by Bill Sempf
24. February 2019 10:39
Cool PoC of the Mac vulnerability CVE-2018-4193, an RCE in WindowServer.
https://www.synacktiv.com/ressources/OffensiveCon_2019_macOS_how_to_gain_root_with_CVE-2018-4193_in_10s.pdf
Terrifying vulnerability in an underlying component of Docker, Kubernates, and other virtuilazation software leads to hypervisor breakdown.
https://github.com/lxc/lxc/commit/6400238d08cdf1ca20d49bafb85f4e224348bf9d
An Oracle DCMA takedown of a Docker container leads to some interesting build awareness. Good Reddit thread.
https://www.reddit.com/r/oracle/comments/arqhjc/our_builds_are_failing_because_oracle_has_dmca/
A fourteen year old flaw was discovered in the encryption facility of WinRAR. Whoops. So much for the thousand eyes on open source theory.
https://arstechnica.com/information-technology/2019/02/nasty-code-execution-bug-in-winrar-threatened-millions-of-users-for-14-years/
Microsoft turbocharges GitHub's bug bounty program.
https://www.zdnet.com/article/github-bug-bounty-microsoft-ramps-up-payouts-to-30000-plus/
And that's the news!
9e132c3e-4e3c-4afc-9098-49afa1740625|0|.0|96d5b379-7e1d-4dac-a6ba-1e50db561b04
Tags:
AppSec
by Bill Sempf
17. February 2019 12:56
A maintainer of the underlying runtime for Docker and Kubernetes) reported a vulnerability.
https://seclists.org/oss-sec/2019/q1/119
Here is a PoC codebase for the above. Well written too.
https://github.com/Frichetten/CVE-2019-5736-PoC
Hashcat can now crack any eight chatacter Windows password in two hours.
https://www.theregister.co.uk/2019/02/14/password_length/
Interested in Bug Bounties? Think they are all taken? Facebook CSRF finding nets $25,000.
https://ysamm.com/?p=185
And that's the news.
535e9e18-8ba3-462f-abcc-594bba364b59|0|.0|96d5b379-7e1d-4dac-a6ba-1e50db561b04
Tags:
by Bill Sempf
10. February 2019 16:33
Ullaakut on Reddit posted this toolset: Gorsair, a tool to remotely access the exposed Docker API of vulnerable Docker containers. Works, too.
https://github.com/Ullaakut/Gorsair
Someone already pwned TLS 1.3, for crying out loud.
https://eprint.iacr.org/2018/1173
Cool attack on CORS configuration in mobile devices
https://research.digitalinterruption.com/2019/01/31/multiple-vulnerabilities-found-in-mobile-device-management-software/
RCE in Libreoffice. Not so free NOW areya?
https://insert-script.blogspot.com/2019/02/libreoffice-cve-2018-16858-remote-code.html
And that's the news. Stay warm.
44d84b37-89f0-4898-9256-24a12a893f49|0|.0|96d5b379-7e1d-4dac-a6ba-1e50db561b04
Tags: