Archive for July, 2010

Promoz


http://www.zeroscience.mk/files/zsl-2010-mk.pdf (MK)
http://www.zeroscience.mk/files/zsl-2010-en.pdf (EN)

http://www.slideshare.net/zeroscience

http://docs.google.com/fileview?id=1mlQavGeh2nL3antQe2d6bHH6BkBsA6xNC-rPD-asWxo46iCvoZb-yqSakTpt&hl=en (MK)

http://docs.google.com/fileview?id=1oNbi_uwIV-nNmtGJpKjsHGibsCkgmn1xy5AT8slfW6hkNHtB7kv4N3_B-mem&hl=en (EN)

http://www.facebook.com/Zero.Science.Lab
http://twitter.com/zeroscience
http://www.linkedin.com/companies/zero-science-lab

http://www.iwmnetwork.com
http://www.it.com.mk

Recoleccion de Informacion con Google (OWASP Argentina)

A presentation by Maximiliano Soler (security researcher at Zero Science Lab) held on 30th of June in Argentina by OWASP (http://www.owasp.org/index.php/OWASP_Day_Argentina_2010)

Beware that the presentation is in Spanish language ;)

You can check out the slides online: http://www.slideshare.net/secret/HeyOiUUrh2Bv5v

Or download here: IG_with_Google-SPA.pps

Corel WordPerfect Office X5 and Corel Presentations X5 File Handling Vulnerabilities

- Corel WordPerfect Office X5 15.0.0.357 (wpd) Remote Buffer Preoccupation PoC

- Corel Presentations X5 15.0.0.357 (shw) Remote Buffer Preoccupation PoC

Corel Corporation

http://www.corel.com

Version: 15.0.0.357 (Standard Edition)

- Summary: Corel® WordPerfect® Office X5 – Standard Edition is the essential
office suite for word processing, spreadsheets, presentations and email.
Chosen over Microsoft® Office by millions of longtime users, it integrates
the latest productivity software with the best of the Web. Work faster and
collaborate more efficiently with all-new Web services, new Microsoft® Office
SharePoint® support, more PDF tools and even better compatibility with Microsoft
Office. It’s everything you expect in an office suite—for less.

- Desc: Corel WordPerfect and Corel Presentations X5 is prone to a remote buffer overflow vulnerability because
the application fails to perform adequate boundary checks on user supplied input with
.WPD (WordPerfect Document) and .SHW (Presentations Slide Show) file. Attackers may exploit this issue to execute arbitrary
code in the context of the application. Failed attacks will cause denial-of-service
conditions.

- Tested On: Microsoft Windows XP Professional SP3 (English)

- Vulnerability Discovered By: Gjoko ‘LiquidWorm’ Krstic

- liquidworm gmail com

- Zero Science Lab – http://www.zeroscience.mk

- 09.07.2010

- Vendor status:

[09.07.2010] Vulnerability discovered.
[09.07.2010] Initial contact with the vendor.
[12.07.2010] No reply from vendor.
[12.07.2010] Public advisory released.

Details:

- Corel Presentations X5 15.0.0.357 (shw) Remote Buffer Preoccupation PoC
- Corel WordPerfect Office X5 15.0.0.357 (wpd) Remote Buffer Preoccupation PoC

ZSL MK Crew…Find the Perpetrator…far right :)

Xplico 0.5.7 (add.ctp) Remote XSS Vulnerability

Summary

The goal of Xplico is extract from an internet traffic capture the applications data contained. For example, from a pcap file Xplico extracts each email (POP, IMAP, and SMTP protocols), all HTTP contents, each VoIP call (SIP), FTP, TFTP, and so on. Xplico isn’t a network protocol analyzer. Xplico is an open source Network Forensic Analysis Tool (NFAT).

Description

Xplico is vulnerable to Cross-Site Scripting vulnerability. An attacker can use the “POST” to take advantage of this vulnerability, injecting code into the web pages viewed by other users.

——————————————————————————–

Detecting vulnerabilities
- /opt/xplico/xi/app/views/pols/add.ctp:13
- /opt/xplico/xi/app/views/pols/add.ctp:14
- /opt/xplico/xi/app/views/sols/add.ctp:10

——————————————————————————–

More info: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4944.php

Vendor info: http://www.xplico.org/archives/710