So recently, after almost a year in development, I finally published my iOS security app called TrustR. Frankly I’m quite surprised that no other security teams beat me to the release of this new type of security app – since it secures the iOS platform in such an obvious and necessary way. For years [...]
Archive for the ‘Vulnerabilities’ Category
Fixing iOS Security with TrustR
Posted: 6th March 2012 by nicko in Utilities, VulnerabilitiesTags: iOS security, iPad security, iPhone security, privacy, TrustR
File Expert “path” Directory Traversal Vulnerability
Posted: 16th July 2011 by sharpe in VulnerabilitiesTags: Android
Summary Sarid Harper has discovered a vulnerability in File Expert for Android, which can be exploited by malicious users to gain knowledge of sensitive information. Input passed to the “path” parameter in “/webapps/file/listing” is not properly sanitised before being used to display files and directories. This can be exploited to list arbitrary directories and files [...]
File Expert File Deletion Vulnerability
Posted: 16th July 2011 by sharpe in VulnerabilitiesTags: Android
Summary Sarid Harper has discovered a vulnerability in File Expert for Android, which can be exploited by malicious users to delete files residing outside the FTP root. The vulnerability is caused by an error in the way FTP “DELE” requests are handled. This can be exploited to escape the FTP root and delete arbitrary files [...]
Outlook Email File Attachment Denial of Service Vulnerability
Posted: 26th November 2010 by sharpe in VulnerabilitiesTags: Outlook
Summary Sarid Harper has discovered a vulnerability in Outlook, which can be exploited by malicious, anonymous individuals to cause a DoS (Denial of Service). The vulnerability is caused as a result of the improper handling of email file attachments with no extension. This can be exploited to cause a DoS by tricking a user into [...]
Acrobat Reader *.PDF file Integer Overflow Vulnerability
Posted: 1st September 2010 by sharpe in VulnerabilitiesTags: CVE-2010-2862
Summary A vulnerability has been discovered in Acrobat Reader, which can be exploited by malicious, anonymous individuals to compromise a vulnerable system. The integer overflow in the CoolType.dll module is caused when parsing the “maxCompositePoints” field value in the TrueType font’s Maximum Profile table (maxp), and can be exploited to corrupt memory via a maliciously [...]
Command-line Argument Handling in Standard Windows Binaries
Posted: 2nd June 2010 by sharpe in VulnerabilitiesTags: Command line
Looking at some of the components present within the %systemroot%\system32 directory can be fun when attempting to identify low-hanging-fruit-vulnerabilities. I made a simple fuzzer that enumerated all executables within a given directory and attempted to execute them with user-defined arguments. A more advanced method also supported by the tool, is to specify the arguments for [...]
WinAsm *.WAP File Buffer Overflow Vulnerability
Posted: 28th May 2010 by sharpe in VulnerabilitiesTags: WinAsm
Summary Sarid Harper has discovered a vulnerability in WinAsm Studio, which can be exploited by malicious, anonymous individuals to compromise a vulnerable system. The vulnerability is caused as a result of improper bounds checking when reading *.WAP files. This can be exploited to cause a stack-based buffer overflow by tricking a user into opening a [...]
WinAsm *.RC File Buffer Overflow Vulnerability
Posted: 12th April 2010 by sharpe in VulnerabilitiesTags: WinAsm
Summary Sarid Harper has discovered a vulnerability in WinAsm Studio, which can be exploited by malicious, anonymous individuals to compromise a vulnerable system. The vulnerability is caused as a result of improper bounds checking when reading *.RC files. This can be exploited to cause a stack-based buffer overflow by tricking a user into opening a [...]
Crimson Editor Dictionary File Buffer Overflow Vulnerability
Posted: 3rd April 2010 by sharpe in VulnerabilitiesTags: Crimson Editor
Summary Sarid Harper has discovered a vulnerability in Crimson Editor, which can be exploited by malicious, anonymous individuals to compromise a vulnerable system. The vulnerability is caused as a result of improper bounds checking when reading words from dictionary files. This can be exploited to cause a stack-based buffer overflow by tricking a user into [...]
Crimson Editor Configuration File Buffer Overflow Vulnerability
Posted: 18th March 2010 by sharpe in VulnerabilitiesTags: Crimson Editor
Summary Sarid Harper has discovered a vulnerability in Crimson Editor, which can be exploited by malicious, anonymous individuals to compromise a vulnerable system. The vulnerability is caused as a result of improper bounds checking when reading configuration files. This can be exploited to cause a stack-based buffer overflow by tricking a user into using a [...]
