«
Expand/Collapse
725 items tagged "windows"
Related tags:
vista [+],
shellcode [+],
service microsoft [+],
player [+],
microsoft windows media [+],
microsoft [+],
service vulnerability [+],
poc [+],
paper [+],
based buffer overflow [+],
windows servers [+],
server [+],
security [+],
buffer overflow vulnerability [+],
windows security [+],
hat europe [+],
free error [+],
europe [+],
zipx [+],
windows server [+],
unauthorized access [+],
truetype font [+],
symantec [+],
remote buffer overflow [+],
proof of concept [+],
overflow [+],
microsoft windows media player [+],
exploits [+],
exec [+],
backup exec [+],
windows 2000 [+],
web context [+],
traversal [+],
test environment [+],
system distribution [+],
remote buffer overflow vulnerability [+],
recycle [+],
memory corruption [+],
mac os [+],
info2 [+],
info [+],
hooking [+],
file deletion [+],
english windows [+],
directory traversal [+],
directory [+],
david litchfield [+],
cesar cerrudo [+],
authors [+],
aslr [+],
asia [+],
apple safari [+],
microsoft windows [+],
zed attack [+],
zap [+],
x player [+],
windows versions [+],
windows version [+],
windows port [+],
windows box [+],
viper [+],
url [+],
ultimate [+],
tool [+],
time component [+],
time behaviour [+],
time [+],
testing tool [+],
tcp [+],
stack buffer [+],
spoof [+],
security experience [+],
security authors [+],
security 2002 [+],
security 2001 [+],
script [+],
safari for windows [+],
safari [+],
remote intrusion [+],
readlayoutfile [+],
proxy [+],
port [+],
microsoft windows vista [+],
malware [+],
kernel function [+],
k lite codec pack [+],
k lite codec [+],
internet [+],
installer [+],
heap [+],
forensics [+],
dvd x player [+],
dns [+],
digital video recording [+],
csrss [+],
critical vulnerability [+],
codebase [+],
clickonce [+],
ccmplayer [+],
buffer overflow exploit [+],
buffer overflow [+],
automation component [+],
assembly [+],
arp spoofing [+],
application level [+],
application installer [+],
afd [+],
black hat [+],
zip file [+],
zip [+],
xp x64 [+],
xampp [+],
windows phone [+],
windows operation [+],
windows operating systems [+],
windows media player [+],
windows internet name service [+],
win32k [+],
vipin kumar [+],
userland [+],
udp port [+],
tyler [+],
token [+],
todd feinman [+],
timer [+],
technical underpinnings [+],
steve riley [+],
standing on the shoulders [+],
software architects [+],
smb [+],
sid [+],
shutdown windows [+],
shutdown [+],
shatter proofing [+],
scripts [+],
removal guide [+],
removal [+],
registry entries [+],
provisioning services [+],
provisioning [+],
prevention mechanism [+],
presentation [+],
per [+],
overflows [+],
ollie whitehouse [+],
nitin kumar vipin kumar tags [+],
msvcrt [+],
microsoft crash [+],
mhtml [+],
messageboxa [+],
message templates [+],
memory [+],
malicious software [+],
magnifier [+],
local [+],
larry leibrock [+],
kostya kortchinsky [+],
kinect [+],
kernel dos [+],
jonathan lindsay [+],
internet name service [+],
inline [+],
information disclosure vulnerability [+],
impersonation [+],
human readable format [+],
httpconsole [+],
http [+],
hosts [+],
hardening [+],
grokevt [+],
framework 4 [+],
formatted request [+],
fax [+],
exploit [+],
emmanuel bouillon [+],
dos [+],
domain authentication [+],
design mistakes [+],
dead authors [+],
david goldman [+],
data access component [+],
data [+],
cryptographic algorithms [+],
cross [+],
createprocessa [+],
crash [+],
conversion tool [+],
command line interface [+],
color [+],
client [+],
citrix [+],
calc [+],
busting [+],
authentication protocols [+],
authentication mechanisms [+],
authentication mechanism [+],
authentication [+],
ajax [+],
agustin azubel [+],
advanced [+],
Tools [+],
Software [+],
BackTrack [+],
code execution [+],
privilege escalation vulnerability [+],
denial of service [+],
vulnerability [+],
usa [+],
local privilege escalation [+],
kernel [+],
yoshiaki [+],
wrq [+],
wouters [+],
world authors [+],
world [+],
wlsi [+],
wins [+],
windows picture and fax viewer [+],
windows passwords [+],
windows nt security [+],
windows internet [+],
windows ids [+],
windows fax [+],
windows explorer [+],
windows common control [+],
wince [+],
william dixon tags [+],
william dixon [+],
wavesec [+],
vpn client [+],
vboot [+],
user [+],
updates [+],
trust model [+],
trap frame [+],
trace [+],
tony sager [+],
tony harris [+],
todd sabin [+],
tim elrod [+],
three feet [+],
threaten [+],
thomas shinder [+],
tftp [+],
technical audit [+],
technical [+],
target system [+],
steve riley timothy bollefer [+],
steve riley tags [+],
stack overflow error [+],
stack [+],
space [+],
sms [+],
single computer [+],
signature verification [+],
ship [+],
sessions [+],
servers [+],
server bugs [+],
seki yoshiaki [+],
seki tags [+],
security windows [+],
security updates [+],
security tags [+],
security patches [+],
security engineering [+],
security configuration guide [+],
secure [+],
scammers [+],
safer use [+],
safeguarding [+],
rpc [+],
ring 0 [+],
resiliency [+],
researcher [+],
reliable [+],
recommendations [+],
read [+],
rdp [+],
qos [+],
professional authors [+],
problem scenarios [+],
privilege [+],
powershell [+],
popular operating systems [+],
poison [+],
picture [+],
phone [+],
pda [+],
payloads [+],
paul wouters [+],
patrick chambet [+],
patches [+],
passwords [+],
passive network [+],
ozone [+],
overflow vulnerability [+],
overflow error [+],
opentype font [+],
opentype [+],
openhack [+],
open ports [+],
ole [+],
null sessions [+],
null [+],
novell client for windows [+],
novell [+],
nist [+],
networkminer [+],
network sniffer [+],
network provider [+],
network [+],
ndistapi [+],
nathan keltner [+],
multiple [+],
msrpc [+],
mpeg [+],
monster [+],
model demonstrations [+],
milroy [+],
microsoft windows server [+],
mark burnett [+],
marinescu [+],
mail [+],
machine [+],
m office [+],
location data [+],
live [+],
lindner [+],
limited [+],
lessons [+],
learned [+],
layer 3 [+],
larcher [+],
keyboard layout [+],
keyboard [+],
k security [+],
k auditing [+],
jpeg [+],
joshua kelley tags [+],
josh daymont [+],
jonathan [+],
john lambert tags [+],
john lambert [+],
joe nocera [+],
jim harrison thomas shinder [+],
jetaudio [+],
james c. foster mark burnett [+],
james c foster [+],
ipsec [+],
intrusion detection [+],
intrusion [+],
internet security and acceleration server [+],
internet security and acceleration [+],
internet explorer [+],
internals [+],
integer overflow vulnerability [+],
improving [+],
host [+],
hips [+],
hijacking [+],
heap memory [+],
heap management [+],
hardening windows [+],
hacks [+],
hacking windows [+],
hacking [+],
glancey [+],
georg wicherski [+],
gdi library [+],
gdi [+],
garda station [+],
forensic [+],
fix [+],
fingerprinting [+],
felix [+],
fax cover page [+],
explorer [+],
exploiting [+],
exploitation [+],
eugene [+],
erik birkholz [+],
eric larcher [+],
environment [+],
driver stack [+],
dos windows [+],
dll [+],
derek milroy [+],
deployment [+],
deploying [+],
dependencies [+],
deep [+],
dcom [+],
daymont [+],
david kennedy [+],
dan kurc [+],
dan kaminsky [+],
cve [+],
corruption [+],
conventional wisdom [+],
configuration [+],
common control library [+],
common [+],
classic sandbox [+],
cisco vpn [+],
cisco guys [+],
cisco event [+],
capturing [+],
cain [+],
business assets [+],
business [+],
built [+],
bryan glancey [+],
broken [+],
bluetooth [+],
black [+],
birkholz [+],
based intrusion detection [+],
barnaby jack tags [+],
authenticode [+],
attacking [+],
asx [+],
arp [+],
applied [+],
ancillary [+],
aims [+],
adrian marinescu [+],
admits [+],
active accessibility [+],
accessibility [+],
Hardware [+],
Bugs [+],
3d scanner [+],
2008 r1 [+],
windows kernel [+],
media [+],
arbitrary code execution [+],
win [+],
vulnerability research [+],
slides [+],
buffer [+],
zeus bot,
zeros,
zero day,
zdi,
youtube,
xxxrealdrawmenuitem,
xp related,
xbox,
wscript,
wmitracemessageva,
wlm dll hijack,
wing commander,
wing,
windowsmobile,
windows xp support,
windows xp sp3,
windows xp sp2,
windows xp service pack,
windows xp home edition,
windows xp exploits,
windows xp,
windows works,
windows vulnerability,
windows systems,
windows systeme,
windows shell,
windows secrets,
windows script,
windows registry,
windows program,
windows operations,
windows nt user,
windows movie maker,
windows mobile,
windows messenger,
windows media unicast service,
windows media services,
windows media service,
windows media player network sharing service,
windows media player codec,
windows media player avi,
windows media encoder 9 series,
windows live messenger,
windows help,
windows exploits,
windows drivers,
windows desktop security,
windows com object,
windows client,
windows boot,
windows address book,
window creation,
window,
win32,
whitepaper,
web habits,
weak,
wce,
warns,
war game,
wab,
vulnerable,
vulnerabilidad,
voila,
vnc server,
vmware tools,
vmware,
vm player,
virtualization,
virtual windows,
viral threats,
video windows,
video pointers,
video case study,
video,
vibrant,
versions of microsoft windows,
version 6,
vbootkit,
validation code,
uses,
user access control,
use,
usb host,
usb cable,
usb,
unpatched,
und,
udf user,
ubuntu,
uac,
txt,
trojan,
trap,
tracing,
toolkit,
tomcat windows,
tomcat,
time windows,
thumbnail view,
thumbnail,
third,
technical detail,
technical cyber security alert,
teamspeak 2,
teamspeak,
tavis ormandy,
task scheduler service,
task,
target host,
target address,
target,
tablet,
t ipad,
sys driver,
sys,
stuxnet,
study,
stack overflow,
spoofing,
source,
sophos,
smtp,
smart tool,
small,
slk,
slaac,
simon inns,
shortcut files,
shortcut,
shmedia,
shikata ga nai,
shellexecute,
shell,
sfnlogonnotify,
sfninstring,
seven,
service windows,
service pack 3,
service,
server virtualization,
seobjectcreatesaclaccessbits,
security woes,
security vulnerability,
security vulnerabilities,
security problem,
security mechanisms,
security hole,
security features,
security experts,
security bugs,
security accounts manager,
secunia,
sebastian fernandez,
script shell,
script host,
script code,
screen,
scheduler,
schannel,
sans,
samsung,
sam,
safeguard,
rosa,
robert,
rle,
riley hassell,
retired,
resistive touch screen,
research,
release candidates,
registry keys,
registry,
reg hack,
recovery,
recent windows,
rand,
race,
r00t,
quot,
pwn,
puerto 445,
pub,
protocol,
protection tool,
progresive,
program group,
program,
probleme avec windows,
prl,
privileges,
print,
predictability,
power plant,
postgresql,
pool overflow,
pointers,
pointer,
poetry authors,
pif files,
pic chips,
phone call,
penetration,
pcs,
patrick becker,
path name,
patch,
party developers,
party,
own,
outlook express microsoft,
outlook express,
outlook,
otf format,
os installations,
original,
orchestration,
operations system,
operations manager,
operations,
openoffice,
open source drivers,
onto,
ogg file,
ogg,
offline,
office,
object,
null pointer,
ntusercheckaccessforintegritylevel,
ntlm,
ntcreatethread,
not,
nonce,
nmb,
new hardware,
new article,
network traffic,
network security course,
negotiate,
nat,
nasty attack,
mysql,
mx record,
multitouch,
msn,
msgbox c,
msgbox,
ms10,
ms windows,
movie,
moore tags,
mode program,
mode,
mobile versions,
mobile version,
mobile,
missed,
misc,
mircosoft,
midi mapping,
midi,
microsoft windows xp home edition,
microsoft windows windows,
microsoft windows versions,
microsoft windows movie maker,
microsoft windows media player 11,
microsoft windows help and support,
microsoft windows defender,
microsoft windows client,
microsoft windows 2000,
microsoft team,
microsoft producer,
microsoft powerpoint,
microsoft outlook express,
microsoft office,
microsoft issues,
microsft power point,
michael weiss,
michael muckin,
meterpreter,
metasploit framework,
metasploit,
messenger version,
messenger,
messagebox,
memory allocation,
media player version,
media player avi,
max msp,
max,
math,
mateusz jurczyk,
mateusz,
materiel,
master browser,
mancunian,
manager. this,
manager. during,
manager,
malformed url,
maker,
mail messages,
magic number,
mac trojan,
mac,
lpksetup,
lotus domino server,
lotus,
logon sessions,
logiciel,
log,
local area network,
lnk,
linux partition,
linux,
lexsi,
leaked,
launches,
latitude,
latches,
laptops,
lan,
lab,
ktm,
krakow,
komppa,
khobe,
kernel threads,
kernel stack,
kerberos,
joojoo,
johnny chung lee,
jean michel picod,
jason kendall,
jari komppa,
jai,
iphone 4,
ipad,
invalid,
internet communication,
integer overflow,
installer windows,
install,
insomnia,
insight,
infosec world,
indo,
iis,
icmpv,
icmpsendecho,
howtos,
host os,
host ip,
hobbiest,
hibernation,
hero,
help centre,
help,
header,
hashes,
handling,
handles,
handler,
hackers,
hacker,
hack in the box,
guitar hero,
guitar,
grestretchbltinternal,
gotchas,
google,
gain,
full disclosure,
full,
ftpsvc,
free tool,
free memory,
free audit,
free anti virus software,
free anti virus,
free,
fragmentation,
found,
font format,
flaw,
firefox,
file permissions,
file,
fil,
fax services,
failover,
f pic,
extension header,
explorer 6 0,
exploited,
exhaustion,
execution,
event,
even internet,
escalation,
entire system,
enterprise,
editor,
ecran,
earthquake,
e mail,
dwarfs,
dubai,
dpapi,
domino web server,
domino version,
domino server,
domino current,
domino base,
domino,
domain admin,
domain,
docume 1,
dns servers,
dns query,
dllhijackauditor,
dll windows,
dll loading,
ditching,
distro,
display driver,
desktop security software,
desktop connections,
desktop,
dereference,
depth,
dep wpm,
dep,
denial,
demonstration code,
dell models,
dell d series,
defender,
default network configuration,
decompression,
debutant,
data validation,
data execution prevention,
darknet,
dangling pointer,
dan crowley,
damit lassen sich,
d remote,
cyber security alert,
custom os,
critical security,
credential,
createwindow,
createsizeddibsection,
crack,
cpp,
could allow remote code execution,
controller,
construction glass,
connexion,
conjunction,
confidence,
compromise,
compatibility,
communication settings,
commander,
com,
code windows,
cmd,
client response,
class,
cl,
cisco,
circumventing,
cinepak,
certificate request,
cert,
centre,
cellphones,
case,
canonical,
building,
bugtraq,
bug,
browser,
brandon baker,
boston,
boot sectors,
boot,
bmp images,
blacklisting,
bit,
betta splendens,
beep,
based,
backup utility,
backdoor,
avi preview,
avi file,
avi,
audit tool,
audio windows,
audio,
attackers,
attacker,
aspr,
apple safari for windows,
apple itunes,
apple,
api,
apache tomcat,
apache 2,
apache,
alternative os,
alternative,
alex ionescu,
alec waters,
aime,
adresse mail,
admin,
activex,
acros,
ace,
access control mechanisms,
Videos,
Tutorials,
Technologies,
Support,
Pentesting,
Newbie,
Issues,
General,
ExploitsVulnerabilities,
Espace,
Discussion,
Countermeasures,
Area,
500gb hard drive,
17 years,
mysql
-
-
19:45
»
Packet Storm Security Exploits
This proof of concept code demonstrates a Microsoft Windows XP keyboard layouts pool corruption vulnerability, post MS12-034. The vulnerability exists in the function win32k!ReadLayoutFile() that parses keyboard layout file data.
-
-
21:13
»
Packet Storm Security Advisories
Core Security Technologies Advisory - There is a bug in the ReadLayoutFile Windows Kernel function that can be leveraged into a local privilege escalation exploit, potentially usable in a client-side attack scenario or after a remote intrusion by other means.
-
21:13
»
Packet Storm Security Recent Files
Core Security Technologies Advisory - There is a bug in the ReadLayoutFile Windows Kernel function that can be leveraged into a local privilege escalation exploit, potentially usable in a client-side attack scenario or after a remote intrusion by other means.
-
21:13
»
Packet Storm Security Misc. Files
Core Security Technologies Advisory - There is a bug in the ReadLayoutFile Windows Kernel function that can be leveraged into a local privilege escalation exploit, potentially usable in a client-side attack scenario or after a remote intrusion by other means.
-
20:30
»
Packet Storm Security Recent Files
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Windows installer.
-
20:30
»
Packet Storm Security Tools
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Windows installer.
-
20:30
»
Packet Storm Security Misc. Files
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. Windows installer.
-
-
14:33
»
Packet Storm Security Exploits
This Metasploit module exploits a remote buffer overflow in the Citrix Provisioning Services 5.6 SP1 (without Hotfix CPVS56SP1E043) by sending a malformed packet to the 6905/UDP port. The module has been successfully tested on Windows Server 2003 SP2, Windows 7, and Windows XP SP3.
-
14:33
»
Packet Storm Security Recent Files
This Metasploit module exploits a remote buffer overflow in the Citrix Provisioning Services 5.6 SP1 (without Hotfix CPVS56SP1E043) by sending a malformed packet to the 6905/UDP port. The module has been successfully tested on Windows Server 2003 SP2, Windows 7, and Windows XP SP3.
-
-
14:12
»
Packet Storm Security Recent Files
This is a simple script to spawn dns spoofing, arp spoofing, a fake update page for Windows and a backdoored executable on a webserver to cause the Windows box to connect back. Requires Metasploit.
-
14:12
»
Packet Storm Security Tools
This is a simple script to spawn dns spoofing, arp spoofing, a fake update page for Windows and a backdoored executable on a webserver to cause the Windows box to connect back. Requires Metasploit.
-
14:12
»
Packet Storm Security Misc. Files
This is a simple script to spawn dns spoofing, arp spoofing, a fake update page for Windows and a backdoored executable on a webserver to cause the Windows box to connect back. Requires Metasploit.
-
-
8:14
»
Hack a Day
Even though we’ve seen dozens of Kinect hacks over the years, there are a few problems with the Kinect hardware itself. The range of the Kinect sensor starts at three feet, a fact not conducive to 3D scanner builds. Also, it’s not possible to connect more than one Kinect to a single computer – something that would lead [...]
-
-
15:50
»
Packet Storm Security Recent Files
P0f is a tool that utilizes an array of sophisticated, purely passive traffic fingerprinting mechanisms to identify the players behind any incidental TCP/IP communications (often as little as a single normal SYN) without interfering in any way. Version 3 is a complete rewrite of the original codebase, incorporating a significant number of improvements to network-level fingerprinting, and introducing the ability to reason about application-level payloads (e.g., HTTP).
-
15:50
»
Packet Storm Security Tools
P0f is a tool that utilizes an array of sophisticated, purely passive traffic fingerprinting mechanisms to identify the players behind any incidental TCP/IP communications (often as little as a single normal SYN) without interfering in any way. Version 3 is a complete rewrite of the original codebase, incorporating a significant number of improvements to network-level fingerprinting, and introducing the ability to reason about application-level payloads (e.g., HTTP).
-
15:50
»
Packet Storm Security Misc. Files
P0f is a tool that utilizes an array of sophisticated, purely passive traffic fingerprinting mechanisms to identify the players behind any incidental TCP/IP communications (often as little as a single normal SYN) without interfering in any way. Version 3 is a complete rewrite of the original codebase, incorporating a significant number of improvements to network-level fingerprinting, and introducing the ability to reason about application-level payloads (e.g., HTTP).
-
-
5:22
»
Packet Storm Security Exploits
Proof of concept malicious .docm file that exploits the Microsoft Windows Assembly Execution vulnerability as described in MS12-005.
-
-
14:22
»
Packet Storm Security Advisories
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows. The vulnerability is caused by a use-after-free error in the "mshtml.dll" module when handling a specific Time behavior, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page.
-
14:22
»
Packet Storm Security Recent Files
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows. The vulnerability is caused by a use-after-free error in the "mshtml.dll" module when handling a specific Time behavior, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page.
-
14:22
»
Packet Storm Security Misc. Files
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows. The vulnerability is caused by a use-after-free error in the "mshtml.dll" module when handling a specific Time behavior, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page.
-
14:21
»
Packet Storm Security Advisories
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows. The vulnerability is caused by a use-after-free error in the TIME (datime.dll) module when loaded via a specific behavior, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page.
-
14:21
»
Packet Storm Security Recent Files
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows. The vulnerability is caused by a use-after-free error in the TIME (datime.dll) module when loaded via a specific behavior, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page.
-
14:21
»
Packet Storm Security Misc. Files
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows. The vulnerability is caused by a use-after-free error in the TIME (datime.dll) module when loaded via a specific behavior, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page.
-
14:20
»
Packet Storm Security Advisories
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows Media Player. The vulnerability is caused by a buffer overflow error in the XDSCodec & Encypter/Decrypter Tagger Filters "ENCDEC.DLL" within Windows Media Player when processing certain fields within a DVR-MS (Digital Video Recording) file, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page or a malicious ".dvr-ms" media file.
-
14:20
»
Packet Storm Security Recent Files
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows Media Player. The vulnerability is caused by a buffer overflow error in the XDSCodec & Encypter/Decrypter Tagger Filters "ENCDEC.DLL" within Windows Media Player when processing certain fields within a DVR-MS (Digital Video Recording) file, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page or a malicious ".dvr-ms" media file.
-
14:20
»
Packet Storm Security Misc. Files
VUPEN Vulnerability Research Team discovered a vulnerability in Microsoft Windows Media Player. The vulnerability is caused by a buffer overflow error in the XDSCodec & Encypter/Decrypter Tagger Filters "ENCDEC.DLL" within Windows Media Player when processing certain fields within a DVR-MS (Digital Video Recording) file, which could be exploited by remote attackers to compromise a vulnerable system via a specially crafted web page or a malicious ".dvr-ms" media file.
-
-
10:32
»
Packet Storm Security Exploits
This Metasploit module exploits a stack based buffer overflow in CCMPlayer 1.5. Opening a m3u playlist with a long track name, a SEH exception record can be overwritten with parts of the controllable buffer. SEH execution is triggered after an invalid read of an injectable address, thus allowing arbitrary code execution. This Metasploit module works on multiple Windows platforms including: Windows XP SP3, Windows Vista, and Windows 7.
-
10:32
»
Packet Storm Security Recent Files
This Metasploit module exploits a stack based buffer overflow in CCMPlayer 1.5. Opening a m3u playlist with a long track name, a SEH exception record can be overwritten with parts of the controllable buffer. SEH execution is triggered after an invalid read of an injectable address, thus allowing arbitrary code execution. This Metasploit module works on multiple Windows platforms including: Windows XP SP3, Windows Vista, and Windows 7.
-
10:32
»
Packet Storm Security Misc. Files
This Metasploit module exploits a stack based buffer overflow in CCMPlayer 1.5. Opening a m3u playlist with a long track name, a SEH exception record can be overwritten with parts of the controllable buffer. SEH execution is triggered after an invalid read of an injectable address, thus allowing arbitrary code execution. This Metasploit module works on multiple Windows platforms including: Windows XP SP3, Windows Vista, and Windows 7.
-
-
19:09
»
Packet Storm Security Exploits
Apple Safari versions 5.0 and later on Mac OS and Windows are vulnerable to a directory traversal issue with the handling of "safari-extension://" URLs. Attackers can create malicious websites that trigger Safari to send files from the victim's system to the attacker. Arbitrary Javascript can be executed in the web context of the Safari extension.
-
19:09
»
Packet Storm Security Exploits
Apple Safari versions 5.0 and later on Mac OS and Windows are vulnerable to a directory traversal issue with the handling of "safari-extension://" URLs. Attackers can create malicious websites that trigger Safari to send files from the victim's system to the attacker. Arbitrary Javascript can be executed in the web context of the Safari extension.
-
19:09
»
Packet Storm Security Recent Files
Apple Safari versions 5.0 and later on Mac OS and Windows are vulnerable to a directory traversal issue with the handling of "safari-extension://" URLs. Attackers can create malicious websites that trigger Safari to send files from the victim's system to the attacker. Arbitrary Javascript can be executed in the web context of the Safari extension.
-
19:09
»
Packet Storm Security Misc. Files
Apple Safari versions 5.0 and later on Mac OS and Windows are vulnerable to a directory traversal issue with the handling of "safari-extension://" URLs. Attackers can create malicious websites that trigger Safari to send files from the victim's system to the attacker. Arbitrary Javascript can be executed in the web context of the Safari extension.
-
-
18:42
»
Packet Storm Security Recent Files
Whitepaper called Bypassing Windows 7 Kernel ASLR. In this paper, the author explains every step to code an exploit with a useful kernel ASLR bypass. Successful exploitation is performed on Windows 7 SP0 / SP1.
-
18:42
»
Packet Storm Security Misc. Files
Whitepaper called Bypassing Windows 7 Kernel ASLR. In this paper, the author explains every step to code an exploit with a useful kernel ASLR bypass. Successful exploitation is performed on Windows 7 SP0 / SP1.
-
-
10:54
»
SecDocs
-
-
10:39
»
SecDocs
Authors:
Matthieu Suiche Tags:
forensic Event:
Black Hat USA 2010 Abstract: This talk is introducing MoonSols Windows Memory Toolkit aims at being the ultimate memory and crash dump acquisition and conversion tool for Windows. Including live acquisition on Windows of Microsoft crash dumps, the conversion of hibernation file into crashdump, and even to get a crashdump of a running VMWare Virtual Machine without rebooting it and without any BSOD!
-
-
11:52
»
SecDocs
Authors:
Matthieu Suiche Tags:
forensic Event:
Black Hat USA 2010 Abstract: This talk is introducing MoonSols Windows Memory Toolkit aims at being the ultimate memory and crash dump acquisition and conversion tool for Windows. Including live acquisition on Windows of Microsoft crash dumps, the conversion of hibernation file into crashdump, and even to get a crashdump of a running VMWare Virtual Machine without rebooting it and without any BSOD!
-
-
13:18
»
SecDocs
Authors:
Georg Wicherski Tags:
virtual machine malware malware analysis Event:
Black Hat USA 2010 Abstract: The increasing amount of new malware each day does not only put anti-virus companies up to new limits handling these samples for detection by creating new signatures. But also for network security providers and administrators, getting information on how samples affect the networks they try to protect is an increasing problem. Dynamic analysis of malware by execution in sandboxes has been an approach that has been successfully applied in both of these problem scenarios, however classic sandbox approaches clearly suffer from severe scalability problems. Most of these rely on setting up a real target system  such as the Windows XP operating system  as a virtual machine with additional software that does logging of performed actions. While these are easy to develop and set up, they require a separate virtual machine instance for each malware sample to be analyzed and therefore do not scale up with today's requirements in terms of malware growth. Anti-Virus vendors tried to circumvent performance issues for file analysis by developing custom emulators that can be deployed on a customer end-host for detection and do not require a whole operating system inside a virtual machine. These emulators however often are software interpreters for the x86 instruction set and run therefore into execution speed limitations on their own. Additionally, they suffer from detectability because they try to emulate every single Windows API but suffer from accuracy issues. dirtbox is an attempt to implement a highly scalable x86/Windows emulator that can be both used for simple malware detection and detailed behavior analysis reports. Instead of emulating every single x86 instruction in software, malware instructions are executed directly on the host CPU in a per basic block fashion. A disassembling run on each basic block ensures that no privileged or control flow subverting instructions are executed. The notion of virtual memory that is separated from the emulators memory is employed by special LDT segments and switching segment selectors before executing guest instructions. Since no instrumentation alike instruction rewriting is being done, disassembler results per basic block can be cached and all execution happens in the same process without context-switches, a high grade of performance is achieved. The operating system is emulated at the syscall layer. While this layer is mostly undocumented and implementing it in an accurate fashion is a challenging task on its own, the fact that no register changes are leaked from Ring 0 thwarts a lot of detection techniques. For usage of the high-level APIs, corresponding libraries are directly mapped into the virtual memory as well.
-
-
10:45
»
SecDocs
Authors:
Agustin Azubel Hernan Ochoa Tags:
Windows NTLM Event:
Black Hat USA 2010 Abstract: In February 2010, we found a vulnerability in the SMB NTLM Windows Authentication mechanism that have been present in Windows systems for at least 14 years (from Windows NT 4 to Windows Server 2008). You probably haven't heard about this vulnerability, but basically the authentication mechanism used by all Windows systems to access remote resources using SMB was flawed, allowing attackers to get read/write access to remote resources and remote code execution without credentials, using different techniques such as passive replay attacks, active collection of duplicate challenges/responses, and prediction of challenges. This vulnerability is also a good example of flaws found in challenge-response authentication mechanisms. This presentation will describe the vulnerability in detail, including its scope and severity, explain different techniques to exploit the flaws found and demo fully functional exploit code.
-
10:45
»
SecDocs
Authors:
Agustin Azubel Hernan Ochoa Tags:
Windows NTLM Event:
Black Hat USA 2010 Abstract: In February 2010, we found a vulnerability in the SMB NTLM Windows Authentication mechanism that have been present in Windows systems for at least 14 years (from Windows NT 4 to Windows Server 2008). You probably haven't heard about this vulnerability, but basically the authentication mechanism used by all Windows systems to access remote resources using SMB was flawed, allowing attackers to get read/write access to remote resources and remote code execution without credentials, using different techniques such as passive replay attacks, active collection of duplicate challenges/responses, and prediction of challenges. This vulnerability is also a good example of flaws found in challenge-response authentication mechanisms. This presentation will describe the vulnerability in detail, including its scope and severity, explain different techniques to exploit the flaws found and demo fully functional exploit code.
-
-
0:23
»
SecDocs
Authors:
David Kennedy Joshua Kelley Tags:
Windows Event:
Black Hat USA 2010 Abstract: Microsoft Powershell is an extensible and powerful arsenal to any systems administrator... and hacker. Now being installed by default in Server 2008, Windows 7, and optional in other operating systems, Powershell is something that will be a prevalent default on the most popular operating systems going forward. Since Microsoft removed our method of delivering malicious payloads on a system through Windows debug, we got creative. Through this presentation, we will release two working payloads (bind and reverse) written purely in Powershell and the ability to deliver whatever payload you want onto the operating system and execute. We'll also be releasing a Metasploit auxiliary module utilizing this new attack vector the day of the talk. Also included in this talk is ways of bypassing the execution restrictions which requires no modifications to the operating system to execute powershell backdoors. Lastly, there will be discussion on the future of Powershell and how we can use it for more advanced attack vectors going forward.
-
6:36
»
SecDocs
Authors:
Nathan Keltner Tim Elrod Tags:
Windows exploiting Event:
Black Hat USA 2010 Abstract: Just how much damage *can* be done with EIP under a non-Administrative Windows environment? Much, much more than you likely think. Through new techniques and live examples, attendees will be guided through the modern day attack surface of a restrictive corporate Windows world. Based purely on the Windows privilege model, demonstrations and new code will cover techniques related to collecting and replaying passwords and password hashes, destroying the browser trust model, attacking the network and the domain, and more, all without administrative access. Moving into a world of Windows Vista, 7, and hardened XP environments, the days of easily popping shells with Admin access are becoming less common. When a Limited User is exploited via a client side vulnerability, damage is often believed to be lessened due to the inability of attacker code to access sensitive portions of the OS, such as those containing passwords and password hashes, without an additional privilege escalation exploit. Despite conventional wisdom from vendors and security press, taking your users out of the 'Local Administrators' OU doesn't mean your environment is magically protected from privilege-agnostic attackers.
-
-
7:40
»
Packet Storm Security Recent Files
This document is the second of a series of five articles relating to the art of hooking. As a test environment they will use an english Windows Seven SP1 operating system distribution.
-
7:40
»
Packet Storm Security Misc. Files
This document is the second of a series of five articles relating to the art of hooking. As a test environment they will use an english Windows Seven SP1 operating system distribution.
-
-
10:04
»
SecDocs
Authors:
Cesar Cerrudo Tags:
Windows exploiting Event:
Black Hat USA 2010 Abstract: On April 14, 2009 Microsoft released a patch (documented here) to fix the issues detailed in my previous Token Kidnapping presentation (download PDF). The patch properly fixed the issues but... This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the brand new Windows 2008 R2 and Windows 7. These new attacks allow to bypass new Windows services protections such as Per service SID, Write restricted token, etc. It will be demonstrated that almost any process with impersonation rights can elevate privileges to Local System account and completely compromise Windows OSs. While the issues are not critical in nature since impersonation rights are required, they allow to exploit services such as IIS 6, IIS 7, SQL Server, etc. in some specific scenarios. Exploits code for those services will be released. The presentation will be given in a very practical way showing how the new issues were found, with what tools, techniques, etc. allowing the participants to learn how to easily find these kind security issues in Windows operating systems.
-
10:04
»
SecDocs
Authors:
Cesar Cerrudo Tags:
Windows exploiting Event:
Black Hat USA 2010 Abstract: On April 14, 2009 Microsoft released a patch (documented here) to fix the issues detailed in my previous Token Kidnapping presentation (download PDF). The patch properly fixed the issues but... This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the brand new Windows 2008 R2 and Windows 7. These new attacks allow to bypass new Windows services protections such as Per service SID, Write restricted token, etc. It will be demonstrated that almost any process with impersonation rights can elevate privileges to Local System account and completely compromise Windows OSs. While the issues are not critical in nature since impersonation rights are required, they allow to exploit services such as IIS 6, IIS 7, SQL Server, etc. in some specific scenarios. Exploits code for those services will be released. The presentation will be given in a very practical way showing how the new issues were found, with what tools, techniques, etc. allowing the participants to learn how to easily find these kind security issues in Windows operating systems.
-
1:53
»
SecDocs
Tags:
Windows hardening secure development Event:
Black Hat USA 2010 Abstract: Microsoft has implemented lots of useful functionality in Windows that they use in their own products. Many of these features can be used to enhance the security of third party applications, but not many developers or software architects know about them. This talk will detail some of the technical underpinnings of Windows features like UAC, IE protected mode and Terminal Serivces and show how they can be used to defend your own software from attack.
-
1:53
»
SecDocs
Tags:
Windows hardening secure development Event:
Black Hat USA 2010 Abstract: Microsoft has implemented lots of useful functionality in Windows that they use in their own products. Many of these features can be used to enhance the security of third party applications, but not many developers or software architects know about them. This talk will detail some of the technical underpinnings of Windows features like UAC, IE protected mode and Terminal Serivces and show how they can be used to defend your own software from attack.
-
-
8:22
»
Packet Storm Security Exploits
This Metasploit module exploits a stack-based buffer overflow on DVD X Player 5.5 Pro and Standard. By supplying a long string of data in a plf file (playlist), the MediaPlayerCtrl.dll component will attempt to extract a filename out of the string, and then copy it on the stack without any proper bounds checking, which causes a buffer overflow, and results arbitrary code execution under the context of the user. This Metasploit module has been designed to target common Windows systems such as: Windows XP SP2/SP3, Windows Vista, and Windows 7.
-
8:22
»
Packet Storm Security Recent Files
This Metasploit module exploits a stack-based buffer overflow on DVD X Player 5.5 Pro and Standard. By supplying a long string of data in a plf file (playlist), the MediaPlayerCtrl.dll component will attempt to extract a filename out of the string, and then copy it on the stack without any proper bounds checking, which causes a buffer overflow, and results arbitrary code execution under the context of the user. This Metasploit module has been designed to target common Windows systems such as: Windows XP SP2/SP3, Windows Vista, and Windows 7.
-
8:22
»
Packet Storm Security Misc. Files
This Metasploit module exploits a stack-based buffer overflow on DVD X Player 5.5 Pro and Standard. By supplying a long string of data in a plf file (playlist), the MediaPlayerCtrl.dll component will attempt to extract a filename out of the string, and then copy it on the stack without any proper bounds checking, which causes a buffer overflow, and results arbitrary code execution under the context of the user. This Metasploit module has been designed to target common Windows systems such as: Windows XP SP2/SP3, Windows Vista, and Windows 7.
-
-
14:06
»
SecDocs
Authors:
Emmanuel Bouillon Tags:
authentication MITM Kerberos Event:
Hashdays 2010 Abstract: The shift from Windows Server 2003 / XP to Server 2008 / Windows 7 has come with some more or less subtle changes in the default behavior on key components, cornerstones of the security of this kind of infrastructures. Amongst these changes some affect the authentication mechanism in place when systems and users are part of an Active Directory domain. Such evolutions like the withdrawal of weak cryptographic algorithms, DES is no longer supported for cryptosystems, are for the sake of security. This talk will explore these new default behaviors when they deal with domain authentication protocols and their consequences on the ability for an attacker to steal both system and user credentials. In a first part, we will cursorily review the main changes in the defaults configuration of recent MS Windows systems as well as some advised hardening that might be in place on some security inclined environment. These settings tend to make usual credentials stealing and replay techniques inefficient. In a second part, we will present innovative techniques to tackle this new adversary environment and finally we will discuss stealthiness of these techniques for domain credential stealing.
-
14:05
»
SecDocs
Authors:
Emmanuel Bouillon Tags:
authentication MITM Kerberos Event:
Hashdays 2010 Abstract: The shift from Windows Server 2003 / XP to Server 2008 / Windows 7 has come with some more or less subtle changes in the default behavior on key components, cornerstones of the security of this kind of infrastructures. Amongst these changes some affect the authentication mechanism in place when systems and users are part of an Active Directory domain. Such evolutions like the withdrawal of weak cryptographic algorithms, DES is no longer supported for cryptosystems, are for the sake of security. This talk will explore these new default behaviors when they deal with domain authentication protocols and their consequences on the ability for an attacker to steal both system and user credentials. In a first part, we will cursorily review the main changes in the defaults configuration of recent MS Windows systems as well as some advised hardening that might be in place on some security inclined environment. These settings tend to make usual credentials stealing and replay techniques inefficient. In a second part, we will present innovative techniques to tackle this new adversary environment and finally we will discuss stealthiness of these techniques for domain credential stealing.
-
-
15:22
»
Packet Storm Security Advisories
Microsoft Windows 7 Ultimate SP1 32 bit and 64 bit suffers from a RPC denial of service vulnerability due to mishandling of malformed DHCPv6 packets.
-
15:22
»
Packet Storm Security Recent Files
Microsoft Windows 7 Ultimate SP1 32 bit and 64 bit suffers from a RPC denial of service vulnerability due to mishandling of malformed DHCPv6 packets.
-
15:22
»
Packet Storm Security Misc. Files
Microsoft Windows 7 Ultimate SP1 32 bit and 64 bit suffers from a RPC denial of service vulnerability due to mishandling of malformed DHCPv6 packets.
-
20:39
»
Packet Storm Security Recent Files
Whitepaper called Userland Hooking in Windows. This document is the first of a series of five articles relating to the art of hooking. As a test environment, it will use an English Windows Seven SP1 operating system distribution.
-
20:39
»
Packet Storm Security Misc. Files
Whitepaper called Userland Hooking in Windows. This document is the first of a series of five articles relating to the art of hooking. As a test environment, it will use an English Windows Seven SP1 operating system distribution.
-
-
17:04
»
SecuriTeam
.Microsoft Windows Contains a vulnerability is caused by an integer overflow error in the GDI+ library
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
18:44
»
SecuriTeam
Microsoft Windows contains a vulnerability caused by a stack overflow error in the OpenType Compact Font Format (CFF) driver "ATMFD.dll".
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
18:01
»
Packet Storm Security Recent Files
The del2info utility was written to analyze Windows Recycle Bin INFO2 and $I?????? files. It can extract file deletion time, original path, and size of deleted files and whether they have been moved from the Recycle Bin. It supports files from Windows 2000 to 7.
-
18:01
»
Packet Storm Security Misc. Files
The del2info utility was written to analyze Windows Recycle Bin INFO2 and $I?????? files. It can extract file deletion time, original path, and size of deleted files and whether they have been moved from the Recycle Bin. It supports files from Windows 2000 to 7.
-
-
23:03
»
Packet Storm Security Recent Files
The del2info utility was written to analyze Windows Recycle Bin INFO2 and $I?????? files. It can extract file deletion time, original path, and size of deleted files and whether they have been moved from the Recycle Bin. It supports files from Windows 2000 to 7.
-
23:03
»
Packet Storm Security Misc. Files
The del2info utility was written to analyze Windows Recycle Bin INFO2 and $I?????? files. It can extract file deletion time, original path, and size of deleted files and whether they have been moved from the Recycle Bin. It supports files from Windows 2000 to 7.
-
-
15:12
»
Packet Storm Security Recent Files
GrokEVT is a collection of scripts for reading Windows event log files on Unix. The scripts work together on one or more mounted Windows partitions to extract all information needed (registry entries, message templates, and log files) to convert the logs to a human-readable format.
-
15:12
»
Packet Storm Security Misc. Files
GrokEVT is a collection of scripts for reading Windows event log files on Unix. The scripts work together on one or more mounted Windows partitions to extract all information needed (registry entries, message templates, and log files) to convert the logs to a human-readable format.
-
-
2:46
»
Packet Storm Security Advisories
VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Windows. The vulnerability is caused by an integer underflow error in the Object Linking and Embedding (OLE) Automation component when processing malformed Windows Metafile (WMF) data via the "_PictLoadMetaFileRaw()" function, which could be exploited by remote attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page.
-
2:46
»
Packet Storm Security Recent Files
VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Windows. The vulnerability is caused by an integer underflow error in the Object Linking and Embedding (OLE) Automation component when processing malformed Windows Metafile (WMF) data via the "_PictLoadMetaFileRaw()" function, which could be exploited by remote attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page.
-
2:46
»
Packet Storm Security Misc. Files
VUPEN Vulnerability Research Team discovered a critical vulnerability in Microsoft Windows. The vulnerability is caused by an integer underflow error in the Object Linking and Embedding (OLE) Automation component when processing malformed Windows Metafile (WMF) data via the "_PictLoadMetaFileRaw()" function, which could be exploited by remote attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page.
-
-
20:54
»
SecuriTeam
The Windows Picture and Fax Viewer "shimgvw.dll" library is vulnerable to an Integer and Buffer Overflow vulnerability.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
6:43
»
Packet Storm Security Recent Files
This is an HTTP console to remote administer Windows hosts with a browser-based, AJAX-enabled, command-line interface. Server requires .NET 3.5. Written in C# and JavaScript.
-
6:43
»
Packet Storm Security Misc. Files
This is an HTTP console to remote administer Windows hosts with a browser-based, AJAX-enabled, command-line interface. Server requires .NET 3.5. Written in C# and JavaScript.