pr Solaris 11.4 xscreensaver Privilege Escalation By packetstormsecurity.com Published On :: Wed, 16 Oct 2019 15:03:23 GMT Solaris version 11.4 xscreensaver local privilege escalation exploit. Full Article
pr Solaris xscreensaver Privilege Escalation By packetstormsecurity.com Published On :: Wed, 23 Oct 2019 20:15:30 GMT This Metasploit module exploits a vulnerability in xscreensaver versions since 5.06 on unpatched Solaris 11 systems which allows users to gain root privileges. xscreensaver allows users to create a user-owned file at any location on the filesystem using the -log command line argument introduced in version 5.06. This module uses xscreensaver to create a log file in /usr/lib/secure/, overwrites the log file with a shared object, and executes the shared object using the LD_PRELOAD environment variable. This module has been tested successfully on xscreensaver version 5.15 on Solaris 11.1 (x86) and xscreensaver version 5.15 on Solaris 11.3 (x86). Full Article
pr SunOS 5.10 Generic_147148-26 Local Privilege Escalation By packetstormsecurity.com Published On :: Wed, 15 Jan 2020 23:33:33 GMT SunOS version 5.10 Generic_147148-26 local privilege escalation exploit. A buffer overflow in the CheckMonitor() function in the Common Desktop Environment versions 2.3.1 and earlier and 1.6 and earlier, as distributed with Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long palette name passed to dtsession in a malicious .Xdefaults file. Full Article
pr Common Desktop Environment 1.6 Local Privilege Escalation By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 22:34:40 GMT A buffer overflow in the _SanityCheck() function in the Common Desktop Environment version distributed with Oracle Solaris 10 1/13 (Update 11) and earlier allows local users to gain root privileges via a long calendar name or calendar owner passed to sdtcm_convert in a malicious calendar file. The open source version of CDE (based on the CDE 2.x codebase) is not affected, because it does not ship the vulnerable program. Versions 1.6 and below are affected. Full Article
pr Practical Attacks With DNS Rebinding By packetstormsecurity.com Published On :: Wed, 04 Apr 2018 20:57:19 GMT Full Article headline dns flaw
pr Unprecedented DNS Hijacking Attacks Linked To Iran By packetstormsecurity.com Published On :: Sat, 12 Jan 2019 16:36:04 GMT Full Article headline dns iran
pr A Deep Dive On The Recent Widespread DNS Hijacking Attacks By packetstormsecurity.com Published On :: Tue, 19 Feb 2019 15:23:06 GMT Full Article headline hacker privacy dns cyberwar phish
pr Fortinet FortiSIEM 5.0 / 5.2.1 Improper Certification Validation By packetstormsecurity.com Published On :: Tue, 01 Oct 2019 20:48:19 GMT A FortiSIEM collector connects to a Supervisor/Worker over HTTPS TLS (443/TCP) to register itself as well as relaying event data such as syslog, netflow, SNMP, etc. When the Collector (the client) connects to the Supervisor/Worker (the server), the client does not validate the server-provided certificate against its root-CA store. Since the client does no server certificate validation, this means any certificate presented to the client will be considered valid and the connection will succeed. If an attacker spoofs a Worker/Supervisor using an ARP or DNS poisoning attack (or any other MITM attack), the Collector will blindly connect to the attacker's HTTPS TLS server. It will disclose the authentication password used along with any data being relayed. Versions 5.0 and 5.2.1 have been tested and are affected. Full Article
pr CurveBall Microsoft Windows CryptoAPI Spoofing Proof Of Concept By packetstormsecurity.com Published On :: Thu, 16 Jan 2020 16:16:02 GMT This is a proof of concept exploit that demonstrates the Microsoft Windows CryptoAPI spoofing vulnerability as described in CVE-2020-0601 and disclosed by the NSA. Full Article
pr SMBv3 Compression Buffer Overflow By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 19:01:13 GMT A vulnerability exists within the Microsoft Server Message Block 3.1.1 (SMBv3) protocol that can be leveraged to execute code on a vulnerable server. This local exploit implementation leverages this flaw to elevate itself before injecting a payload into winlogon.exe. Full Article
pr Git Credential Helper Protocol Newline Injection By packetstormsecurity.com Published On :: Wed, 15 Apr 2020 18:45:49 GMT A git clone action can leak cached / stored credentials for github.com to example.com due to insecure handling of newlines in the credential helper protocol. Full Article
pr PTP-RAT Screen Share Proof Of Concept By packetstormsecurity.com Published On :: Thu, 09 Nov 2017 05:22:22 GMT PTP-RAT is a proof of concept that allows data theft via screen-share protocols. Each screen flash starts with a header. This contains a magic string, "PTP-RAT-CHUNK" followed by a sequence number. When the receiver is activated, it starts taking screenshots at twice the transmission frequency (the Nyquist rate). When it detects a valid header, it decodes the pixel colour information and waits on the next flash. As soon as a valid header is not detected, it reconstructs all the flashes and saves the result to a file. To transfer a file, you run an instance of the Rat locally on your hacktop, and set that up as a receiver. Another instance is run on the remote server and this acts as a sender. You simply click on send file, and select a file to send. The mouse pointer disappears and the screen begins to flash as the file is transmitted via the pixel colour values. At the end of the transfer, a file-save dialog appears on the receiver, and the file is saved. Full Article
pr Project Open CMS 5.0.3 Cross Site Scripting / SQL Injection By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 14:48:04 GMT Project Open CMS version 5.0.3 suffers from cross site scripting and remote SQL injection vulnerabilities. Full Article
pr School ERP Pro 1.0 SQL Injection By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:31:19 GMT School ERP Pro version 1.0 suffers from a remote SQL injection vulnerability. Full Article
pr WordPress ChopSlider 3 SQL Injection By packetstormsecurity.com Published On :: Fri, 08 May 2020 19:47:15 GMT WordPress ChopSlider plugin version 3 suffers from a remote SQL injection vulnerability. Full Article
pr SSH/SSL RSA Private Key Passphrase Dictionary Enumerator By packetstormsecurity.com Published On :: Mon, 09 Apr 2018 16:22:49 GMT This is a script to perform SSH/SSL RSA private key passphrase enumeration with a dictionary attack. Full Article
pr Gadgets Can Be Hacked To Produce Dangerous Sounds By packetstormsecurity.com Published On :: Sun, 11 Aug 2019 18:14:53 GMT Full Article headline flaw cyberwar science conference
pr Team That Made Gene-Edited Babies Sentenced To Prison, Fined By packetstormsecurity.com Published On :: Thu, 02 Jan 2020 16:04:59 GMT Full Article headline china fraud science
pr FreeBSD Project Reveals Servers Were Compromised By packetstormsecurity.com Published On :: Mon, 19 Nov 2012 16:04:03 GMT Full Article headline hacker data loss bsd backdoor
pr OpenBSD Forks, Prunes, Fixes OpenSSL By packetstormsecurity.com Published On :: Tue, 22 Apr 2014 15:09:34 GMT Full Article headline flaw bsd ssl cryptography
pr NetBSD, OpenBSD Improve Kernel Security, Randomly By packetstormsecurity.com Published On :: Mon, 23 Oct 2017 13:48:18 GMT Full Article headline bsd
pr OpenBSD Patches Auth Bypass, Privilege Escalation Vulns By packetstormsecurity.com Published On :: Thu, 05 Dec 2019 16:54:00 GMT Full Article headline flaw bsd patch
pr Royals Sue Daily Mail Over U.K. Data Protection Act Violation By packetstormsecurity.com Published On :: Thu, 03 Oct 2019 14:13:31 GMT Full Article headline government privacy britain data loss
pr Hacker Who Blackmailed Apple In 2017 Gets No Prison Time By packetstormsecurity.com Published On :: Sat, 21 Dec 2019 06:49:02 GMT Full Article headline hacker britain fraud apple
pr British Rail Station Wi-Fi Provider Exposed Traveler Data By packetstormsecurity.com Published On :: Mon, 02 Mar 2020 15:21:04 GMT Full Article headline privacy britain wireless data loss
pr UK Home Office Breached GDPR 100 Times Through Botched Management Of EU Settlement Scheme By packetstormsecurity.com Published On :: Mon, 02 Mar 2020 15:21:11 GMT Full Article headline government privacy britain data loss
pr UK Coronavirus App Must Respect Privacy Rights By packetstormsecurity.com Published On :: Mon, 23 Mar 2020 14:27:48 GMT Full Article headline privacy virus phone britain
pr UK Privacy Advocates Warn Over COVID-19 Contact Tracing App By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 14:45:42 GMT Full Article headline government privacy virus phone britain
pr German e-Gov Protocol Carries Ancient Vulns By packetstormsecurity.com Published On :: Mon, 03 Jul 2017 15:44:14 GMT Full Article headline government flaw germany
pr Facebook Broke German Privacy Laws By packetstormsecurity.com Published On :: Tue, 13 Feb 2018 16:19:47 GMT Full Article headline government privacy germany facebook social
pr Germany Proposes Router Security Guidelines By packetstormsecurity.com Published On :: Mon, 26 Nov 2018 15:31:28 GMT Full Article headline government germany
pr Office 365 Declared Illegal In German Schools Due To Privacy Risks By packetstormsecurity.com Published On :: Tue, 16 Jul 2019 13:53:53 GMT Full Article headline government privacy microsoft flaw germany
pr German Police Storm Bulletproof Data Center In Former NATO Bunker By packetstormsecurity.com Published On :: Tue, 01 Oct 2019 13:50:06 GMT Full Article headline government germany
pr Pressure Mounts For Swiss Probe Into Spying Operation By packetstormsecurity.com Published On :: Thu, 13 Feb 2020 15:20:34 GMT Full Article headline government privacy usa phone germany spyware cryptography switzerland goverment
pr Anonymous Leaks Paris Climate Summit Officials' Private Data By packetstormsecurity.com Published On :: Sat, 05 Dec 2015 02:08:03 GMT Full Article headline government data loss france anonymous
pr Facebook Hit By French Privacy Order By packetstormsecurity.com Published On :: Tue, 09 Feb 2016 15:04:08 GMT Full Article headline privacy data loss france facebook
pr Russian Hackers Target French Presidential Candidate By packetstormsecurity.com Published On :: Tue, 25 Apr 2017 14:00:53 GMT Full Article headline hacker government russia fraud cyberwar france
pr Team Macron Praised For Feeding Phishing Spies Duff Info By packetstormsecurity.com Published On :: Tue, 09 May 2017 00:45:07 GMT Full Article headline government russia fraud spyware france phish
pr French Privacy Regulator Fines Google $57M For GDPR Violation By packetstormsecurity.com Published On :: Tue, 22 Jan 2019 14:26:46 GMT Full Article headline government privacy google france
pr Twitter 5.0 Eavesdropping Proof Of Concept By packetstormsecurity.com Published On :: Thu, 22 Nov 2012 18:22:22 GMT The Twitter 5.0 application for iPhone grabs images over HTTP and due to this, allows for a man in the middle attack / image swap. Proof of concept included. Full Article
pr WordPress Windows Desktop And iPhone Photo Uploader File Upload By packetstormsecurity.com Published On :: Thu, 09 Apr 2015 03:33:33 GMT WordPress Windows Desktop and iPhone Photo Uploader plugin suffers from a remote shell upload vulnerability. Full Article
pr Hackers Wipe US Servers Of Email Provider VFEmail By packetstormsecurity.com Published On :: Tue, 12 Feb 2019 17:37:49 GMT Full Article headline hacker privacy email data loss
pr Facebook Emails Seem To Show Zuck Knew Of Privacy Issues By packetstormsecurity.com Published On :: Thu, 13 Jun 2019 16:06:51 GMT Full Article headline privacy email data loss facebook
pr Sextortion Botnet Spreads 30,000 Emails An Hour By packetstormsecurity.com Published On :: Wed, 16 Oct 2019 14:45:04 GMT Full Article headline email cybercrime botnet fraud
pr OpenSMTPD 6.6.1 Local Privilege Escalation By packetstormsecurity.com Published On :: Tue, 11 Feb 2020 15:51:04 GMT smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell meta-characters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation. Full Article
pr World's Favorite Open-Source PDF Interpreter Needs Patching Again By packetstormsecurity.com Published On :: Thu, 24 Jan 2019 15:33:14 GMT Full Article headline linux flaw
pr First-Ever Malware Strain Spotted Abusing New DoH Protocol By packetstormsecurity.com Published On :: Wed, 03 Jul 2019 15:46:06 GMT Full Article headline malware linux dns denial of service
pr Critical Linux Wi-Fi Bug Allows System Compromise By packetstormsecurity.com Published On :: Sat, 19 Oct 2019 15:36:59 GMT Full Article headline linux wireless flaw
pr RICOH SP 4510DN Printer HTML Injection By packetstormsecurity.com Published On :: Thu, 09 May 2019 14:55:55 GMT An HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. Full Article
pr RICOH SP 4520DN Printer HTML Injection By packetstormsecurity.com Published On :: Thu, 09 May 2019 18:22:22 GMT An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn or entryDisplayNameIn parameter. Full Article