<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:gr="http://www.google.com/schemas/reader/atom/" xmlns:idx="urn:atom-extension:indexing" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" idx:index="no" gr:dir="ltr"><!--
Content-type: Preventing XSRF in IE.

--><generator uri="http://www.google.com/reader">Google Reader</generator><id>tag:google.com,2005:reader/user/02921839077878952869/label/s3cur1ty</id><title>"s3cur1ty" via m1k3 in Google Reader</title><gr:continuation>CPu856_UmrAC</gr:continuation><author><name>m1k3</name></author><updated>2012-05-27T14:47:31Z</updated><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/s3cur1ty-news" /><feedburner:info uri="s3cur1ty-news" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gr:crawl-timestamp-msec="1338130051215"><id gr:original-id="[sales] ASIN: 3898647722 Amazon.de - Sun, 27 May 2012 05:01:52 -0700">tag:google.com,2005:reader/item/05105138bd83a64f</id><title type="html">Sold 1 copy on Amazon.de - Sunday, May 27th at 5am</title><published>2012-05-27T12:01:52Z</published><updated>2012-05-27T12:01:52Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/WL1UzM5mGis/3898647722" type="text/html" /><summary xml:base="http://www.novelrank.com/" type="html">&lt;a href="http://www.novelrank.com/asin/3898647722"&gt;"Metasploit: Das Handbuch zum Penetration-Testing-Framework"&lt;/a&gt; by &lt;em&gt;Michael Messner&lt;/em&gt; (Perfect Paperback) has sold &lt;strong&gt;1&lt;/strong&gt; book on Amazon.de on Sunday, May 27, 2012 at 5am Pacific Time.&lt;br&gt; It has jumped to a new Amazon SalesRank of &lt;strong&gt;5,470&lt;/strong&gt; from a previous SalesRank of &lt;strong&gt;12,615&lt;/strong&gt;.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/WL1UzM5mGis" height="1" width="1"/&gt;</summary><author><name>admin@novelrank.com (Mario Lurig)</name></author><source gr:stream-id="feed/http://www.novelrank.com/asin/3898647722/rss"><id>tag:google.com,2005:reader/feed/http://www.novelrank.com/asin/3898647722/rss</id><title type="html">[sales] Metasploit: Das Handbuch zum Penetration-Testing-Framework (Perfect Paperback)</title><link rel="alternate" href="http://www.novelrank.com/" type="text/html" /></source><feedburner:origLink>http://www.novelrank.com/asin/3898647722</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1338119434243"><id gr:original-id="http://www.heise.de/security/meldung/Avira-erklaert-Ausfall-der-Verhaltenserkennung-1585181.html/from/atom10">tag:google.com,2005:reader/item/35fe781e06c2593c</id><title type="html">Avira erklärt Ausfall der Verhaltenserkennung</title><published>2012-05-27T10:55:00Z</published><updated>2012-05-27T10:56:27Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/bHpaYQ0rp4w/atom10" type="text/html" /><summary xml:base="http://www.heise.de/security/" type="html">In einer Stellungnahme erklärt Avira, weshalb die Verhaltenserkennung seiner Produkte Mitte Mai zahlreiche Rechner lahmlegte. Das Modul soll in Kürze wieder eingeschaltet werden.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/bHpaYQ0rp4w" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.heise.de/security/news/news-atom.xml"><id>tag:google.com,2005:reader/feed/http://www.heise.de/security/news/news-atom.xml</id><title type="html">heise Security</title><link rel="alternate" href="http://www.heise.de/security/" type="text/html" /></source><feedburner:origLink>http://www.heise.de/security/meldung/Avira-erklaert-Ausfall-der-Verhaltenserkennung-1585181.html/from/atom10</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1338108227070"><id gr:original-id="edb-18932">tag:google.com,2005:reader/item/b5a9512fb8f9e5bd</id><category term="remote" /><title type="html">[remote] - Symantec Web Gateway 5.0.2 Remote LFI Root Exploit</title><published>2012-05-26T07:28:20Z</published><updated>2012-05-26T07:28:20Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/yMHykgrAxtg/18932" type="text/html" /><summary xml:base="http://www.exploit-db.com/" type="html">Symantec Web Gateway 5.0.2 Remote LFI Root Exploit&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/yMHykgrAxtg" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.exploit-db.com/rss.php"><id>tag:google.com,2005:reader/feed/http://www.exploit-db.com/rss.php</id><title type="html">Exploit-DB updates</title><link rel="alternate" href="http://www.exploit-db.com" type="text/html" /></source><feedburner:origLink>http://www.exploit-db.com/exploits/18932</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1338048392740"><id gr:original-id="http://www.heise.de/security/meldung/Microsoft-Mehr-Datenschutz-fuer-die-Cloud-1585115.html/from/atom10">tag:google.com,2005:reader/item/07d30d7265695565</id><title type="html">Microsoft: Mehr Datenschutz für die Cloud</title><published>2012-05-26T15:48:00Z</published><updated>2012-05-26T15:50:15Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/iSkLPXjUJMk/atom10" type="text/html" /><summary xml:base="http://www.heise.de/security/" type="html">Seit Dezember versucht Microsoft, die Bedenken potenzieller europäischer Cloud-Kunden beim Datenschutz zu zerstreuen. Nun kündigt Microsoft einen weiteren Schritt für den Cloud-Dienst CRM Online an.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/iSkLPXjUJMk" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.heise.de/security/news/news-atom.xml"><id>tag:google.com,2005:reader/feed/http://www.heise.de/security/news/news-atom.xml</id><title type="html">heise Security</title><link rel="alternate" href="http://www.heise.de/security/" type="text/html" /></source><feedburner:origLink>http://www.heise.de/security/meldung/Microsoft-Mehr-Datenschutz-fuer-die-Cloud-1585115.html/from/atom10</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1338038208570"><id gr:original-id="http://seclists.org/fulldisclosure/2012/May/267">tag:google.com,2005:reader/item/0a30f3ca39ff6e30</id><title type="html">New tool: Hyperion - A runtime encrypter for	32-bit PE files</title><published>2012-05-26T12:49:39Z</published><updated>2012-05-26T12:49:39Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/VkLtH5m84Wg/267" type="text/html" /><summary xml:base="http://seclists.org/#fulldisclosure" type="html">&lt;p&gt;Posted by Levent Kayan on May 26&lt;/p&gt;Hi there,&lt;br&gt;
&lt;br&gt;
We just published Hyperion-1.0.zip source code at nullsecurity. The&lt;br&gt;
presentation / slides are also available.&lt;br&gt;
&lt;br&gt;
[ FILE ]&lt;br&gt;
&lt;br&gt;
Hyperion-1.0.zip&lt;br&gt;
&lt;br&gt;
[ DESCR ]&lt;br&gt;
&lt;br&gt;
Hyperion is a runtime encrypter for 32-bit portable     executables. It is&lt;br&gt;
a reference implementation and bases on the paper &amp;quot;Hyperion:&lt;br&gt;
Implementation of a PE-Crypter&amp;quot;.&lt;br&gt;
&lt;br&gt;
[ SITE ]&lt;br&gt;
&lt;br&gt;
Tool @ &lt;a rel="nofollow" href="http://www.nullsecurity.net/binary.html"&gt;http://www.nullsecurity.net/binary.html&lt;/a&gt;&lt;br&gt;
Slides @ &lt;a rel="nofollow" href="http://nullsecurity.net/papers.html"&gt;http://nullsecurity.net/papers.html&lt;/a&gt;...&lt;br&gt;&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/VkLtH5m84Wg" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://seclists.org/rss/fulldisclosure.rss"><id>tag:google.com,2005:reader/feed/http://seclists.org/rss/fulldisclosure.rss</id><title type="html">Full Disclosure</title><link rel="alternate" href="http://seclists.org/#fulldisclosure" type="text/html" /></source><feedburner:origLink>http://seclists.org/fulldisclosure/2012/May/267</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1338038180853"><id gr:original-id="[sales] ASIN: 3898647722 Amazon.de - Fri, 25 May 2012 12:05:53 -0700">tag:google.com,2005:reader/item/bdbf73c2c9f7b917</id><title type="html">Sold 1 copy on Amazon.de - Friday, May 25th at 12pm</title><published>2012-05-25T19:05:53Z</published><updated>2012-05-25T19:05:53Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/WL1UzM5mGis/3898647722" type="text/html" /><summary xml:base="http://www.novelrank.com/" type="html">&lt;a href="http://www.novelrank.com/asin/3898647722"&gt;"Metasploit: Das Handbuch zum Penetration-Testing-Framework"&lt;/a&gt; by &lt;em&gt;Michael Messner&lt;/em&gt; (Perfect Paperback) has sold &lt;strong&gt;1&lt;/strong&gt; book on Amazon.de on Friday, May 25, 2012 at 12pm Pacific Time.&lt;br&gt; It has jumped to a new Amazon SalesRank of &lt;strong&gt;15,613&lt;/strong&gt; from a previous SalesRank of &lt;strong&gt;53,718&lt;/strong&gt;.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/WL1UzM5mGis" height="1" width="1"/&gt;</summary><author><name>admin@novelrank.com (Mario Lurig)</name></author><source gr:stream-id="feed/http://www.novelrank.com/asin/3898647722/rss"><id>tag:google.com,2005:reader/feed/http://www.novelrank.com/asin/3898647722/rss</id><title type="html">[sales] Metasploit: Das Handbuch zum Penetration-Testing-Framework (Perfect Paperback)</title><link rel="alternate" href="http://www.novelrank.com/" type="text/html" /></source><feedburner:origLink>http://www.novelrank.com/asin/3898647722</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1338022344585"><id gr:original-id="http://www.heise.de/security/meldung/Polizei-warnt-per-Facebook-vor-Trojaner-1585054.html/from/atom10">tag:google.com,2005:reader/item/aae45ebe75eca576</id><title type="html">Polizei warnt per Facebook vor Trojaner</title><published>2012-05-26T08:31:00Z</published><updated>2012-05-26T09:18:44Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/QuVa2vkxxPE/atom10" type="text/html" /><summary xml:base="http://www.heise.de/security/" type="html">Per Facebook warnt die Polizei Hannover vor der neuesten Variante des Ukash/Paysafe-Trojaners. Gegen die bislang unbekannten Täter werde bereits in rund 35 Verfahren ermittelt.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/QuVa2vkxxPE" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.heise.de/security/news/news-atom.xml"><id>tag:google.com,2005:reader/feed/http://www.heise.de/security/news/news-atom.xml</id><title type="html">heise Security</title><link rel="alternate" href="http://www.heise.de/security/" type="text/html" /></source><feedburner:origLink>http://www.heise.de/security/meldung/Polizei-warnt-per-Facebook-vor-Trojaner-1585054.html/from/atom10</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337976580402"><id gr:original-id="">tag:google.com,2005:reader/item/26cc4f72ce2acd94</id><category term="Columns - Hadnagy" /><title type="html">An Insider's Look at the Social-Engineer.Org SE CtF at DEFCON</title><published>2012-05-25T12:11:00Z</published><updated>2012-05-25T12:11:00Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/uuQyPDYFfTI/" type="text/html" /><summary xml:base="http://www.ethicalhacker.net/" type="html">By Chris Hadnagy 


I want you to picture this scene:  It is a warm day in sunny Maryland, my phone rings.  I answer it. 


	
	Me – “Chris speaking…”
	Voice – “Hello Sir, this is Special Agent Smith (name changed) from the FBI, I would like to speak to you about this social engineering contest…”
	Me – “Nice Dave, not falling for it.  Good try sucker!”
	Voice – “Sir, I already mentioned my name is Special Agent Smith, not Dave.  It is important that we…
	Me – “Blah, Blah Blah.. right Dave.  You are always trying to get me....&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/uuQyPDYFfTI" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.ethicalhacker.net/index2.php?option=com_rss&amp;feed=RSS2.0&amp;no_html=1"><id>tag:google.com,2005:reader/feed/http://www.ethicalhacker.net/index2.php?option=com_rss&amp;feed=RSS2.0&amp;no_html=1</id><title type="html">The Ethical Hacker Network RSS News Feed</title><link rel="alternate" href="http://www.ethicalhacker.net" type="text/html" /></source><feedburner:origLink>http://www.ethicalhacker.net/content/view/423/24/</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337970346438"><id gr:original-id="http://futurezone.at/produkte/9278-erstes-project-glass-video-aufgetaucht.php">tag:google.com,2005:reader/item/a4d3527bf75ea0b1</id><category term="Produkte" /><title type="html">Erstes Project-Glass-Video aufgetaucht</title><published>2012-05-25T13:00:00Z</published><updated>2012-05-25T13:00:00Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/uAtNhJBMofs/9278-erstes-project-glass-video-aufgetaucht.php" type="text/html" /><summary xml:base="http://www.futurezone.at/rss.xml" type="html">&lt;img src="http://futurezone.at/mmedia/medienpool/2012-04-05/9386_fe2.jpg" alt=""&gt; Ein Google-Mitarbeiter hat ein erstes Videos veröffentlicht, das mit der Augmented-Reality-Brille Project Glass aufgenommen wurde&lt;br&gt;&lt;br&gt;&lt;img src="http://top.oewabox.at/cgi-bin/ivw/CP/redcont/computerundtechnik/sonstiges/futurezone.at/rss/9278" alt="" height="1" width="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/uAtNhJBMofs" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.futurezone.at/rss.xml"><id>tag:google.com,2005:reader/feed/http://www.futurezone.at/rss.xml</id><title type="html">futurezone.at</title><link rel="alternate" href="http://www.futurezone.at/" type="text/html" /></source><feedburner:origLink>http://futurezone.at/produkte/9278-erstes-project-glass-video-aufgetaucht.php</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337970305422"><id gr:original-id="http://futurezone.at/digitallife/9279-russischer-superhacker-erhaelt-haftstrafe.php">tag:google.com,2005:reader/item/334f6e33988f97ca</id><category term="Digital Life" /><title type="html">Russischer "Superhacker" erhält Haftstrafe</title><published>2012-05-25T13:20:00Z</published><updated>2012-05-25T13:20:00Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/mVjjCvQG4cw/9279-russischer-superhacker-erhaelt-haftstrafe.php" type="text/html" /><summary xml:base="http://www.futurezone.at/rss.xml" type="html">Soll mehr als 30 Millionen Rechner attackiert haben&lt;br&gt;&lt;br&gt;&lt;img src="http://top.oewabox.at/cgi-bin/ivw/CP/redcont/computerundtechnik/sonstiges/futurezone.at/rss/9279" alt="" height="1" width="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/mVjjCvQG4cw" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.futurezone.at/rss.xml"><id>tag:google.com,2005:reader/feed/http://www.futurezone.at/rss.xml</id><title type="html">futurezone.at</title><link rel="alternate" href="http://www.futurezone.at/" type="text/html" /></source><feedburner:origLink>http://futurezone.at/digitallife/9279-russischer-superhacker-erhaelt-haftstrafe.php</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337966303422"><id gr:original-id="http://www.heise.de/security/meldung/SMS-Dienstleister-soll-wegen-Android-Malware-zahlen-1584653.html/from/atom10">tag:google.com,2005:reader/item/0f723eabb78fa3ab</id><title type="html">SMS-Dienstleister soll wegen Android-Malware zahlen</title><published>2012-05-25T16:35:00Z</published><updated>2012-05-25T16:45:14Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/Cm831xdOw78/atom10" type="text/html" /><summary xml:base="http://www.heise.de/security/" type="html">Mit gefälschten Apps haben Betrüger Android-Nutzern durch Premium-SMS das Geld aus der Tasche gezogen. Jetzt muss der in Großbritannien registrierte Betreiber der Rufnummern den entstandenen Schaden erstatten und eine Strafe zahlen.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/Cm831xdOw78" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.heise.de/security/news/news-atom.xml"><id>tag:google.com,2005:reader/feed/http://www.heise.de/security/news/news-atom.xml</id><title type="html">heise Security</title><link rel="alternate" href="http://www.heise.de/security/" type="text/html" /></source><feedburner:origLink>http://www.heise.de/security/meldung/SMS-Dienstleister-soll-wegen-Android-Malware-zahlen-1584653.html/from/atom10</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337964324262"><id gr:original-id="http://www.heise.de/security/meldung/SMS-Dienstleister-zahlt-Strafe-wegen-Android-Malware-1584653.html/from/atom10">tag:google.com,2005:reader/item/d0663f0ee5532e3e</id><title type="html">SMS-Dienstleister zahlt Strafe wegen Android-Malware</title><published>2012-05-25T16:35:00Z</published><updated>2012-05-25T16:36:24Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/0zy3ypK1GS4/atom10" type="text/html" /><summary xml:base="http://www.heise.de/security/" type="html">Mit rund 30 gefälschten Apps haben Betrüger Android-Nutzern durch Premium-SMS das Geld aus der Tasche gezogen. Jetzt muss der Betreiber der genutzten Rufnummern den entstandenen Schaden erstatten und eine Strafe zahlen.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/0zy3ypK1GS4" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.heise.de/security/news/news-atom.xml"><id>tag:google.com,2005:reader/feed/http://www.heise.de/security/news/news-atom.xml</id><title type="html">heise Security</title><link rel="alternate" href="http://www.heise.de/security/" type="text/html" /></source><feedburner:origLink>http://www.heise.de/security/meldung/SMS-Dienstleister-zahlt-Strafe-wegen-Android-Malware-1584653.html/from/atom10</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337961310874"><id gr:original-id="https://www.corelan.be/?p=9244">tag:google.com,2005:reader/item/47f2c6a04e493d1e</id><category term="Cons and Seminars" /><category term="18 allocations" /><category term="allocator" /><category term="bin" /><category term="BlockStride" /><category term="BusyBitmap" /><category term="chunk" /><category term="FirstAllocationOffset" /><category term="FreeEntryOffset" /><category term="ghost-in-the-7-allocator" /><category term="heap" /><category term="lfh" /><category term="low fragmentation heap" /><category term="peb" /><category term="UserBlocks" /><category term="windows" /><category term="windows 7" /><category term="windows 8" /><category term="_heap_entry" /><category term="_lfh_block_zone_" /><title type="html">HITB2012AMS Day 2 – Ghost in the Allocator</title><published>2012-05-25T14:59:50Z</published><updated>2012-05-25T14:59:50Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/rTRj8tq5Pro/" type="text/html" /><summary xml:base="https://www.corelan.be/" type="html">Ghost in the Allocator – Abusing the Windows 7 / 8 Low Fragmentation Heap After introducing himself, Steven Seeley, Senior Penetration Tester and Security Researcher at Stratsec starts his presentation by sharing the talk agenda: Why target the heap manager Heap terms Some Windows 7 theory WIndows 7 exploitation Changes introduced in Windows 8 Heap Windows [...]&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/rTRj8tq5Pro" height="1" width="1"/&gt;</summary><author><name>Corelan Team (corelanc0d3r)</name></author><source gr:stream-id="feed/http://www.corelan.be:8800/index.php/feed/"><id>tag:google.com,2005:reader/feed/http://www.corelan.be:8800/index.php/feed/</id><title type="html">Corelan Team</title><link rel="alternate" href="https://www.corelan.be" type="text/html" /></source><feedburner:origLink>https://www.corelan.be/index.php/2012/05/25/hitb2012ams-day-2-ghost-in-the-allocator/</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337959970944"><id gr:original-id="http://www.heise.de/security/meldung/Jailbreak-fuer-iOS-5-1-1-veroeffentlicht-1584624.html/from/atom10">tag:google.com,2005:reader/item/bfa3e338211ff77b</id><title type="html">Jailbreak für iOS 5.1.1 veröffentlicht</title><published>2012-05-25T13:20:00Z</published><updated>2012-05-25T16:30:07Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/Ot7ggswnCwc/atom10" type="text/html" /><summary xml:base="http://www.heise.de/security/" type="html">Mit Version 2.0 des Programms Absinthe können Nutzer einen ungebundenen Jailbreak von iOS 5.1.1 durchführen – auch auf dem iPhone 4S und dem neuen iPad.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/Ot7ggswnCwc" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.heise.de/security/news/news-atom.xml"><id>tag:google.com,2005:reader/feed/http://www.heise.de/security/news/news-atom.xml</id><title type="html">heise Security</title><link rel="alternate" href="http://www.heise.de/security/" type="text/html" /></source><feedburner:origLink>http://www.heise.de/security/meldung/Jailbreak-fuer-iOS-5-1-1-veroeffentlicht-1584624.html/from/atom10</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337954023702"><id gr:original-id="https://www.corelan.be/?p=9233">tag:google.com,2005:reader/item/52292f85d51458e9</id><category term="Cons and Seminars" /><category term="adobe" /><category term="agarri" /><category term="dtd" /><category term="embed" /><category term="firefox" /><category term="java" /><category term="meterpreter" /><category term="nicolas grégoire" /><category term="oracle" /><category term="parser" /><category term="php" /><category term="processing" /><category term="rest" /><category term="xml" /><category term="xslt" /><category term="xxe" /><title type="html">HITB2012AMS Day 2 – Attacking XML Processing</title><published>2012-05-25T13:30:16Z</published><updated>2012-05-25T13:30:16Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/VFO9mFmfrhE/" type="text/html" /><summary xml:base="https://www.corelan.be/" type="html">Attacking XML Processing Dressed in a classy Corelan Team T-Shirt, Nicolas Grégoire kicks off his presentation by introducing himself. Nicolas has been asked by a customer to audit some XML-DSig applications 18 months ago and found a number of bugs. This triggered him to do more research on this topic. This technology is present in [...]&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/VFO9mFmfrhE" height="1" width="1"/&gt;</summary><author><name>Corelan Team (corelanc0d3r)</name></author><source gr:stream-id="feed/http://www.corelan.be:8800/index.php/feed/"><id>tag:google.com,2005:reader/feed/http://www.corelan.be:8800/index.php/feed/</id><title type="html">Corelan Team</title><link rel="alternate" href="https://www.corelan.be" type="text/html" /></source><feedburner:origLink>https://www.corelan.be/index.php/2012/05/25/hitb2012ams-day-2-attacking-xml-processing/</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337948906415"><id gr:original-id="tag:blogger.com,1999:blog-8539880144347728238.post-7987604730973865241">tag:google.com,2005:reader/item/7c2049208ccc545e</id><category term="Pentesting" scheme="http://www.blogger.com/atom/ns#" /><title type="html">From LOW to PWNED [11] Honorable Mention: Open NFS</title><published>2012-05-25T12:00:00Z</published><updated>2012-05-25T12:00:10Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/a2Zz6Gvg0hE/from-low-to-pwned-11-honorable-mention.html" type="text/html" /><link rel="replies" href="http://carnal0wnage.attackresearch.com/feeds/7987604730973865241/comments/default" title="Post Comments" type="application/atom+xml" /><link rel="replies" href="http://www.blogger.com/comment.g?blogID=8539880144347728238&amp;postID=7987604730973865241" title="0 Comments" type="text/html" /><content xml:base="http://carnal0wnage.attackresearch.com/" type="html">Post [11] Honorable Mention: Open NFS&lt;br&gt;&lt;br&gt;Open NFS mounts/shares are awesome.  talk about sometimes finding &amp;quot;The Goods&amp;quot;.  More than once an organization has been backing up everyone&amp;#39;s home directories to an NFS share with bad permissions.  so checking to see whats shared and what you can access is important.&lt;br&gt;&lt;br&gt;Low? currently an "info" with Nessus 5&lt;br&gt;&lt;div style="clear:both;text-align:center"&gt;&lt;a href="http://1.bp.blogspot.com/-DweWj7HKtgA/T6lO2nkUqUI/AAAAAAAAA0A/5narKLilXbM/s1600/nfs-nessus.PNG" style="margin-left:1em;margin-right:1em"&gt;&lt;img border="0" height="211" src="http://1.bp.blogspot.com/-DweWj7HKtgA/T6lO2nkUqUI/AAAAAAAAA0A/5narKLilXbM/s400/nfs-nessus.PNG" width="400"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br&gt;Anyway, you probably want to know about finding it. You have a few options.&lt;br&gt;&lt;br&gt;standard portscanning (of course)&lt;br&gt;&lt;br&gt;1. scan for port 111/2049&lt;br&gt;2. do showmount -e / showmount -a&lt;br&gt;3. metasploit module&lt;br&gt;&lt;br&gt;example:&lt;br&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;,Courier,monospace"&gt;root@attacker]# showmount -e 192.168.0.1&lt;br&gt;Export list for 192.168.0.1:&lt;br&gt;/export/home/  (everyone)&lt;br&gt;/export/mnt/   (everyone)&lt;br&gt;/export/share/ (everyone)&lt;/span&gt;&lt;br&gt;&lt;br&gt;3. look to see what's exported and who is mounting ("everyone" FTW)&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;div&gt;To mount an NFS share use the following after first creating a directory on your local machine:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;,Courier,monospace"&gt;[root@attacker~]#mount -t nfs 192.168.0.1:/export/home /tmp/badperms&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;change directories to /tmp/badperms and you should see the contents of /export/home on 192.168.0.1&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;to abuse NFS you can check out the rest from &lt;a href="http://www.vulnerabilityassessment.co.uk/nfs.htm"&gt;http://www.vulnerabilityassessment.co.uk/nfs.htm&lt;/a&gt; it talks about tricking NFS to become users.  I&amp;#39;m going to put it here in case it goes missing later:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;"You ask now, how do you circumvent file          permissions and the use of the sticky bit, this is done with a little          prior planning and slight of hand to confuse the remote machine.&lt;br&gt;&lt;br&gt;If we have a /export/home/dave          directory that we have gone into, we will see a number of files          belonging to dave, some or all of which you may be able to read.           The one thing the system will give you is the owners UID on the remote          system after issuing an ls -al command i.e.&lt;br&gt;&lt;br&gt;-rwxr----- 517 wheel 898 daves_secret_doc&lt;br&gt;&lt;br&gt;The permissions at the moment do not let          you do anything with the file as you are not the owner (yet) and not a          member of the group wheel.&lt;br&gt;&lt;br&gt;Move away from the mount point and unmount          the share&lt;br&gt;umount /local_dir&lt;br&gt;&lt;br&gt;create a user called dave&lt;br&gt;useradd dave&lt;br&gt;passwd dave&lt;br&gt;&lt;br&gt;Edit /etc/passwd          and change the UID to 517&lt;br&gt;&lt;br&gt;Remount the share as local root&lt;br&gt;&lt;br&gt;Go into daves directory&lt;br&gt;cd dave&lt;br&gt;&lt;br&gt;issue the command&lt;br&gt;su dave&lt;br&gt;&lt;br&gt;As you are local root you can do this and          as you have an account called dave you will not need a password&lt;br&gt;&lt;br&gt;Now the quirky stuff - As the UID for your          local account dave matches the username and UID of the remote, the          remote system now thinks your his dave, hey presto you can now do          whatever you want with daves_secret_doc."&lt;/blockquote&gt;&lt;/div&gt;NfSpy is supposed to assist with the above: &lt;a href="https://github.com/bonsaiviking/NfSpy"&gt;https://github.com/bonsaiviking/NfSpy&lt;/a&gt;&lt;br&gt;&lt;br&gt;nmap scripts to do additional info gathering&lt;br&gt;&lt;br&gt;&lt;a href="http://nmap.org/nsedoc/scripts/nfs-ls.html"&gt;nfs-ls&lt;/a&gt;&lt;br&gt;&lt;a href="http://nmap.org/nsedoc/scripts/nfs-showmount.html"&gt;nfs-showmount&lt;/a&gt;&lt;br&gt;&lt;a href="http://nmap.org/nsedoc/scripts/nfs-statfs.html"&gt;nfs-statfs&lt;/a&gt;&lt;br&gt;&lt;br&gt;Valsmith and hdmoore gave their tactical exploitation talk at defcon 15 and talked about NFS (file services section of the &lt;a href="http://www.defcon.org/images/defcon-15/dc15-presentations/dc-15-moore_and_valsmith.pdf"&gt;slides&lt;/a&gt;) &lt;a href="http://video.google.com/videoplay?docid=8220256903673801959"&gt;video&lt;/a&gt;  &lt;a href="http://www.sysroot.eu/library/papers/Tactical%20Exploitation.pdf"&gt;white paper&lt;/a&gt; they also gave it at blackhat in a much longer format, unfortunately the video is broken into multiple 14 minute parts, so go Google for it (lazy)&lt;br&gt;&lt;br&gt;Fun Reading:&lt;br&gt;Swiss Cyber Storm II Case: NFS Hacking: &lt;a href="http://www.csnc.ch/misc/files/publications/2009_scsII_axel_neumann_NFS.pdf"&gt;http://www.csnc.ch/misc/files/publications/2009_scsII_axel_neumann_NFS.pdf&lt;/a&gt;&lt;div&gt;&lt;img width="1" height="1" src="https://blogger.googleusercontent.com/tracker/8539880144347728238-7987604730973865241?l=carnal0wnage.attackresearch.com" alt=""&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/a2Zz6Gvg0hE" height="1" width="1"/&gt;</content><author><name>CG</name></author><source gr:stream-id="feed/http://carnal0wnage.attackresearch.com/rss.xml"><id>tag:google.com,2005:reader/feed/http://carnal0wnage.attackresearch.com/rss.xml</id><title type="html">Carnal0wnage &amp;amp; Attack Research Blog</title><link rel="alternate" href="http://carnal0wnage.attackresearch.com/" type="text/html" /></source><feedburner:origLink>http://carnal0wnage.attackresearch.com/2012/05/from-low-to-pwned-11-honorable-mention.html</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337943061227"><id gr:original-id="https://www.corelan.be/?p=9221">tag:google.com,2005:reader/item/4d71eddc7c80cd90</id><category term="Cons and Seminars" /><category term="alex bazhanyuk" /><category term="bitblaze" /><category term="dangerousfunctions-ida" /><category term="fuzzing" /><category term="hooking" /><category term="ida pro" /><category term="kernel" /><category term="nikita tarakanov" /><category term="qemu" /><category term="reverse engineering" /><category term="taint analysis" /><category term="temu" /><category term="tracing" /><category term="vine" /><category term="vulnerability" /><category term="www-corelan-be" /><title type="html">HITB2012AMS Day 2 – Taint Analysis</title><published>2012-05-25T10:32:48Z</published><updated>2012-05-25T10:32:48Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/Q-0Haqr-u44/" type="text/html" /><summary xml:base="https://www.corelan.be/" type="html">Automatically Searching for Vulnerabilities: How to use Taint Analysis to find Security Flaws (by Alex Bazhanyuk (not present) and Nikita Tarakanov, Reverse Engineers, CISS) Nikita explains they have been working on reversing binaries and auditing source code for a long time.   Alex currently works on the BitBlaze work, and moved to the US to [...]&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/Q-0Haqr-u44" height="1" width="1"/&gt;</summary><author><name>Corelan Team (corelanc0d3r)</name></author><source gr:stream-id="feed/http://www.corelan.be:8800/index.php/feed/"><id>tag:google.com,2005:reader/feed/http://www.corelan.be:8800/index.php/feed/</id><title type="html">Corelan Team</title><link rel="alternate" href="https://www.corelan.be" type="text/html" /></source><feedburner:origLink>https://www.corelan.be/index.php/2012/05/25/hitb2012ams-day-2-taint-analysis/</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337938881272"><id gr:original-id="https://www.corelan.be/?p=9215">tag:google.com,2005:reader/item/ed281c8fd0285d71</id><category term="Cons and Seminars" /><category term="adobe" /><category term="amsterdam" /><category term="eps" /><category term="ghostscript" /><category term="hitb" /><category term="memory dump" /><category term="mifare" /><category term="multifunctional" /><category term="office" /><category term="postscript" /><category term="printer" /><category term="ps" /><category term="word" /><category term="xerox" /><title type="html">HITB2012AMS Day 2 – PostScript – Danger Ahead</title><published>2012-05-25T09:30:20Z</published><updated>2012-05-25T09:30:20Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/tRqHXX9hW0w/" type="text/html" /><summary xml:base="https://www.corelan.be/" type="html">Good morning everyone, welcome back at Hack In The Box 2012 Amsterdam ! Before looking at the first talk that I attended today, I would like to mention that you can find copies of the talks and materials on the hitb.org website.   Files are made available right after a talk or lab finishes, you [...]&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/tRqHXX9hW0w" height="1" width="1"/&gt;</summary><author><name>Corelan Team (corelanc0d3r)</name></author><source gr:stream-id="feed/http://www.corelan.be:8800/index.php/feed/"><id>tag:google.com,2005:reader/feed/http://www.corelan.be:8800/index.php/feed/</id><title type="html">Corelan Team</title><link rel="alternate" href="https://www.corelan.be" type="text/html" /></source><feedburner:origLink>https://www.corelan.be/index.php/2012/05/25/hitb2012ams-day-2-postscript-danger-ahead/</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337935794810"><id gr:original-id="http://www.heise.de/security/meldung/Vier-Jahre-Haft-fuer-Botnetz-Betreiber-1584203.html/from/atom10">tag:google.com,2005:reader/item/6a6ebb85821c86cb</id><title type="html">Vier Jahre Haft für Botnetz-Betreiber</title><published>2012-05-25T08:30:00Z</published><updated>2012-05-25T09:41:46Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/IhHgNcKLhzE/atom10" type="text/html" /><summary xml:base="http://www.heise.de/security/" type="html">Ein 27 Jahre alter Russe, der das Bredolab-Botnetz betrieben hat, wurde von einem armenischen Gericht verurteilt.&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/IhHgNcKLhzE" height="1" width="1"/&gt;</summary><author gr:unknown-author="true"><name>(author unknown)</name></author><source gr:stream-id="feed/http://www.heise.de/security/news/news-atom.xml"><id>tag:google.com,2005:reader/feed/http://www.heise.de/security/news/news-atom.xml</id><title type="html">heise Security</title><link rel="alternate" href="http://www.heise.de/security/" type="text/html" /></source><feedburner:origLink>http://www.heise.de/security/meldung/Vier-Jahre-Haft-fuer-Botnetz-Betreiber-1584203.html/from/atom10</feedburner:origLink></entry><entry gr:crawl-timestamp-msec="1337922262752"><id gr:original-id="http://www.room362.com/blog/2012/5/25/sudoers-commented-includes-used-for-evil.html">tag:google.com,2005:reader/item/c9d24ddeda5dba60</id><title type="html">SUDOERS Commented Includes used for Evil</title><published>2012-05-25T05:33:00Z</published><updated>2012-05-25T05:33:00Z</updated><link rel="alternate" href="http://feedproxy.google.com/~r/s3cur1ty-news/~3/PwvevA8B0ZU/sudoers-commented-includes-used-for-evil.html" type="text/html" /><content xml:base="http://www.room362.com/blog/" xml:lang="en-US" type="html">&lt;p&gt;I found a number of things interesting when reading the following post:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.offensive-security.com/vulndev/freepbx-exploit-phone-home/"&gt;http://www.offensive-security.com/vulndev/freepbx-exploit-phone-home/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Too bad that nmap's interactive mode was taken out, but there are a great number of other such methods, most notably VI's shell mode. &lt;/p&gt;
&lt;p&gt;But when I started looking into appending or inserting lines into /etc/sudoers for &lt;a href="http://www.nationalccdc.org/"&gt;CCDC&lt;/a&gt;, I happened upon an interesting function of that file. Near the end of the file there are two lines:&lt;/p&gt;
&lt;p&gt;# See sudoers(5) for more information on "#include" directives:&lt;br&gt;#includedir /etc/sudoers.d&lt;/p&gt;
&lt;p&gt;Both look commented out, but in actuality, exactly as-is the #includedir line is interpreted and acted upon. So any file that you put in the /etc/sudoers.d directory counts as an extension of the /etc/sudoers file. Make a small edit to the default README file with a bunch of added # commented out lines copied directly from the sudo man page, with a&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;nobody ALL = NOPASSWD: ALL&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;or www-data plus a webshell makes for easy re-exploitation&lt;/p&gt;
&lt;p&gt; Just an evil way to stay hidden on a 'nix box… &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update: &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;nmap --script &amp;lt;(echo &amp;quot;os.execute(&amp;#39;/bin/sh&amp;#39;)&amp;quot;)&lt;/p&gt;
&lt;p&gt;'nuf said…  (thanks &lt;a href="https://twitter.com/bonsaiviking"&gt;@bonsaiviking&lt;/a&gt; )&lt;/p&gt;&lt;div&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Room362com?a=6J2IP3oOn-0:BsGhf2nkCjo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Room362com?a=6J2IP3oOn-0:BsGhf2nkCjo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Room362com?i=6J2IP3oOn-0:BsGhf2nkCjo:V_sGLiPBpWU" border="0"&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Room362com?a=6J2IP3oOn-0:BsGhf2nkCjo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Room362com?i=6J2IP3oOn-0:BsGhf2nkCjo:gIN9vFwOqvQ" border="0"&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Room362com?a=6J2IP3oOn-0:BsGhf2nkCjo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Room362com?a=6J2IP3oOn-0:BsGhf2nkCjo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Room362com?i=6J2IP3oOn-0:BsGhf2nkCjo:F7zBnMyn0Lo" border="0"&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Room362com?a=6J2IP3oOn-0:BsGhf2nkCjo:I56M4DFLkF8"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Room362com?i=6J2IP3oOn-0:BsGhf2nkCjo:I56M4DFLkF8" border="0"&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Room362com/~4/6J2IP3oOn-0" height="1" width="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/s3cur1ty-news/~4/PwvevA8B0ZU" height="1" width="1"/&gt;</content><author><name>Rob Fuller</name></author><source gr:stream-id="feed/http://feeds.feedburner.com/Room362com"><id>tag:google.com,2005:reader/feed/http://feeds.feedburner.com/Room362com</id><title type="html">Room362.com RSS Feed</title><link rel="alternate" href="http://www.room362.com/blog/" type="text/html" /></source><feedburner:origLink>http://feedproxy.google.com/~r/Room362com/~3/6J2IP3oOn-0/sudoers-commented-includes-used-for-evil.html</feedburner:origLink></entry></feed>

