<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4885660736775804679</id><updated>2014-11-10T14:39:46.107-06:00</updated><category term="Vulnerability"/><category term="Disclosure"/><category term="Advisories"/><category term="Research"/><category term="Vulnerability Advisory"/><category term="Conferences"/><category term="SolarWinds"/><category term="Updates"/><category term="Analysis"/><category term="Infographic"/><category term="Privacy"/><category term="Veracode"/><category term="ACTi"/><category term="Article"/><category term="Axway"/><category term="Black Hat"/><category term="Cybele"/><category term="Data Protector"/><category term="Defcon"/><category term="EXEC_BAR"/><category term="Epicor"/><category term="Frameworks"/><category term="HP"/><category term="IBM"/><category term="ID Theft"/><category term="IPMI"/><category term="ISSA"/><category term="Lenovo"/><category term="Metropolis"/><category term="Novell"/><category term="SEPM"/><category term="Symantec Endpoint Protection Manager"/><category term="TRISC"/><category term="Talks"/><category term="Tracking"/><category term="Twonky"/><category term="VMware"/><category term="Video"/><category term="bypass"/><category term="malware"/><category term="shim"/><category term="uac"/><category term="user account control"/><title type='text'>DDI Labs</title><subtitle type='html'>Digital Defense Vulnerability Research and Security Analytics Blog&lt;br&gt;&lt;br&gt;</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ddilabs.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>35</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-4214679168814569610</id><published>2014-05-27T16:35:00.000-05:00</published><updated>2014-06-03T14:42:15.628-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="bypass"/><category scheme="http://www.blogger.com/atom/ns#" term="malware"/><category scheme="http://www.blogger.com/atom/ns#" term="shim"/><category scheme="http://www.blogger.com/atom/ns#" term="uac"/><category scheme="http://www.blogger.com/atom/ns#" term="user account control"/><title type='text'>Shimming Your Way Past UAC</title><summary type="text">

Using Application Compatibility Fixes To Bypass User Account Control

Chris Graham

@cgrahamseven


An often-overlooked method that can be used by an attacker to gain elevated code execution is utilization of a framework that is provided by Microsoft to help legacy applications function on newer versions of Windows. That framework is known as the application compatibility toolkit. Unfortunately</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4214679168814569610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4214679168814569610'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2014/05/shimming-your-way-past-uac.html' title='Shimming Your Way Past UAC'/><author><name>cgrahamseven</name><uri>http://www.blogger.com/profile/10518499213968364899</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/-ddyrTZbhfxM/UJ70kAskWQI/AAAAAAAAAA4/DqJSdC-Oaq0/s220/seagrams.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-9036674898160825265</id><published>2014-03-26T09:07:00.000-05:00</published><updated>2014-03-28T15:54:03.424-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Analysis"/><category scheme="http://www.blogger.com/atom/ns#" term="SEPM"/><category scheme="http://www.blogger.com/atom/ns#" term="Symantec Endpoint Protection Manager"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>Symantec Endpoint Protection Manager XXE/SQLi: From Disclosure To PoC</title><summary type="text">

Finding CVE-2013-5014 and CVE-2013-5015

Chris Graham
@cgrahamseven










Sometimes there is nothing more ironic than coming across critical vulnerabilities in the very security software designed to protect systems.  In these cases not only does the security software fail to prevent an intrusion; it actually becomes the vector that allows system compromise of an otherwise secure machine.  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/9036674898160825265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/9036674898160825265'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2014/03/symantec-endpoint-protection-manager.html' title='Symantec Endpoint Protection Manager XXE/SQLi: From Disclosure To PoC'/><author><name>cgrahamseven</name><uri>http://www.blogger.com/profile/10518499213968364899</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/-ddyrTZbhfxM/UJ70kAskWQI/AAAAAAAAAA4/DqJSdC-Oaq0/s220/seagrams.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-yZZBL9mwzUk/Uw4Eiswb06I/AAAAAAAAACw/cvEHQUjnxKk/s72-c/sepm_tomcat_dir.PNG" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-7035402041683160847</id><published>2014-02-24T09:37:00.001-06:00</published><updated>2014-02-24T15:54:13.196-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Analysis"/><category scheme="http://www.blogger.com/atom/ns#" term="Data Protector"/><category scheme="http://www.blogger.com/atom/ns#" term="EXEC_BAR"/><category scheme="http://www.blogger.com/atom/ns#" term="HP"/><category scheme="http://www.blogger.com/atom/ns#" term="Research"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>Fun With HP Data Protector EXEC_BAR Remote Command Execution</title><summary type="text">

Deep Dive Analysis Of CVE-2013-2347

Chris Graham

@cgrahamseven


One of the benefits our clients have when using our vulnerability scanner is that many of the vulnerability checks we write are non-authenticated. This means that we do not require credentials to authenticate to hosts over the network in order to check for vulnerabilities. Instead, our team of researchers frequently reverse </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/7035402041683160847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/7035402041683160847'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2014/02/fun-with-hp-data-protector-execbar.html' title='Fun With HP Data Protector EXEC_BAR Remote Command Execution'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-CiPeT7E5kLk/Uwfcef5FHNI/AAAAAAAAACU/FqH3c8k_bMo/s72-c/flow.png" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-1103897457049504948</id><published>2013-11-18T10:22:00.001-06:00</published><updated>2013-11-18T10:24:09.037-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Lenovo"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Advisory"/><title type='text'>LenovoEMC StorageCenter PX4-300R Unauthorized Remote File Retrieval</title><summary type="text">
DDIVRT-2013-55 LenovoEMC StorageCenter PX4-300R Unauthorized Remote File Retrieval

Follow us on Twitter!

Date Discovered
---------------
October 10, 2013

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: Evan Sylvester and r@b13$

Vulnerability Description
-------------------------
The web server for the LenovoEMC StorageCenter PX4-300R allows </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/1103897457049504948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/1103897457049504948'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2013/11/lenovoemc-storagecenter-px4-300r.html' title='LenovoEMC StorageCenter PX4-300R Unauthorized Remote File Retrieval'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-9019138487717843955</id><published>2013-07-02T15:02:00.001-05:00</published><updated>2013-07-09T16:24:14.536-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IPMI"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Advisory"/><title type='text'>The Backdoor on the Side of Your Server</title><summary type="text">

A note to our readers....

The following is a blog post our organization was
withholding while privately warning companies about a set of critical IPMI
vulnerabilities in their rack mount hardware and the threat they posed to their
security posture.  Some of the content was covered
in a B-Sides San Antonio talk two months ago by one of our researchers.

Today the full-scope of this threat was </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/9019138487717843955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/9019138487717843955'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2013/07/the-backdoor-on-side-of-your-server_2.html' title='The Backdoor on the Side of Your Server'/><author><name>Mike C</name><uri>https://plus.google.com/104921546830683570355</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-5xMezxAgpXA/UdMw7xJKOKI/AAAAAAAAAAY/QeUh7K5jPkM/s72-c/ipmi_zero.png" height="72" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-3464568722345982472</id><published>2013-05-09T10:00:00.000-05:00</published><updated>2013-05-09T11:51:36.170-05:00</updated><title type='text'>DDIVRT-2013-53 Actuate &#39;ActuateJavaComponent&#39; Multiple Vulnerabilities</title><summary type="text">

Follow us on Twitter!



Severity

--------

High



Date
Discovered

---------------

March 19, 2013



Discovered
By

-------------

Digital
Defense, Inc. Vulnerability Research Team

Credit:
Dennis Lavrinenko, Bobby Lockett, and r@b13$



1. Actuate &#39;ActuateJavaComponent&#39; Arbitrary File
Retrieval



Vulnerability
Description

-------------------------

Actuate 10 contains a vulnerability </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3464568722345982472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3464568722345982472'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2013/05/ddivrt-2013-53-actuate.html' title='DDIVRT-2013-53 Actuate &#39;ActuateJavaComponent&#39; Multiple Vulnerabilities'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-5480568084640011342</id><published>2013-04-15T10:00:00.000-05:00</published><updated>2013-04-15T10:00:11.598-05:00</updated><title type='text'>DDIVRT-2013-52 Dell EqualLogic PS6110X Directory Traversal</title><summary type="text">
Follow us on Twitter!

Title
-----
DDIVRT-2013-52 Dell EqualLogic PS6110X Directory Traversal

Severity
--------
High

Date Discovered
---------------
February 19, 2013

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: Evan Sylvester and r@b13$

Vulnerability Description
-------------------------
The Dell EqualLogic PS6110X is vulnerable to a directory </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/5480568084640011342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/5480568084640011342'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2013/04/ddivrt-2013-52-dell-equallogic-ps6110x.html' title='DDIVRT-2013-52 Dell EqualLogic PS6110X Directory Traversal'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-2692972430563340232</id><published>2013-03-15T00:00:00.000-05:00</published><updated>2013-03-15T07:37:09.480-05:00</updated><title type='text'>DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory Traversal</title><summary type="text">
DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory Traversal

Follow us on Twitter!

Title
-----
DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory Traversal

Severity
--------
High

Date Discovered
---------------
January 22, 2013

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: r@b13$

Vulnerability Description
-------------------------
The EverFocus </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/2692972430563340232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/2692972430563340232'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2013/03/ddivrt-2013-50-everfocus-epara264-16x1_15.html' title='DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory Traversal'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-4568728516783133171</id><published>2012-12-14T12:02:00.000-06:00</published><updated>2012-12-14T12:03:15.760-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Advisory"/><title type='text'>VMware View Connection Server Directory Traversal </title><summary type="text">
DDIVRT-2012-48 VMware View Connection Server Directory Traversal (CVE-2012-5978)

Follow us on Twitter!

Severity
--------
High

Date Discovered
---------------
September 26, 2012

Discovered By
-------------
Digital Defense, Inc. Vulnerability Research Team
Credit: r@b13$

Vulnerability Description
-------------------------
The tunnel-server component of the VMware View Connection Server fails </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4568728516783133171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4568728516783133171'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/12/vmware-view-connection-server-directory.html' title='VMware View Connection Server Directory Traversal '/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-4289327439719490851</id><published>2012-12-06T10:48:00.000-06:00</published><updated>2012-12-06T10:48:54.592-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Privacy"/><title type='text'>I Know What You Are Reading...</title><summary type="text">

Before e-readers and tablet computers, the only worry that most book readers had was whether or not the someone, usually the federal government, could keep tabs on what was being checked out at the local library.  While the possibility existed for this surveillance, the likelihood that you were going to be singled out was relatively low.  



My how things have changed.



With the advent of </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4289327439719490851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4289327439719490851'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/12/i-know-what-you-are-reading.html' title='I Know What You Are Reading...'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-6201021765020845500</id><published>2012-11-27T12:16:00.000-06:00</published><updated>2012-11-27T12:16:44.496-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ID Theft"/><category scheme="http://www.blogger.com/atom/ns#" term="Infographic"/><category scheme="http://www.blogger.com/atom/ns#" term="Veracode"/><title type='text'></title><summary type="text">
Another awesome infographic from our friends at Veracode!


Infographic by Veracode Application Security



</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/6201021765020845500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/6201021765020845500'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/11/identity-theft-infographic.html' title=''/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-6852867836108985110</id><published>2012-11-05T09:07:00.001-06:00</published><updated>2012-11-05T09:09:50.697-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Infographic"/><category scheme="http://www.blogger.com/atom/ns#" term="Privacy"/><category scheme="http://www.blogger.com/atom/ns#" term="Tracking"/><category scheme="http://www.blogger.com/atom/ns#" term="Veracode"/><title type='text'></title><summary type="text">
Ever wonder how you are being tracked on the Internet?  Here is a really nice infographic from our good friends at Veracode that breaks it all down.



Infographic by Veracode Application Security

</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/6852867836108985110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/6852867836108985110'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/11/ever-wonder-how-you-are-being-tracked.html' title=''/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-5829447294985093873</id><published>2012-10-04T17:25:00.001-05:00</published><updated>2012-10-04T17:25:21.698-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Novell"/><category scheme="http://www.blogger.com/atom/ns#" term="Research"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Advisory"/><title type='text'>Novell GroupWise Agents Arbitrary File Retrieval</title><summary type="text">

DDIVRT-2012-42 Novell GroupWise Agents Arbitrary File Retrieval (CVE-2012-0419)Follow us on Twitter! Severity--------High
Date Discovered---------------April 2, 2012

Discovered By-------------Digital Defense, Inc. VulnerabilityResearch TeamCredit: r@b13$Vulnerability Description-------------------------The HTTP interfaces for Novell GroupWise 8.0.2 Post Office Agent, Message Transfer Agent, </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/5829447294985093873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/5829447294985093873'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/10/novell-groupwise-agents-arbitrary-file_4.html' title='Novell GroupWise Agents Arbitrary File Retrieval'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-109493737497211676</id><published>2012-06-19T11:14:00.001-05:00</published><updated>2012-10-04T10:01:50.174-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="SolarWinds"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Advisory"/><title type='text'>SolarWinds Network Performance Monitor Blind SQL Injection</title><summary type="text">DDIVRT-2012-45 SolarWinds Network Performance Monitor Blind SQL InjectionFollow us on Twitter!


Severity--------HighDate Discovered---------------April 26, 2012Discovered By-------------Digital Defense, Inc. Vulnerability Research TeamCredit: r@b13$Vulnerability Description-------------------------The SolarWinds Orion Network Performance Monitor 9.1 and prior contains a blind SQL injection flaw </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/109493737497211676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/109493737497211676'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/06/solarwinds-network-performance-monitor.html' title='SolarWinds Network Performance Monitor Blind SQL Injection'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-1945343663785158094</id><published>2012-05-16T12:52:00.000-05:00</published><updated>2012-05-16T12:52:52.128-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Conferences"/><category scheme="http://www.blogger.com/atom/ns#" term="ISSA"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Our CTO, Gordon MacKay Speaks @ Alamo ISSA Quarterly Chapter Meeting</title><summary type="text">
Our thanks to the Alamo ISSA Chapter for hosting our CTO, Gordon MacKay yesterday as a speaker along with Ira Winkler and Dan Teal from CoreTrace.  Great venue and attendance!



Transparency Statement:  DDI is a Gold Sponsor for the Alamo ISSA Chapter.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/1945343663785158094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/1945343663785158094'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/05/our-cto-gordon-mackay-speaks-alamo-issa.html' title='Our CTO, Gordon MacKay Speaks @ Alamo ISSA Quarterly Chapter Meeting'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-5907656634610476106</id><published>2012-05-16T12:43:00.000-05:00</published><updated>2012-05-16T12:43:59.936-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Epicor"/><category scheme="http://www.blogger.com/atom/ns#" term="Research"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Advisory"/><title type='text'>Epicor Returns Management SOAP-Based Blind SQL Injection</title><summary type="text">
DDIVRT-2012-44 Epicor Returns Management SOAP-Based Blind SQL InjectionFollow Us on Twitter! 



Severity: HighDate Discovered: April 12, 2012Discovered By: Chris Graham

Additional Discovered By: r@b13$



Vulnerability Description:Digital Defense, Inc. (DDI) has discovered a blind SQL injection vulnerability in the Epicor Returns Management software SOAP interface.  Left unremediated, this </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/5907656634610476106'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/5907656634610476106'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/05/epicor-returns-management-soap-based.html' title='Epicor Returns Management SOAP-Based Blind SQL Injection'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-4520174809092845665</id><published>2012-04-30T14:22:00.000-05:00</published><updated>2012-05-17T09:08:24.845-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ACTi"/><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Research"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>ACTi Web Configurator cgi-bin Directory Traversal</title><summary type="text">




DDIVRT-2012-41 ACTi Web Configurator cgi-bin Directory Traversal



Follow Us on Twitter!




Severity: High



Date Discovered: March 8, 2012




Discovered By: Digital Defense, Inc. Vulnerability Research Team

Credit: shmoov and r@b13$




Vulnerability Description

The ACTi Web Configurator 3.0 for ACTi IP Surveillance Cameras contains a directory traversal vulnerability within the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4520174809092845665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4520174809092845665'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/04/acti-web-configurator-cgi-bin-directory.html' title='ACTi Web Configurator cgi-bin Directory Traversal'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-6935117688464022273</id><published>2012-04-30T14:07:00.001-05:00</published><updated>2012-04-30T14:10:53.726-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Research"/><category scheme="http://www.blogger.com/atom/ns#" term="Twonky"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>PacketVideo TwonkyServer and TwonkyMedia Directory Traversal</title><summary type="text">DDIVRT-2012-40 PacketVideo TwonkyServer and TwonkyMedia Directory Traversal
Follow Us on Twitter!
Severity--------High
Date Discovered---------------March 12, 2012
Discovered By-------------DigitalDefense, Inc. Vulnerability Research TeamCredit: r@b13$
Vulnerability Description-------------------------Multiple PacketVideo products contain a directory traversal vulnerability within the web server </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/6935117688464022273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/6935117688464022273'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/04/packetvideo-twonkyserver-and.html' title='PacketVideo TwonkyServer and TwonkyMedia Directory Traversal'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-3327075370492394206</id><published>2012-03-12T15:59:00.002-05:00</published><updated>2012-03-12T16:01:03.923-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>Disclosures in the Works!</title><summary type="text">We&#39;ve got two new disclosures in the works....stay tuned!</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3327075370492394206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3327075370492394206'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/03/disclosures-in-works.html' title='Disclosures in the Works!'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-3459644976144346193</id><published>2012-02-13T11:22:00.002-06:00</published><updated>2012-02-13T11:24:45.205-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="SolarWinds"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>SolarWinds Storage Manager Server SQL Injection Authentication Bypass - Update!</title><summary type="text">&lt;!--[if gte mso 9]&gt;     0   0   1   108   619   DDI   5   1   726   14.0          &lt;![endif]--&gt;  &lt;!--[if gte mso 9]&gt;     Normal   0               false   false   false      EN-US   JA   X-NONE                                                                                             &lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3459644976144346193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3459644976144346193'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/02/solarwinds-storage-manager-server-sql.html' title='SolarWinds Storage Manager Server SQL Injection Authentication Bypass - Update!'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-209862652330055926</id><published>2012-02-02T09:59:00.004-06:00</published><updated>2012-02-02T09:59:49.953-06:00</updated><title type='text'>Conferences We&#39;ll Be Attending...Updated!</title><summary type="text">
Just added several new conferences we&#39;ll be attending!</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/209862652330055926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/209862652330055926'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/02/conferences-well-be-attendingupdated.html' title='Conferences We&#39;ll Be Attending...Updated!'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-46440642443804573</id><published>2012-01-27T17:10:00.000-06:00</published><updated>2012-01-27T17:10:09.665-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Conferences"/><title type='text'>Conferences We&#39;ll Be Attending...Updated!</title><summary type="text">Just updated the list of infosec conferences we&#39;ll be attending this year.  Looking forward to seeing our old friends and meeting some new ones!</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/46440642443804573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/46440642443804573'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/01/conferences-well-be-attendingupdated.html' title='Conferences We&#39;ll Be Attending...Updated!'/><author><name>BadK@rma</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-3874250748465493541</id><published>2012-01-23T09:55:00.007-06:00</published><updated>2012-01-23T10:02:57.807-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Research"/><category scheme="http://www.blogger.com/atom/ns#" term="SolarWinds"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>SolarWinds Storage Manager Server SQL Injection Authentication Bypass</title><summary type="text">DDIVRT-2011-39 SolarWinds Storage Manager Server SQL Injection Authentication BypassFollow Us on Twitter!Severity--------HighDate Discovered---------------December 7, 2011Discovered By-------------Digital Defense, Inc. Vulnerability Research TeamCredit: r@b13$Vulnerability Description-------------------------The &#39;LoginServlet&#39; page on port 9000 of the SolarWinds Storage Manager Server is </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3874250748465493541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/3874250748465493541'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/01/solarwinds-storage-manager-server-sql.html' title='SolarWinds Storage Manager Server SQL Injection Authentication Bypass'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-2606524879001307184</id><published>2012-01-10T16:52:00.008-06:00</published><updated>2012-01-10T17:09:07.613-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Advisories"/><category scheme="http://www.blogger.com/atom/ns#" term="Disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="Research"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability"/><title type='text'>Vulnerability Disclosure:  HP JetDirect Device Page Directory Traversal</title><summary type="text">&lt;!--[if gte mso 9]&gt;     0   0   1   11   66   DDI   1   1   76   14.0          &lt;![endif]--&gt;  &lt;!--[if gte mso 9]&gt;     Normal   0               false   false   false      EN-US   JA   X-NONE                                                                                             &lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/2606524879001307184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/2606524879001307184'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2012/01/vulnerability-disclosure-hp-jetdirect.html' title='Vulnerability Disclosure:  HP JetDirect Device Page Directory Traversal'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-4885660736775804679.post-4769044050392915238</id><published>2011-12-07T16:11:00.007-06:00</published><updated>2011-12-07T16:20:28.246-06:00</updated><title type='text'>Vulnerability Disclosure:  KnowledgeTree login.php Blind SQL Injection</title><summary type="text">DDIVRT-2011-38 KnowledgeTree login.php Blind SQL InjectionSeverity--------HighDate Discovered---------------November 18, 2011Discovered By-------------Digital Defense, Inc. Vulnerability Research TeamCredit: sxkeebler and r@b13$Vulnerability Description-------------------------The KnowledgeTree login.php login page is vulnerable to a blind SQL injection vulnerability within the username field.  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4769044050392915238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4885660736775804679/posts/default/4769044050392915238'/><link rel='alternate' type='text/html' href='http://ddilabs.blogspot.com/2011/12/vulnerability-disclosure-knowledgetree.html' title='Vulnerability Disclosure:  KnowledgeTree login.php Blind SQL Injection'/><author><name>R@b13$</name><uri>http://www.blogger.com/profile/15954497050292755550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>