Free skillTubeŽ movie! "Hacking Mac OS X - A Case Study"
Sunday, 06 May 2007
This movie demonstrates in three parts how the bad guys exploit vulnerabilities in Mac OS X to gain access to the system. Even an activated firewall does not necessarily protect from such attacks, as will be demonstrated in the second part. The last part shows how an attacker can install a backdoor on a Mac OS X system, giving him GUI-based access. Restricted user rights will not stop this attack either. View this skillTube movie in its full length!
 
Upcoming skillTubeŽ movie: "Creating alphanumeric shellcode"
Friday, 04 May 2007
We are pleased to announce that a new skillTube will soon be available on our web page. The module explains in detail how one can create alphanumeric shellcodes for os' running on an x86 architecture.
 
Exploitable Vulnerability in Intervation's MailCopa
Wednesday, 02 May 2007
While developing one of our advanced security training movies, we identified an exploitable vulnerability in the latest release of InterVetions' MailCopa. Successful exploitation of this vulnerability allows an attacker to execute arbitrary code in the context of the user executing MailCopa. In a web-based attack scenario, an attacker can insert a link in the following way:

<a href="mailto:test_@_example.com?subject=aaaaaaaaaaaa ... aaaaaaaaaaaaa">

If the user can be tricked into clicking on such a malicious link, an overflow occurs, leading to code execution on the victim's system.

Countermeasures:
The vendor was informed on April 30, 2007 and published a patched version just a few hours later. Amazing response time!

Credits:
skilltube.com
 
New skillTubeŽ movie! "Exploiting Format String Vulnerabilities on Mac OS X"
Friday, 27 April 2007

Format String Vulnerabilities have publicly been discussed in the year 2000.
They allow to read from and write to almost any memory location. Code execution is just one possibility, overwriting important data another.
In this movie, we analyze a format string vulnerability step by step. The student will learn what it needs to analyze and write a working exploit code with focus on Mac OS X/Unix systems. 

 
Upcoming skillTubeŽ movie! "Exploiting Format String Vulnerabilities on Mac OS X"
Tuesday, 17 April 2007
We are pleased to announce that a new skillTube will soon be available on our web page. The module deals with format string vulnerabilities with focus on Mac OS X / Unix systems and explains in detail how the bad guys exploit them to break into computer systems.
 
<< Start < Prev 1 2 3 4 Next > End >>

Results 19 - 27 of 31