|
Sunday, 06 May 2007 |
|
This movie demonstrates in three parts how the bad guys exploit vulnerabilities in Mac OS X to gain access to the system. Even an activated firewall does not necessarily protect from such attacks, as will be demonstrated in the second part. The last part shows how an attacker can install a backdoor on a Mac OS X system, giving him GUI-based access. Restricted user rights will not stop this attack either. View this skillTube movie in its full length! |
|
|
Friday, 04 May 2007 |
We are pleased to announce that a new skillTube will soon be available
on our web page. The module explains in detail how one can create alphanumeric shellcodes for os' running on an x86 architecture. |
|
|
Wednesday, 02 May 2007 |
While developing one of our advanced security training movies, we identified an exploitable vulnerability in the latest release of InterVetions' MailCopa. Successful exploitation of this vulnerability allows an attacker to execute arbitrary code in the context of the user executing MailCopa. In a web-based attack scenario, an attacker can insert a link in the following way:
<a href="mailto:test_@_example.com?subject=aaaaaaaaaaaa ... aaaaaaaaaaaaa">
If the user can be tricked into clicking on such a malicious link, an overflow occurs, leading to code execution on the victim's system.
Countermeasures:
The vendor was informed on April 30, 2007 and published a patched version just a few hours later. Amazing response time!
Credits:
skilltube.com |
|
|
Friday, 27 April 2007 |
|
Format String Vulnerabilities have publicly been discussed in the year 2000. They
allow to read from and write to almost any memory location. Code
execution is just one possibility, overwriting important data another. In
this movie, we analyze a format string vulnerability step by step. The
student will learn what it needs to analyze and write a working exploit
code with focus on Mac OS X/Unix systems.
|
|
|
Tuesday, 17 April 2007 |
|
We are pleased to announce that a new skillTube will soon be available on our web page. The module deals with format string vulnerabilities with focus on Mac OS X / Unix systems and explains in detail how the bad guys exploit them to break into computer systems. |
|
|
|
<< Start < Prev 1 2 3 4 Next > End >>
|
| Results 19 - 27 of 31 |