<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-608158407696852947</id><updated>2011-08-03T00:22:25.113-07:00</updated><title type='text'>Research on unsecurity</title><subtitle type='html'>Security research discovered by: 1c239c43f521145fa8385d64a9c32243</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://unsecurityresearch.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://unsecurityresearch.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Monarch</name><uri>http://www.blogger.com/profile/00127937541503546345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-608158407696852947.post-7073823186533492622</id><published>2010-01-24T13:18:00.000-08:00</published><updated>2010-01-24T13:18:32.082-08:00</updated><title type='text'>Moving - http://www.unsecurityresearch.com</title><content type='html'>&lt;a href="http://www.unsecurityresearch.com/"&gt;http://www.unsecurityresearch.com&lt;/a&gt; will be the new home for security research updates.&lt;br /&gt;&lt;br /&gt;Please refer there for all my future advisories and work.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/608158407696852947-7073823186533492622?l=unsecurityresearch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unsecurityresearch.blogspot.com/feeds/7073823186533492622/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://unsecurityresearch.blogspot.com/2010/01/moving-httpwwwunsecurityresearchcom.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/7073823186533492622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/7073823186533492622'/><link rel='alternate' type='text/html' href='http://unsecurityresearch.blogspot.com/2010/01/moving-httpwwwunsecurityresearchcom.html' title='Moving - http://www.unsecurityresearch.com'/><author><name>Monarch</name><uri>http://www.blogger.com/profile/00127937541503546345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-608158407696852947.post-372392663666925170</id><published>2009-12-21T13:33:00.000-08:00</published><updated>2010-01-23T19:14:27.100-08:00</updated><title type='text'>Research updated</title><content type='html'>The cumulative list of vulnerabilities I've discovered was updated today.&lt;br /&gt;For a full list refer to: &lt;a href="http://unsecurityresearch.blogspot.com/2009/02/advisories-upcoming.html"&gt;http://unsecurityresearch.blogspot.com/2009/02/advisories-upcoming.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;New items are:&lt;br /&gt;Vendor: &lt;b&gt;Oracle&lt;/b&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote&lt;br /&gt;Status: Under review&lt;br /&gt;Discovered: 1/2010 &lt;br /&gt;(Best discovery yet)&lt;br /&gt;&lt;br /&gt;Vendor: &lt;b&gt;Oracle&lt;/b&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote&lt;br /&gt;Status: Under review&lt;br /&gt;Discovered: 12-20-09&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Vendor: &lt;b&gt;Novell&lt;/b&gt;&lt;br /&gt;Severity: High &lt;br /&gt;Type: Remote&lt;br /&gt;Status: ZDI-CAN-680&lt;br /&gt;Discovered: 12-04-09&lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote vulnerability&lt;br /&gt;Status: &lt;i&gt;ZDI-CAN-622&lt;/i&gt;&lt;br /&gt;Discovered: 9-19-09&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/608158407696852947-372392663666925170?l=unsecurityresearch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unsecurityresearch.blogspot.com/feeds/372392663666925170/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/12/research-updated-1-unsold.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/372392663666925170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/372392663666925170'/><link rel='alternate' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/12/research-updated-1-unsold.html' title='Research updated'/><author><name>Monarch</name><uri>http://www.blogger.com/profile/00127937541503546345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-608158407696852947.post-3005798403717571995</id><published>2009-06-01T17:27:00.000-07:00</published><updated>2009-09-11T08:18:33.264-07:00</updated><title type='text'>Research - Discarded</title><content type='html'>This section will list potential vulnerabilities that I have discarded.If reporting them to the vendor is easy then you I'll wait for their response before posting.&lt;br /&gt;&lt;br /&gt;Firefox - bug 492779&lt;br /&gt;&lt;span style="font-size: 100%;"&gt;&lt;span id=":hc"&gt;PL_Base64D&lt;wbr&gt;&lt;/wbr&gt;ecode integer overflow&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Code changes made: &lt;a href="http://bonsai.mozilla.org/cvsview2.cgi?diff_mode=context&amp;amp;whitespace_mode=show&amp;amp;subdir=mozilla/nsprpub/lib/libc/src&amp;amp;command=DIFF_FRAMESET&amp;amp;file=base64.c&amp;amp;rev1=3.7&amp;amp;rev2=3.8&amp;amp;root=/cvsroot"&gt;here&lt;/a&gt; and &lt;a href="http://bonsai.mozilla.org/cvsview2.cgi?diff_mode=context&amp;amp;whitespace_mode=show&amp;amp;subdir=mozilla/nsprpub/lib/libc/src&amp;amp;command=DIFF_FRAMESET&amp;amp;file=base64.c&amp;amp;rev1=3.8&amp;amp;rev2=3.9&amp;amp;root=/cvsroot"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looked very promising at first. A common library routine used in many places with a straight forward integer overflow, caused because it multiplied before dividing..Exploitation also looked promising since we could control the amount to overflow the buffer with by using invalid base64 characters to make the decode no-op.&lt;br /&gt;&lt;br /&gt;Reason for discarding:&lt;br /&gt;Was unable to trigger it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/608158407696852947-3005798403717571995?l=unsecurityresearch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unsecurityresearch.blogspot.com/feeds/3005798403717571995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/06/research-discarded.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/3005798403717571995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/3005798403717571995'/><link rel='alternate' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/06/research-discarded.html' title='Research - Discarded'/><author><name>Monarch</name><uri>http://www.blogger.com/profile/00127937541503546345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-608158407696852947.post-7366722821202433511</id><published>2009-02-28T10:36:00.000-08:00</published><updated>2010-01-23T19:19:08.345-08:00</updated><title type='text'>Advisories - Published</title><content type='html'>Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: &lt;b&gt;High&lt;/b&gt;&lt;br /&gt;Type: Remote vulnerability&lt;br /&gt;Published: &lt;a href="http://www.zerodayinitiative.com/advisories/ZDI-10-001/"&gt;ZDI-10-001&lt;/a&gt;&lt;br /&gt;Discovered: 02-09&lt;br /&gt;Comments: Interesting that Novell patches the vulnerability and releases patch but advisory is not published until several months later. I wonder if many vendors do this. &lt;br /&gt;&lt;br /&gt;Vendor: &lt;b&gt;Sun&lt;/b&gt;&lt;br /&gt;Product: &lt;b&gt;Solaris - w(1)&lt;/b&gt;&lt;br /&gt;Severity: Medium&lt;br /&gt;Published: &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-266348-1"&gt;Sun Alert&lt;/a&gt;&lt;br /&gt;Sun Bug: 6821298&lt;br /&gt;Notes: I respect Sun alot, so no further details provided. &lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;IBM&lt;/span&gt;&lt;br /&gt;Product:&lt;span style="font-weight: bold;"&gt; AIX&lt;/span&gt;&lt;br /&gt;Severity: Medium&lt;br /&gt;Type: Local privilege escalation&lt;br /&gt;Notes: Three privilege escalations found, Two published &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;muxatmd buffer overflow&lt;/span&gt;&lt;br /&gt;&lt;a href="https://labs.idefense.com/intelligence/vulnerabilities/display.php?id=784"&gt; 4-15-09 iDefense&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/34543"&gt; Bugtraq ID:              34543&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;libc arbitrary file overwrite&lt;/span&gt;&lt;br /&gt;&lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=802"&gt;5-20-09 iDefense&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/35034"&gt;Bugtraq ID: 35034&lt;/a&gt;&lt;br /&gt;This is also the first bug I have ever sold, was a rather eye-opening experience.&lt;br /&gt;I really would have expected more from developers working on libc.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;My research is published giving credit to: 1c239c43f521145fa8385d64a9c32243&lt;br /&gt;(Except my very first few)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/608158407696852947-7366722821202433511?l=unsecurityresearch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unsecurityresearch.blogspot.com/feeds/7366722821202433511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/02/advisories-published.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/7366722821202433511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/7366722821202433511'/><link rel='alternate' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/02/advisories-published.html' title='Advisories - Published'/><author><name>Monarch</name><uri>http://www.blogger.com/profile/00127937541503546345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-608158407696852947.post-6700022655615246584</id><published>2009-02-28T10:30:00.000-08:00</published><updated>2010-01-24T13:20:01.785-08:00</updated><title type='text'>Advisories - Upcoming</title><content type='html'>Update: &lt;a href="http://www.unsecurityresearch.com/"&gt;http://www.unsecurityresearch.com&lt;/a&gt;&lt;br /&gt;Will be the new home for all my security research updates. Please refer there for all my future work and advisories.&amp;nbsp; The list below is being left but will not be updated.&amp;nbsp; 1-24-2010 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vendor: &lt;b&gt;Oracle &lt;/b&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote&lt;br /&gt;Status: Under review&lt;br /&gt;Discovered: 1/2010&lt;br /&gt;&lt;br /&gt;Vendor: &lt;b&gt;Novell&lt;/b&gt;&lt;br /&gt;Severity: Low&lt;br /&gt;Type: Remote&lt;br /&gt;Status: Under review&lt;br /&gt;Discovered: Several months ago, did not submit to ZDI until now since it may have overlapped with previous discovery&lt;br /&gt;&lt;br /&gt;Vendor: &lt;b&gt;Oracle&lt;/b&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote&lt;br /&gt;Status: Under review&lt;br /&gt;Discovered: 12-20-09&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Vendor: &lt;b&gt;Novell&lt;/b&gt;&lt;br /&gt;Severity: High &lt;br /&gt;Type: Remote&lt;br /&gt;Status: ZDI-CAN-680 &lt;br /&gt;Discovered: 12-04-09&lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote vulnerability&lt;br /&gt;Status: &lt;i&gt;ZDI-CAN-622&lt;/i&gt;&lt;br /&gt;Discovered: 9-19-09&lt;br /&gt;&amp;nbsp; &lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote vulnerability&lt;br /&gt;Status: &lt;i&gt;ZDI-CAN-622&lt;/i&gt;&lt;br /&gt;Discovered: 9-16-09&lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: High&lt;br /&gt;Type: Remote vulnerability&lt;br /&gt;Status: Sold ZDI-CAN-607&lt;br /&gt;Discovered: 8-12-09&lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: Medium&lt;br /&gt;Type: Remote vulnerability (Post-Auth)&lt;br /&gt;Status: Sold ZDI-CAN-572 &lt;br /&gt;Discovered: Can't remember..&lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: Low&lt;br /&gt;Type: Remote vulnerability&lt;br /&gt;Status: Sold  &lt;i&gt;ZDI-CAN-477&lt;/i&gt;&lt;br /&gt;Discovered: 2-29-09&lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;IBM&lt;/span&gt;&lt;br /&gt;Severity: Medium&lt;br /&gt;Type: Local privilege escalation&lt;br /&gt;2 published, &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=784"&gt;4-15-09 iDefense&lt;/a&gt;, &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=802"&gt;5-20-09 iDefense&lt;/a&gt;&lt;br /&gt;1 unpublished&lt;br /&gt;&lt;br /&gt;Vendor:&lt;span style="font-weight: bold;"&gt; Sun&lt;/span&gt;&lt;br /&gt;Severity: Medium &lt;br /&gt;Status: &lt;span style="font-style: italic;"&gt;Reported to Sun&lt;/span&gt; - &lt;span style="font-size: 100%;"&gt;&lt;span id=":ie"&gt;Sun bugs  6821298, 6821299&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 100%;"&gt;&lt;span id=":ie"&gt;6821298 - Fixed - &lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-266348-1"&gt;Sun Alert&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Vendor: &lt;span style="font-weight: bold;"&gt;Novell&lt;/span&gt;&lt;br /&gt;Severity: Low&lt;br /&gt;Status: Sold - ZDI-CAN-440, ZDI-CAN-445&lt;br /&gt;Discovered: 02-09&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you would like to fund research into a particular application, contact me.&lt;br /&gt;If you would like to purchase anything listed as For Sale, contact me&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/608158407696852947-6700022655615246584?l=unsecurityresearch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unsecurityresearch.blogspot.com/feeds/6700022655615246584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/02/advisories-upcoming.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/6700022655615246584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/608158407696852947/posts/default/6700022655615246584'/><link rel='alternate' type='text/html' href='http://unsecurityresearch.blogspot.com/2009/02/advisories-upcoming.html' title='Advisories - Upcoming'/><author><name>Monarch</name><uri>http://www.blogger.com/profile/00127937541503546345</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
