOS Software and Cisco IOS XE Software contains a denial of service (DoS) vulnerability in the SSH version 2 (SSHv2) feature. An unauthenticated, remote attacker could exploit this vulnerability by attempting a reverse SSH login with a crafted username. Successful exploitation of this vulnerability could allow an attacker to create a DoS condition by causing the device to reload. Repeated exploits could create a sustained DoS condition. The SSH server in Cisco IOS Software and Cisco IOS XE Software is an optional service, but its use is highly recommended as a security best practice for the management of Cisco IOS devices. Devices that are not configured to accept SSHv2 connections are not affected by this vulnerability. Cisco has released free software updates that address this vulnerability.
-
22:01
»
Packet Storm Security Misc. Files
Cisco Security Advisory - The Secure Shell (SSH) server implementation in Cisco IOS Software and Cisco IOS XE Software contains a denial of service (DoS) vulnerability in the SSH version 2 (SSHv2) feature. An unauthenticated, remote attacker could exploit this vulnerability by attempting a reverse SSH login with a crafted username. Successful exploitation of this vulnerability could allow an attacker to create a DoS condition by causing the device to reload. Repeated exploits could create a sustained DoS condition. The SSH server in Cisco IOS Software and Cisco IOS XE Software is an optional service, but its use is highly recommended as a security best practice for the management of Cisco IOS devices. Devices that are not configured to accept SSHv2 connections are not affected by this vulnerability. Cisco has released free software updates that address this vulnerability.
-
21:46
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS Software contains a denial of service (DoS) vulnerability in the Wide Area Application Services (WAAS) Express feature that could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Cisco IOS Software also contains a DoS vulnerability in the Measurement, Aggregation, and Correlation Engine (MACE) feature that could allow an unauthenticated, remote attacker to cause the router to reload. An attacker could exploit these vulnerabilities by sending transit traffic through a router configured with WAAS Express or MACE. Successful exploitation of these vulnerabilities could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Repeated exploits could allow a sustained DoS condition. Cisco has released free software updates that address these vulnerabilities.
-
21:46
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS Software contains a denial of service (DoS) vulnerability in the Wide Area Application Services (WAAS) Express feature that could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Cisco IOS Software also contains a DoS vulnerability in the Measurement, Aggregation, and Correlation Engine (MACE) feature that could allow an unauthenticated, remote attacker to cause the router to reload. An attacker could exploit these vulnerabilities by sending transit traffic through a router configured with WAAS Express or MACE. Successful exploitation of these vulnerabilities could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Repeated exploits could allow a sustained DoS condition. Cisco has released free software updates that address these vulnerabilities.
-
21:46
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco IOS Software contains a denial of service (DoS) vulnerability in the Wide Area Application Services (WAAS) Express feature that could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Cisco IOS Software also contains a DoS vulnerability in the Measurement, Aggregation, and Correlation Engine (MACE) feature that could allow an unauthenticated, remote attacker to cause the router to reload. An attacker could exploit these vulnerabilities by sending transit traffic through a router configured with WAAS Express or MACE. Successful exploitation of these vulnerabilities could allow an unauthenticated, remote attacker to cause the router to leak memory or to reload. Repeated exploits could allow a sustained DoS condition. Cisco has released free software updates that address these vulnerabilities.
-
20:55
»
Packet Storm Security Advisories
Cisco Security Advisory - The Cisco IOS Software Internet Key Exchange (IKE) feature contains a denial of service (DoS) vulnerability. Cisco has released free software updates that address this vulnerability.
-
20:43
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS Software and Cisco IOS XE Software contain a vulnerability in the RSVP feature when used on a device configured with VPN routing and forwarding (VRF) instances. This vulnerability could allow an unauthenticated, remote attacker to cause an interface wedge, which can lead to loss of connectivity, loss of routing protocol adjacency, and other denial of service (DoS) conditions. This vulnerability could be exploited repeatedly to cause an extended DoS condition. A workaround is available to mitigate this vulnerability. Cisco has released free software updates that address this vulnerability.
-
20:43
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS Software and Cisco IOS XE Software contain a vulnerability in the RSVP feature when used on a device configured with VPN routing and forwarding (VRF) instances. This vulnerability could allow an unauthenticated, remote attacker to cause an interface wedge, which can lead to loss of connectivity, loss of routing protocol adjacency, and other denial of service (DoS) conditions. This vulnerability could be exploited repeatedly to cause an extended DoS condition. A workaround is available to mitigate this vulnerability. Cisco has released free software updates that address this vulnerability.
-
20:43
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco IOS Software and Cisco IOS XE Software contain a vulnerability in the RSVP feature when used on a device configured with VPN routing and forwarding (VRF) instances. This vulnerability could allow an unauthenticated, remote attacker to cause an interface wedge, which can lead to loss of connectivity, loss of routing protocol adjacency, and other denial of service (DoS) conditions. This vulnerability could be exploited repeatedly to cause an extended DoS condition. A workaround is available to mitigate this vulnerability. Cisco has released free software updates that address this vulnerability.
-
20:38
»
Packet Storm Security Advisories
Cisco Security Advisory - A vulnerability in the Multicast Source Discovery Protocol (MSDP) implementation of Cisco IOS Software and Cisco IOS XE Software could allow a remote, unauthenticated attacker to cause a reload of an affected device. Repeated attempts to exploit this vulnerability could result in a sustained denial of service (DoS) condition. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.
-
20:38
»
Packet Storm Security Recent Files
Cisco Security Advisory - A vulnerability in the Multicast Source Discovery Protocol (MSDP) implementation of Cisco IOS Software and Cisco IOS XE Software could allow a remote, unauthenticated attacker to cause a reload of an affected device. Repeated attempts to exploit this vulnerability could result in a sustained denial of service (DoS) condition. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.
-
20:38
»
Packet Storm Security Misc. Files
Cisco Security Advisory - A vulnerability in the Multicast Source Discovery Protocol (MSDP) implementation of Cisco IOS Software and Cisco IOS XE Software could allow a remote, unauthenticated attacker to cause a reload of an affected device. Repeated attempts to exploit this vulnerability could result in a sustained denial of service (DoS) condition. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.
-
-
21:06
»
Packet Storm Security Exploits
Ricoh DC Software DL-10 FTP server (SR10.exe) versions 1.1.0.6 and below remote buffer overflow proof of concept exploit that sends a malformed request.
-
21:06
»
Packet Storm Security Recent Files
Ricoh DC Software DL-10 FTP server (SR10.exe) versions 1.1.0.6 and below remote buffer overflow proof of concept exploit that sends a malformed request.
-
21:06
»
Packet Storm Security Misc. Files
Ricoh DC Software DL-10 FTP server (SR10.exe) versions 1.1.0.6 and below remote buffer overflow proof of concept exploit that sends a malformed request.
-
-
11:01
»
Hack a Day
With a simple digital TV USB capture card, you can build your own software defined radio or spectrum analyzer. While it may not be as cool as [Jeri Ellsworth]‘s SDR, it’s still very useful and only requires $20 in hardware. The only piece of hardware required for this build is a USB FM/DTV capture device with the [...]
-
-
22:38
»
SecDocs
Authors:
Meredith L. Patterson Tags:
security Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: Why is the overwhelming majority of common networked software still not secure, despite all effort to the contrary? Why is it almost certain to get exploited so long as attackers can craft its inputs? Why is it the case that no amount of effort seems to be enough to fix software that must speak certain protocols? The answer to these questions is that for many protocols and services currently in use on the Internet, the problem of recognizing and validating their "good", expected inputs from bad ones is either not well-posed or is undecidable (i. e., no algorithm can exist to solve it in the general case), which means that their implementations cannot even be comprehensively tested, let alone automatically checked for weaknesses or correctness. The designers' desire for more functionality has made these protocols effectively unsecurable. In this talk we'll draw a direct connection between this ubiquitous insecurity and basic computer science concepts of Turing completeness and theory of languages. We will show how well-meant protocol designs are doomed to their implementations becoming clusters of 0-days, and will show where to look for these 0-days. We will also discuss simple principles of how to avoid designing such protocols.
-
-
13:01
»
Hack a Day
[Troy Wright] acquired a lot of twenty broken Dell Axim PDAs. This type hardware was quite popular a decade ago, but looks archaic when compared to a modern cell phone. That’s why he was able to get them for a song. After a bit of work he managed to resurrect eight of the units, but was dismayed [...]
-
-
21:27
»
SecDocs
Authors:
Wes Faler Tags:
alghoritm Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: You write software. You test software. You know how to tell if the software is working. Automate your software testing sufficiently and you can let the computer do the writing for you! "Genetic Programming", especially "Cartesian Genetic Programming" (CGP), is a powerful tool for creating software and designing physical objects. See how to do CGP as we invent image filters for the Part Time Scientists' 3D cameras. Danger: Actual code will be shown!
-
21:27
»
SecDocs
Authors:
Wes Faler Tags:
alghoritm Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: You write software. You test software. You know how to tell if the software is working. Automate your software testing sufficiently and you can let the computer do the writing for you! "Genetic Programming", especially "Cartesian Genetic Programming" (CGP), is a powerful tool for creating software and designing physical objects. See how to do CGP as we invent image filters for the Part Time Scientists' 3D cameras. Danger: Actual code will be shown!
-
21:27
»
SecDocs
Authors:
Wes Faler Tags:
alghoritm Event:
Chaos Communication Congress 28th (28C3) 2011 Abstract: You write software. You test software. You know how to tell if the software is working. Automate your software testing sufficiently and you can let the computer do the writing for you! "Genetic Programming", especially "Cartesian Genetic Programming" (CGP), is a powerful tool for creating software and designing physical objects. See how to do CGP as we invent image filters for the Part Time Scientists' 3D cameras. Danger: Actual code will be shown!
-
-
10:22
»
Hack a Day
[Maxzillian] sent in a pretty amazing project he’s been beta testing called ReconstructMe. Even though this project is just the result of software developers getting bored at their job, there’s a lot of potential in the 3D scanning abilities of ReconstructMe. ReconstructMe is a software interface that allows anyone with a Kinect (or other 3D [...]
-
-
19:12
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco TelePresence Video Communication Servers running software versions prior to X7.0.1 contain vulnerabilities that could allow an attacker to cause a denial of service (DoS) condition. Cisco has released free software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities.
-
19:12
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco TelePresence Video Communication Servers running software versions prior to X7.0.1 contain vulnerabilities that could allow an attacker to cause a denial of service (DoS) condition. Cisco has released free software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities.
-
19:12
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco TelePresence Video Communication Servers running software versions prior to X7.0.1 contain vulnerabilities that could allow an attacker to cause a denial of service (DoS) condition. Cisco has released free software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities.
-
11:19
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Cius Software contains a denial of service vulnerability that could cause the device to stop responding. Devices running Cius Software Versions prior to 9.2(1) SR2 are vulnerable. A remote, unauthenticated attacker could exploit this vulnerability by sending malicious network traffic to affected devices. Cisco has released free software updates that address this vulnerability.
-
11:19
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Cius Software contains a denial of service vulnerability that could cause the device to stop responding. Devices running Cius Software Versions prior to 9.2(1) SR2 are vulnerable. A remote, unauthenticated attacker could exploit this vulnerability by sending malicious network traffic to affected devices. Cisco has released free software updates that address this vulnerability.
-
11:19
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Cius Software contains a denial of service vulnerability that could cause the device to stop responding. Devices running Cius Software Versions prior to 9.2(1) SR2 are vulnerable. A remote, unauthenticated attacker could exploit this vulnerability by sending malicious network traffic to affected devices. Cisco has released free software updates that address this vulnerability.
-
-
16:01
»
Hack a Day
[Richard] sent in a link to the Python controlled microcontroller he’s been working on. Unlike the previous portable Python boards we’ve seen, [Richard] thinks his pyMCU isn’t best used autonomously. This board is meant to be used only when connected to a computer and to serve as a bridge between the digital world of computers and our [...]
-
-
10:01
»
Hack a Day
Writing a paper in LaTeX will always result in beautiful output, but if you’d like to put that document up on the web you’re limited to two reasonable options: serve the document as a .PDF (with the horrors involves, although Chrome makes things much more palatable), or relying on third-party browser plugins like TeX The [...]
-
-
19:35
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco NX-OS Software is affected by a denial of service (DoS) vulnerability that could cause Cisco Nexus 1000v, 5000, and 7000 Series Switches that are running affected versions of Cisco NX-OS Software to reload when the IP stack processes a malformed IP packet. Cisco has released free software updates that address this vulnerability.
-
19:35
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco NX-OS Software is affected by a denial of service (DoS) vulnerability that could cause Cisco Nexus 1000v, 5000, and 7000 Series Switches that are running affected versions of Cisco NX-OS Software to reload when the IP stack processes a malformed IP packet. Cisco has released free software updates that address this vulnerability.
-
19:35
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco NX-OS Software is affected by a denial of service (DoS) vulnerability that could cause Cisco Nexus 1000v, 5000, and 7000 Series Switches that are running affected versions of Cisco NX-OS Software to reload when the IP stack processes a malformed IP packet. Cisco has released free software updates that address this vulnerability.
-
11:02
»
Hack a Day
It’s no secret that the 3D printer community is extremely fragmented. With three models of RepRaps, three printer kits from Makerbot, and hundreds of ‘printers of the week,’ it’s extremely frustrating for beginners to wrap their heads around the pros and cons of each machine. The software for these printers is segmented nearly as much [...]
-
-
12:45
»
Hack a Day
So let’s say your using an Arduino in your project. You already have the hardware-based serial interface working with one portion of the project and need a second serial port for unrelated hardware. The obvious solution is to write one in software. But this is a place where working in the Arduino environment gets really [...]
-
-
9:25
»
Hack a Day
[JD] at isotope11 was looking for a way to get instant feedback whenever a developer broke a piece of software they were working on. After finding a 48 inch tall traffic light, he knew what he had to do. Now, the entire development team knows the status of their code from a traffic light hanging [...]
-
-
13:32
»
SecDocs
Authors:
Russell Spitler Tags:
phone Event:
Black Hat Abu Dhabi 2011 Abstract: Mobile devices and the risk posed by vulnerabilities in the software that runs them are proliferating. This talk scrutinizes challenges faced in securing mobile apps and contrasts them with legacy software security initiatives. We discuss how outsourcing confounds security efforts, how the mobile app lifecycle makes risk a hot potato, and conclude with the top mobile threats and how to avoid them.
-
10:01
»
Hack a Day
We find the programming challenge of game-playing bots to be fascinating. Take a look at this Python bot which plays Burrito Bison all the way through (video after the break). This is a totally pedantic exercise which has no purpose, other than to hone your mastery of a certain programming problem. And to that we [...]
-
-
10:01
»
Hack a Day
As weird as it might sound, there’s a way to use Google documents as a web proxy. The image above is a screenshot of [Antonio] demonstrating how he can view text data from any site through the web giant’s cloud applications. Certain sites may be blocked from your location, but the big G can load [...]
-
-
9:58
»
Hack a Day
This temperature display may not knock your socks off, but it’s a simple demonstration of how you can used vector graphics as a web readout for data (translated). [Luca] wrote this four page tutorial to help others, he makes it look really easy, and the sky’s the limit on eye candy once you get he basics [...]
-
-
11:36
»
Hack a Day
If you’ve ever wanted to program a microcontroller “in the cloud,” you might want to head over to Inventor Town, an online IDE that allows you to write and compile firmware for the MSP430 series of microcontrollers. After logging in with your Google account, you’re presented with a ‘My Projects’ page. From there, you can [...]
-
-
15:33
»
Hack a Day
[Karl] set out to improve the depth image that the Kinect camera is able to feed into a computer. He’s come up with a pre-processing package which smooths the depth data in real-time. There are a few problems here, one is that the Kinect has a fairly low resolution, it is also depth limited to [...]
-
-
17:59
»
SecuriTeam
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Zenworks Software Packaging.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
6:01
»
Hack a Day
You’re not still playing nDoom in black and white, are you? What decade do live in? Thankfully, the Doom port for TI-nspire calculators has been upgraded to support color. That is if you’ve got the hardware to run it. The video after the break (and the image above) shows a TI-nspire CX running the popular [...]
-
-
7:01
»
Hack a Day
Last semester, [Peter], [Jared], and [Jeremy] took a course on embedded systems. They managed to turn out a very accurate copy of the classic Space Invaders in their class. Not wanting good code to go to waste, they decided to develop two player Space Invaders, and we wouldn’t mind testing it out. The guys built [...]
-
-
7:34
»
Packet Storm Security Recent Files
Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.
-
7:34
»
Packet Storm Security Tools
Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.
-
7:34
»
Packet Storm Security Misc. Files
Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.
-
-
22:32
»
Packet Storm Security Recent Files
Whitepaper called Hardware Involved Software Attacks. Computer security vulnerabilities involving hardware are under-represented within the security industry. With a growing number of attackers, malware, and researchers moving beyond pure software attack scenarios and into scenarios incorporating a hardware element, it is important to start laying a foundation on how to understand, characterize, and defend against these types of hybrid attacks. This paper introduces and details a starting taxonomy of security attacks called hardware involved software attacks, in an effort to further security community awareness of hardware security and its role in upholding the security of the PC platform.
-
22:32
»
Packet Storm Security Misc. Files
Whitepaper called Hardware Involved Software Attacks. Computer security vulnerabilities involving hardware are under-represented within the security industry. With a growing number of attackers, malware, and researchers moving beyond pure software attack scenarios and into scenarios incorporating a hardware element, it is important to start laying a foundation on how to understand, characterize, and defend against these types of hybrid attacks. This paper introduces and details a starting taxonomy of security attacks called hardware involved software attacks, in an effort to further security community awareness of hardware security and its role in upholding the security of the PC platform.
-
-
16:50
»
Packet Storm Security Advisories
RSA, The Security Division of EMC, announces security fixes and improvements for RSA SecurID Software Token 4.1 for Microsoft Windows. This release addresses an Insecure Library Loading vulnerability within RSA SecurID Software Token for Windows. This release also provides an alternate installation package for customers who do not require the software token automation API features of the product.
-
16:50
»
Packet Storm Security Recent Files
RSA, The Security Division of EMC, announces security fixes and improvements for RSA SecurID Software Token 4.1 for Microsoft Windows. This release addresses an Insecure Library Loading vulnerability within RSA SecurID Software Token for Windows. This release also provides an alternate installation package for customers who do not require the software token automation API features of the product.
-
16:50
»
Packet Storm Security Misc. Files
RSA, The Security Division of EMC, announces security fixes and improvements for RSA SecurID Software Token 4.1 for Microsoft Windows. This release addresses an Insecure Library Loading vulnerability within RSA SecurID Software Token for Windows. This release also provides an alternate installation package for customers who do not require the software token automation API features of the product.
-
-
7:51
»
Packet Storm Security Exploits
Hillstone Software HS TFTP Server suffers from a denial of service vulnerability. Proof of concept exploit included. The vulnerability is caused due to improper validation of a WRITE/READ request parameter containing a long file name, which allows remote attackers to crash the service.
-
7:51
»
Packet Storm Security Recent Files
Hillstone Software HS TFTP Server suffers from a denial of service vulnerability. Proof of concept exploit included. The vulnerability is caused due to improper validation of a WRITE/READ request parameter containing a long file name, which allows remote attackers to crash the service.
-
7:51
»
Packet Storm Security Misc. Files
Hillstone Software HS TFTP Server suffers from a denial of service vulnerability. Proof of concept exploit included. The vulnerability is caused due to improper validation of a WRITE/READ request parameter containing a long file name, which allows remote attackers to crash the service.
-
-
21:35
»
Packet Storm Security Exploits
Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method. The victim will first be required to trust the publisher Viscom Software. This Metasploit module has been designed to bypass DEP and ASLR under XP IE8, Vista and Win7 with Java support.
-
21:35
»
Packet Storm Security Recent Files
Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method. The victim will first be required to trust the publisher Viscom Software. This Metasploit module has been designed to bypass DEP and ASLR under XP IE8, Vista and Win7 with Java support.
-
21:35
»
Packet Storm Security Misc. Files
Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method. The victim will first be required to trust the publisher Viscom Software. This Metasploit module has been designed to bypass DEP and ASLR under XP IE8, Vista and Win7 with Java support.
-
-
13:56
»
Hack a Day
[Karl] wrote in to tell us about a software package called EagleUp that will import your Eagle CAD PCB designs into Google SketchUp. It bridges the gap between the two using the open source image processing software ImageMagick. As you can see above, you’ll end up with a beautifully rendered 3D model of your hardware. [...]
-
10:01
»
Hack a Day
The International Obfuscated C Code Contest is back. The stated goals of the IOCCC are to, “Write the most obscure C program, show the importance of programming style (by doing the opposite), stress the preprocessor to the breaking point, and illustrate some subtleties of the C language.” If you think you’re up to the task [...]
-
-
7:27
»
Packet Storm Security Advisories
Various antivirus software on Windows fails to detect, block and/or move malware if the executable file has only execution permission and no read, write, or other bits set.
-
7:27
»
Packet Storm Security Recent Files
Various antivirus software on Windows fails to detect, block and/or move malware if the executable file has only execution permission and no read, write, or other bits set.
-
7:27
»
Packet Storm Security Misc. Files
Various antivirus software on Windows fails to detect, block and/or move malware if the executable file has only execution permission and no read, write, or other bits set.
-
-
13:01
»
Hack a Day
Version 6 of the popular schematic and PCB layout software EAGLE is now in beta testing. The most notable change is the migration to XML file formats that we looked at last month. [PT] didn’t waste any time getting his hands on the software and giving it a thorough test drive. The image seen above [...]
-
-
7:01
»
Hack a Day
We know it’s shopped, but we can’t tell because of the pixels. PhD student [Kevin Karsch] along with a few other friends will be presenting their methods to render objects into preexisting photos at SIGGRAPH Asia next month. The paper (PDF…) covers how [Kevin] et al. go about putting impossible objects into photos. The user [...]
-
-
17:59
»
SecuriTeam
Cisco IOS XR software releases are affected by a Denial of Service vulnerability.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
11:01
»
Hack a Day
As the Open Source Hardware movement gathers steam, it has become clear that the tools to work collaboratively on hardware are in the dark ages when compared with slick frameworks like Git used to work on software projects. We’ve read a fair amount about this lately, but the idea of visual difference generation for PCB [...]
-
-
19:32
»
Packet Storm Security Advisories
Apple Security Advisory 2011-10-12-2 - An Apple TV software update is now available and addresses credential interception, spoofing, information disclosure, and various other vulnerabilities.
-
19:32
»
Packet Storm Security Recent Files
Apple Security Advisory 2011-10-12-2 - An Apple TV software update is now available and addresses credential interception, spoofing, information disclosure, and various other vulnerabilities.
-
19:32
»
Packet Storm Security Misc. Files
Apple Security Advisory 2011-10-12-2 - An Apple TV software update is now available and addresses credential interception, spoofing, information disclosure, and various other vulnerabilities.
-
19:28
»
Packet Storm Security Advisories
Apple Security Advisory 2011-10-12-1 - An iOS 5 software update is now available. It addresses an SSL check in CalDAV, a script injection issue in Calendar, issues in CFNetwork, and 90+ other security issues.
-
19:28
»
Packet Storm Security Recent Files
Apple Security Advisory 2011-10-12-1 - An iOS 5 software update is now available. It addresses an SSL check in CalDAV, a script injection issue in Calendar, issues in CFNetwork, and 90+ other security issues.
-
19:28
»
Packet Storm Security Misc. Files
Apple Security Advisory 2011-10-12-1 - An iOS 5 software update is now available. It addresses an SSL check in CalDAV, a script injection issue in Calendar, issues in CFNetwork, and 90+ other security issues.
-
-
16:07
»
Packet Storm Security Recent Files
libprngwrap is a preload-library (so that it doesn't require any changes to the software it alters) which replaces the libc rand() random() and *rand48() calls by code that gets data from /dev/urandom. This might be a little bit more secure.
-
16:07
»
Packet Storm Security Misc. Files
libprngwrap is a preload-library (so that it doesn't require any changes to the software it alters) which replaces the libc rand() random() and *rand48() calls by code that gets data from /dev/urandom. This might be a little bit more secure.
-
-
3:10
»
Packet Storm Security Advisories
StarMoney Banking Software version 8.0 suffers from multiple input validation vulnerabilities that can lead to session hijacking, javascript insertion, and more.
-
3:10
»
Packet Storm Security Recent Files
StarMoney Banking Software version 8.0 suffers from multiple input validation vulnerabilities that can lead to session hijacking, javascript insertion, and more.
-
3:10
»
Packet Storm Security Misc. Files
StarMoney Banking Software version 8.0 suffers from multiple input validation vulnerabilities that can lead to session hijacking, javascript insertion, and more.
-
-
14:56
»
Packet Storm Security Advisories
Cisco Security Advisory - A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. Cisco has released free software updates that address this vulnerability. There are no workarounds available to mitigate this vulnerability other than disabling the Smart Install feature.
-
14:56
»
Packet Storm Security Recent Files
Cisco Security Advisory - A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. Cisco has released free software updates that address this vulnerability. There are no workarounds available to mitigate this vulnerability other than disabling the Smart Install feature.
-
14:56
»
Packet Storm Security Misc. Files
Cisco Security Advisory - A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. Cisco has released free software updates that address this vulnerability. There are no workarounds available to mitigate this vulnerability other than disabling the Smart Install feature.
-
14:53
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS Software contains two vulnerabilities related to Cisco IOS Intrusion Prevention System (IPS) and Cisco IOS Zone-Based Firewall features.
-
14:53
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS Software contains two vulnerabilities related to Cisco IOS Intrusion Prevention System (IPS) and Cisco IOS Zone-Based Firewall features.
-
14:53
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco IOS Software contains two vulnerabilities related to Cisco IOS Intrusion Prevention System (IPS) and Cisco IOS Zone-Based Firewall features.
-
14:51
»
Packet Storm Security Advisories
Cisco Security Advisory - Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software and Cisco IOS XE Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or trigger memory leaks that may result in system instabilities. Affected devices would need to be configured to process SIP messages for these vulnerabilities to be exploitable. Cisco has released free software updates that address these vulnerabilities. There are no workarounds for devices that must run SIP; however, mitigations are available to limit exposure to the vulnerabilities.
-
14:51
»
Packet Storm Security Recent Files
Cisco Security Advisory - Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software and Cisco IOS XE Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or trigger memory leaks that may result in system instabilities. Affected devices would need to be configured to process SIP messages for these vulnerabilities to be exploitable. Cisco has released free software updates that address these vulnerabilities. There are no workarounds for devices that must run SIP; however, mitigations are available to limit exposure to the vulnerabilities.
-
14:51
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software and Cisco IOS XE Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or trigger memory leaks that may result in system instabilities. Affected devices would need to be configured to process SIP messages for these vulnerabilities to be exploitable. Cisco has released free software updates that address these vulnerabilities. There are no workarounds for devices that must run SIP; however, mitigations are available to limit exposure to the vulnerabilities.
-
14:10
»
Packet Storm Security Advisories
Cisco Security Advisory - The Cisco IOS Software network address translation (NAT) feature contains multiple denial of service (DoS) vulnerabilities in the translation of multiple protocols. Cisco has released free software updates that address these vulnerabilities.
-
14:10
»
Packet Storm Security Recent Files
Cisco Security Advisory - The Cisco IOS Software network address translation (NAT) feature contains multiple denial of service (DoS) vulnerabilities in the translation of multiple protocols. Cisco has released free software updates that address these vulnerabilities.
-
14:10
»
Packet Storm Security Misc. Files
Cisco Security Advisory - The Cisco IOS Software network address translation (NAT) feature contains multiple denial of service (DoS) vulnerabilities in the translation of multiple protocols. Cisco has released free software updates that address these vulnerabilities.
-
13:55
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS Software is affected by two vulnerabilities that cause a Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a Multiprotocol Label Switching (MPLS) domain. Workarounds that mitigate these vulnerabilities are available.
-
13:55
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS Software is affected by two vulnerabilities that cause a Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a Multiprotocol Label Switching (MPLS) domain. Workarounds that mitigate these vulnerabilities are available.
-
13:54
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS Software contains a memory leak vulnerability in the Data-Link Switching (DLSw) feature that could result in a device reload when processing crafted IP Protocol 91 packets. Cisco has released free software updates that address this vulnerability.
-
13:54
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS Software contains a memory leak vulnerability in the Data-Link Switching (DLSw) feature that could result in a device reload when processing crafted IP Protocol 91 packets. Cisco has released free software updates that address this vulnerability.
-
-
22:39
»
Packet Storm Security Exploits
Help Desk Software version 1.1b suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities.
-
-
15:58
»
Packet Storm Security Advisories
Cisco Security Advisory - Two vulnerabilities exist in Cisco Unified Service Monitor and Cisco Unified Operations Manager software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
15:58
»
Packet Storm Security Recent Files
Cisco Security Advisory - Two vulnerabilities exist in Cisco Unified Service Monitor and Cisco Unified Operations Manager software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
15:47
»
Packet Storm Security Advisories
Cisco Security Advisory - Two vulnerabilities exist in CiscoWorks LAN Management Solution software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
15:47
»
Packet Storm Security Recent Files
Cisco Security Advisory - Two vulnerabilities exist in CiscoWorks LAN Management Solution software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
15:47
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Two vulnerabilities exist in CiscoWorks LAN Management Solution software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
-
15:01
»
Hack a Day
In a little more than a month, tens of thousands of people around the world will attend a class on Artificial Intelligence at Stanford. Registration for this class is still open for both class ‘tracks’. The “basic” track is simply watching lectures and answering quizzes, or a slightly more advanced version of MIT OpenCourseware or [...]
-
1:53
»
SecDocs
Tags:
Windows hardening secure development Event:
Black Hat USA 2010 Abstract: Microsoft has implemented lots of useful functionality in Windows that they use in their own products. Many of these features can be used to enhance the security of third party applications, but not many developers or software architects know about them. This talk will detail some of the technical underpinnings of Windows features like UAC, IE protected mode and Terminal Serivces and show how they can be used to defend your own software from attack.
-
1:53
»
SecDocs
Tags:
Windows hardening secure development Event:
Black Hat USA 2010 Abstract: Microsoft has implemented lots of useful functionality in Windows that they use in their own products. Many of these features can be used to enhance the security of third party applications, but not many developers or software architects know about them. This talk will detail some of the technical underpinnings of Windows features like UAC, IE protected mode and Terminal Serivces and show how they can be used to defend your own software from attack.
-
-
1:08
»
SecDocs
Authors:
Fabian Mihailowitsch Tags:
keylogger Event:
Hashdays 2010 Abstract: Hardware keyloggers are tiny devices that are plugged between a computer keyboard and a computer. They are available for PS/2 as well as USB keyboards. Once plugged, they are able to record all key strokes and store them using an internal memory. Thereby the main focus is to stay undetected. Most manufacturers promote their models cannot be detected by software and thus have an advantage over software based keyloggers. However that's not correct. Hardware keyloggers make slight changes to the interaction between the keyboard and the computer. These changes can be detected by software and used to determine whether a hardware keylogger is present. During this talk various techniques will be presented to detect hardware keyloggers theoretical and practical. Finally a PoC tool will be released, that implements these described techniques.
-
-
11:35
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs that are running software versions prior to TC4.0.0 or F9.1 contain a vulnerability that could allow an attacker to cause a denial of service. Cisco has released free software updates that address this vulnerability.
-
11:35
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs that are running software versions prior to TC4.0.0 or F9.1 contain a vulnerability that could allow an attacker to cause a denial of service. Cisco has released free software updates that address this vulnerability.
-
11:35
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs that are running software versions prior to TC4.0.0 or F9.1 contain a vulnerability that could allow an attacker to cause a denial of service. Cisco has released free software updates that address this vulnerability.
-
-
17:16
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions. Cisco has released free updated software for most supported releases. A security patch file is also available for all supported versions that will remediate this issue. The patch may be applied to active systems without requiring a reload. Customers are advised to apply a fixed version or upgrade to a fixed train. Customers who need to stay on a version for which updated software is not currently available or who can not immediately apply the update are advised to apply the patch. No workarounds are available for this issue.
-
17:16
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions. Cisco has released free updated software for most supported releases. A security patch file is also available for all supported versions that will remediate this issue. The patch may be applied to active systems without requiring a reload. Customers are advised to apply a fixed version or upgrade to a fixed train. Customers who need to stay on a version for which updated software is not currently available or who can not immediately apply the update are advised to apply the patch. No workarounds are available for this issue.
-
17:16
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions. Cisco has released free updated software for most supported releases. A security patch file is also available for all supported versions that will remediate this issue. The patch may be applied to active systems without requiring a reload. Customers are advised to apply a fixed version or upgrade to a fixed train. Customers who need to stay on a version for which updated software is not currently available or who can not immediately apply the update are advised to apply the patch. No workarounds are available for this issue.
-
-
12:01
»
Hack a Day
Programmers don’t need to get good at a game to achieve a high score, they code a bot for that instead. Take [hypnotizd] for instance. He was learning to write in the C# language and decided to make a bot that plays Bejeweled Blitz on Facebook. He figures he took between 48 and 72 hours [...]
-
-
5:01
»
Hack a Day
[Hasith] sent in this project where he goes through the process of designing a one instruction CPU in Verilog. It may not win a contest for the coolest build on Hack A Day, but we really do appreciate the “applied nerd” aspect of this build. With only one instruction, an OISC is a lot simpler [...]
-
-
5:07
»
Hack a Day
[Mike Field] has always been interested in the Mandelbrot Set since he first read about it back in the ‘80s. Having coded it on a Commodore VIC20 back int he day, he always returned to the Mandelbrot set when he wanted to try out some new programming technology. He wanted to delve deeper into the [...]
-
-
12:20
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Media Experience Engine (MXE) 5600 devices that are running Cisco Media Processing Software releases prior to 1.2 ship with a root administrator account that is enabled by default with a default password. An unauthorized user could use this account to modify the software configuration and operating system settings or gain complete administrative control of the device. A software upgrade is not required to resolve this vulnerability. Customers can change the root account password by issuing a configuration command on affected engines. The workarounds detailed in this document provide instructions for changing the root account password.
-
12:20
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Media Experience Engine (MXE) 5600 devices that are running Cisco Media Processing Software releases prior to 1.2 ship with a root administrator account that is enabled by default with a default password. An unauthorized user could use this account to modify the software configuration and operating system settings or gain complete administrative control of the device. A software upgrade is not required to resolve this vulnerability. Customers can change the root account password by issuing a configuration command on affected engines. The workarounds detailed in this document provide instructions for changing the root account password.
-
12:20
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Media Experience Engine (MXE) 5600 devices that are running Cisco Media Processing Software releases prior to 1.2 ship with a root administrator account that is enabled by default with a default password. An unauthorized user could use this account to modify the software configuration and operating system settings or gain complete administrative control of the device. A software upgrade is not required to resolve this vulnerability. Customers can change the root account password by issuing a configuration command on affected engines. The workarounds detailed in this document provide instructions for changing the root account password.
-
11:49
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
11:49
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
11:49
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability. Cisco has released free software updates that address these vulnerabilities. There are no workarounds available to mitigate these vulnerabilities.
-
-
11:22
»
Hack a Day
The folks at Return Infinity just released a new version of their BareMetal OS, a 64-bit operating system written entirely in assembly. The goal of the BareMetal project, which includes a stripped-down bootloader and a cluster computing platform is to get away from the inefficient obfuscated machine code generated by higher level languages like C/C++ [...]
-
-
19:04
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS XR Software contains a vulnerability in the SSH application that may result in a denial of service condition when the SSH version 1 (SSHv1) protocol is used. The vulnerability is a result of unremoved sshd_lock files consuming all available space in the /tmp filesystem. Cisco has released free software updates that address this vulnerability.
-
19:04
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS XR Software contains a vulnerability in the SSH application that may result in a denial of service condition when the SSH version 1 (SSHv1) protocol is used. The vulnerability is a result of unremoved sshd_lock files consuming all available space in the /tmp filesystem. Cisco has released free software updates that address this vulnerability.
-
19:03
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS XR Software Releases 3.9.0, 3.9.1, 3.9.2, 4.0.0, 4.0.1, 4.0.2, and 4.1.0 are affected by a vulnerability that an unauthenticated, remote user could use to trigger a reload of the Shared Port Adapters (SPA) Interface Processor by sending specific IP version 4 (IPv4) packets to an affected device. Cisco has released free Software Maintenance Units (SMU) that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
-
19:03
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS XR Software Releases 3.9.0, 3.9.1, 3.9.2, 4.0.0, 4.0.1, 4.0.2, and 4.1.0 are affected by a vulnerability that an unauthenticated, remote user could use to trigger a reload of the Shared Port Adapters (SPA) Interface Processor by sending specific IP version 4 (IPv4) packets to an affected device. Cisco has released free Software Maintenance Units (SMU) that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
-
19:03
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco IOS XR Software Releases 3.9.0, 3.9.1, 3.9.2, 4.0.0, 4.0.1, 4.0.2, and 4.1.0 are affected by a vulnerability that an unauthenticated, remote user could use to trigger a reload of the Shared Port Adapters (SPA) Interface Processor by sending specific IP version 4 (IPv4) packets to an affected device. Cisco has released free Software Maintenance Units (SMU) that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
-
18:50
»
Packet Storm Security Advisories
Cisco Security Advisory - Cisco IOS XR Software Releases 3.8.3, 3.8.4, and 3.9.1 are affected by a vulnerability that an unauthenticated, remote user can trigger by sending specific IP version 4 (IPv4) packets to or through an affected device. Successful exploitation could cause the NetIO process to restart. Under a sustained attack, the Cisco CRS Modular Services Card (MSC) on a Cisco Carrier Routing System (CRS) or a Line Card on a Cisco 12000 Series Router or Cisco ASR 9000 Series Aggregation Services Router will reload. Cisco has released free Software Maintenance Units (SMU) that address this vulnerability. There are no workarounds for this vulnerability.
-
18:50
»
Packet Storm Security Recent Files
Cisco Security Advisory - Cisco IOS XR Software Releases 3.8.3, 3.8.4, and 3.9.1 are affected by a vulnerability that an unauthenticated, remote user can trigger by sending specific IP version 4 (IPv4) packets to or through an affected device. Successful exploitation could cause the NetIO process to restart. Under a sustained attack, the Cisco CRS Modular Services Card (MSC) on a Cisco Carrier Routing System (CRS) or a Line Card on a Cisco 12000 Series Router or Cisco ASR 9000 Series Aggregation Services Router will reload. Cisco has released free Software Maintenance Units (SMU) that address this vulnerability. There are no workarounds for this vulnerability.
-
18:50
»
Packet Storm Security Misc. Files
Cisco Security Advisory - Cisco IOS XR Software Releases 3.8.3, 3.8.4, and 3.9.1 are affected by a vulnerability that an unauthenticated, remote user can trigger by sending specific IP version 4 (IPv4) packets to or through an affected device. Successful exploitation could cause the NetIO process to restart. Under a sustained attack, the Cisco CRS Modular Services Card (MSC) on a Cisco Carrier Routing System (CRS) or a Line Card on a Cisco 12000 Series Router or Cisco ASR 9000 Series Aggregation Services Router will reload. Cisco has released free Software Maintenance Units (SMU) that address this vulnerability. There are no workarounds for this vulnerability.
-
-
11:21
»
Hack a Day
One thing we learned by watching [Alton Brown] on all of those Good Eats episodes is that a multitasker is way better than a unitasker. [Joost] is thinking along the same lines by taking a fantastic tool and adding a useful function to it. His software project turns a USB Saleae Logic Analyzer into a signal [...]
-
-
23:09
»
SecuriTeam
Cisco Network Admission Control (NAC) Guest Server system software contains a vulnerability in the RADIUS authentication software.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!