• Home
  • Disclosure Policy
  • About:Me
  • Imprint
Inshell.net
PoC | Inshell.net

Tag Archives: Poc

Photodex ProShow Producer Vulnerability #5: Insecure Library Loading

February 23, 2013 3:54 pm / Leave a Comment / MrTuxracer
ia48-4

This is a sweet vulnerability, because all ProShow installations on all Microsoft Windows operating systems up to Windows 8 are exploitable! Let’s have a look at the details and how to exploit it to get a remote shell When launching the application, it loads several .dlls: The problem ? The application (more specific: the proshow.exe) … Read More →

Posted in: Playground, Vulnerabilities / Tagged: 0-day, dll injection, exploit, PoC

[IA42] Zoner Photo Studio v15 Build 3 (Zps.exe) Registry Value Parsing Local Buffer Overflow

November 9, 2012 12:16 am / Leave a Comment / MrTuxracer

Inshell Security Advisory http://www.inshell.net 1. ADVISORY INFORMATION ———————– Product: Zoner Photo Studio Vendor URL: www.zoner.com Type: Stack-based Buffer Overflow [CWE-121] Date found: 2012-10-17 Date published: 2012-11-09 CVSSv2 Score: 4,4 (AV:L/AC:M/Au:N/C:P/I:P/A:P) CVE: – 2. CREDITS ———- This vulnerability was discovered and researched by Julien Ahrens from Inshell Security. 3. VERSIONS AFFECTED ——————– Zoner Photo Studio 15 … Read More →

Posted in: Vulnerabilities / Tagged: buffer overflow, PoC

[IA9] Socusoft Photo to Video Converter Free/Pro v8.05 (pdmlog.dll) Local Buffer Overflow PoC

February 27, 2012 9:51 pm / Leave a Comment / MrTuxracer
bug

My first vulnerability advisory published through Vulnerability-Lab.com - a great community of vulnerability researchers, who add a real value to the process of finding and disclosing vulnerabilities to vendors. I’ve been looking for quite a long time for a suitable partner to learn and work with, and finally…found it here. I think the transparency and seriousness … Read More →

Posted in: Vulnerabilities / Tagged: buffer overflow, local, PoC

Follow Me!

Follow Me on TwitterFollow Me on LinkedInFollow Me on Exploit-DBFollow Me on RSSFollow Me on E-mail

Links

Latest Tweets

@tekwizz123 maybe...it's a feature: They've already cracked your pwd, and would like to tell you that...indirectly...;-)
7 hours ago
Why should I give #security vulnerability details to multi-million-$ vendors FOR FREE? Most of the times, I don't even get a "thank you".
7 hours ago
@tekwizz123 wtf?
7 hours ago
@i0n1c looks like you're serving as a warehouse ;-)...
7 hours ago
RT @Quinonostante: When I get a telephone call from an 'unknown number' I answer and whisper "Yes, it's done, but there's blood everywhere" #Ha
7 days ago

Blogroll

  • 1337core
  • carnal0wnage
  • cd1zz
  • Crilogs
  • FuzzySecurity
  • Gehaxelt
  • Internetwache
  • KrebsOnSecurity
  • Sicherheit-Online
  • TacticalCode
  • Will

Categories

  • Exploits (4)
  • Papers (2)
  • Playground (21)
  • Security News (3)
  • Site News (5)
  • Tools (1)
  • Tutorials (5)
  • Videos (1)
  • Vulnerabilities (36)

Archive

  • May 2013 (2)
  • April 2013 (1)
  • March 2013 (4)
  • February 2013 (3)
  • January 2013 (3)
  • December 2012 (1)
  • November 2012 (6)
  • October 2012 (1)
  • September 2012 (4)
  • August 2012 (2)
  • July 2012 (3)
  • June 2012 (5)
  • May 2012 (1)
  • April 2012 (4)
  • March 2012 (3)
  • February 2012 (4)
  • January 2012 (4)
  • December 2011 (7)
  • November 2011 (3)

Tag Cloud

0-day advisory buffer overflow bug bounty bypass call cloud DoS eip esp exam exploit hacking hackme IDA ignorance injection inshell lighttpd local Metasploit nmap nop NoSQL Off-Topic opcode PoC pop privileges escalation push python remote reporting ret SafeSEH shellcode SQLi sqlmap stack tool trunk vlan WinALL WPScan XSS
© Copyright 2012 - Inshell.net
Infinity Theme by DesignCoral / WordPress