• Home
  • Disclosure Policy
  • About:Me
  • Imprint
Inshell.net
Inshell.net | root@internet:~# egrep 'IT Security.*Bug Hunting.*Reverse Engineering.*Exploit Development.*Creativity' internet.php

ABBS Audio Media Player v3.1 WinALL Exploit

May 5, 2013 8:30 pm / 6 Comments / MrTuxracer
abbs-6a

A few weeks ago, one of my followers asked me if I can help him writing a functional exploit for the current version of the Audio Media Player by ABBS because he’s experiencing problems with successfully exploiting a NULL-byte issue. All exploits that are available over at the Exploit Database like this one or even this Metasploit … Read More →

Posted in: Exploits, Playground / Tagged: buffer overflow, eip, stack, WinALL

OSCP Course and Exam Review

May 1, 2013 5:30 pm / 4 Comments / MrTuxracer
cert-logo-oscp

As you may have noticed – it went quiet on my blog in the last few weeks. I was heavily working on the challenging Offensive-Security Labs to obtain my Offensive-Security Certified Professional (OSCP) certification. AND ! Yesterday! I received the mail from Offensive-Security that I have successfully completed all requirements for the OSCP certification! I’m really happy … Read More →

Posted in: Playground / Tagged: certification, exam, exploit, oscp, review

PayPal Bug Bounty: PayPaltech.com XSS

April 13, 2013 1:07 pm / Leave a Comment / MrTuxracer
ia41

Great news! Today I received the second payment for another valid Cross-Site Scripting vulnerability covered by PayPal’s bug bounty program.  This time the domain www.paypaltech.com was affected, which provides scripts and samples used for Instant Payment Notifications (IPNs). Sometimes … being on the ethical side of hacking feels good …  :-)

Posted in: Vulnerabilities / Tagged: bug bounty, XSS

Bezirk-Niederbayern.de Fixes Critical SQL-Injection Flaw After 8 Months – Are We Ready For CyberWar?

March 26, 2013 9:20 pm / Leave a Comment / MrTuxracer
ia36-1

That’s amazing bad. Where should I start? In July 2012 I’ve reported a critical SQL – Injection flaw on the official website of Lower Bavaria alongside another small XSS flaw to the owner of the website. The answer did not take that long asking for further details of the flaw and how to exploit it. … Read More →

Posted in: Vulnerabilities / Tagged: arrogance, SQLi, XSS

Photodex ProShow Producer Vulnerability #6: ScsiAccess Local Privilege Escalation

March 19, 2013 9:59 pm / Leave a Comment / MrTuxracer
ia49-1

OK…honestly… I promise (!)… this is the last advisory about the ProShow Producer application, but also the most dangerous one with a CVSS Score of 7,2 and exploitable on at least all english Microsoft Windows based operating systems! The facts ? Quoted from my published advisory: Insecure file permissions on the executable file “scsiaccess.exe”, which … Read More →

Posted in: Playground, Vulnerabilities / Tagged: 0-day, hijack, privileges escalation

TÜV-Nord Fixes Multiple XSS Flaws after Consulting the Data Security Officer of Niedersachsen

March 16, 2013 10:40 am / 1 Comment / MrTuxracer
ia37

Hello readers! Take a moment and read the following article on Wikipedia about the German TÜV which is described as: TÜVs (German pronunciation: [ˈtʏf]; short for German: Technischer Überwachungs-Verein, English: Technical Inspection Association) are German organizations that work to validate the safety of products of all kinds to protect humans and the environment against hazards. As … Read More →

Posted in: Vulnerabilities / Tagged: data protection, ignorance, XSS

HP Intelligent Management Center v5.1: Bypassing javax.faces.ViewState CSRF Protection

March 5, 2013 9:56 pm / Leave a Comment / MrTuxracer
ia32-3

Have you read my last advisory about the HP Intelligent Management Center v5.1 E0202 topoContent.jsf Non-Persistent Cross-Site Scripting Vulnerability ? You should do! Taken by itself it’s not even an interesting vulnerability. But! You’re able to use this XSS flaw to bypass the weak implementation of the JSF javax.faces.ViewState Cross-Site Request Forgery Protection (which is used throughout … Read More →

Posted in: Playground, Vulnerabilities / Tagged: bypass, csrf, XSS

Photodex ProShow Producer Vulnerability #5: Insecure Library Loading

February 23, 2013 3:54 pm / Leave a Comment / MrTuxracer
ia48-4

This is a sweet vulnerability, because all ProShow installations on all Microsoft Windows operating systems up to Windows 8 are exploitable! Let’s have a look at the details and how to exploit it to get a remote shell When launching the application, it loads several .dlls: The problem ? The application (more specific: the proshow.exe) … Read More →

Posted in: Playground, Vulnerabilities / Tagged: 0-day, dll injection, exploit, PoC

Photodex ProShow Producer Vulnerability #4: SEH-Based Buffer Overflow (.PXT)

February 18, 2013 8:06 pm / Leave a Comment / MrTuxracer
ia47-3

And here’s the next one. A SEH-based Buffer Overflow – exploitable on all 32bit windows systems out there . The application does not validate (again, but in a different module) the length of the title value while loading the contents of a ProShow transition file (.pxt) which leads to a buffer overflow condition via an overwritten … Read More →

Posted in: Playground, Vulnerabilities / Tagged: 0-day, buffer overflow, SEH

Photodex ProShow Producer Vulnerability #3: Memory Corruption / Code Execution

February 14, 2013 10:02 pm / Leave a Comment / MrTuxracer
ia46-6

Hello readers, as predicted … here’s the next vulnerability in the ProShow Producer application by Photodex. This time, it’s a dangerous memory corruption which could lead to “remote” code execution using a crafted .pxs file. An attacker only needs minimal social engineering skills like… Hey dude, I’ve got a crazy, nice-looking style set for you. Please … Read More →

Posted in: Playground, Vulnerabilities / Tagged: 0-day, code execution, memory corruption, remote

Post Navigation

1 2 3 … 7 Next »

Follow Me!

Follow Me on TwitterFollow Me on LinkedInFollow Me on Exploit-DBFollow Me on RSSFollow Me on E-mail

Links

Latest Tweets

@MrTuxracer ^^ Ja, ich wusst nicht, ob ich das nennen darf ^^
15 hours ago
Herr @gehaxelt ..."Security-Kram"...stimmt, das wird so oder so total überbewertet :-P
15 hours ago
@MrTuxracer Ich habe das Recht zu schweigen :D - Ich dachte nur, das wäre ggf. für deinen Security-Kram :)
16 hours ago
@gehaxelt WTF? Woher...? Spionierst du mich aus ? Hast du mir einen Trojaner untergejubelt? #paranoia
16 hours ago
@MrTuxracer OK, vlt weiß ich welche :)
16 hours ago

Blogroll

  • 1337core
  • carnal0wnage
  • cd1zz
  • Crilogs
  • FuzzySecurity
  • Gehaxelt
  • Internetwache
  • KrebsOnSecurity
  • Sicherheit-Online
  • TacticalCode
  • Will

Categories

  • Exploits (4)
  • Papers (2)
  • Playground (21)
  • Security News (3)
  • Site News (5)
  • Tools (1)
  • Tutorials (5)
  • Videos (1)
  • Vulnerabilities (36)

Archive

  • May 2013 (2)
  • April 2013 (1)
  • March 2013 (4)
  • February 2013 (3)
  • January 2013 (3)
  • December 2012 (1)
  • November 2012 (6)
  • October 2012 (1)
  • September 2012 (4)
  • August 2012 (2)
  • July 2012 (3)
  • June 2012 (5)
  • May 2012 (1)
  • April 2012 (4)
  • March 2012 (3)
  • February 2012 (4)
  • January 2012 (4)
  • December 2011 (7)
  • November 2011 (3)

Tag Cloud

0-day advisory buffer overflow bug bounty bypass call cloud DoS eip esp exam exploit hacking hackme IDA ignorance injection inshell lighttpd local Metasploit nmap nop NoSQL Off-Topic opcode PoC pop privileges escalation push python remote reporting ret SafeSEH shellcode SQLi sqlmap stack tool trunk vlan WinALL WPScan XSS
© Copyright 2012 - Inshell.net
Infinity Theme by DesignCoral / WordPress