Mobile devices play an important role in the business world. Yet with increased
emphasis on the Bring Your Own Device (BYOD) model, defenses are not where they
need to be to slow the loss of valuable intellectual property.
Corporate defenses have traditionally focused on the network, the endpoints, and
not necessarily on the ecosystem of how these devices interact outside of
network sockets. Smartphones bring unique network connectivity, an array of
sensors, and can be overlooked by resources invested on IDS/IPS not being
effectively leveraged.
Once again a vulnerability in Apples mobile operating system iOS was found by
some guys of the Jailbreak Nation. The newest version of this operating system
suffers from a weakness that makes it possible to unlock the lockscreen of all
iPhones that use iOS version 6.1. In this case it does not matter whether a PIN
or a password is used to unlock the phone. After successful exploitation an
attacker is able to see and edit contact-information, to add new contacts to the
phonebook, to view all pictures, to call the inbox or any of the contacts and to
see and delete the list of recent calls or parts of it.
Almost every higher class DSLR on the market today features multiple and complex
access technologies. To name a few, canons new flagship features IP connectivity
wired via 802.3 as well as wireless via 802.11. All the big vendors are pushing
these features to the market and advertise them with real time image transfer to
the cloud. We have taken a look at the layer 2 and 3 implementations in the
CamOS and the services running upon those, so here is what we found
while examine the EOS 1D X:
Our new
workshop about mobile application testing,
held for the 1st time at the Troopers conference 2013, is coming closer. So I
would like to take the opportunity and post an appetizer for those who are still
undetermined if they should attend the workshop ;-).
While the topic of mobile application testing is a wide field that may contain
reverse engineering, secure storage analysis, vulnerability research, network
traffic analysis and so forth, in the end of the day you have to answer one
question: Can I trust this application and run it on my enterprise devices? So
first you have to define some criteria, which kind of behavior and
characteristics of an application you regard as trustworthy (or not). Let us
peek at malware … besides harming your devices and data, malware is typically:
The root cause of the vulnerability is Rails handling of formatted
parameters. In addition to standard GET and POST parameter formats, Rails can
handle multiple different data encodings inside the body of POST requests. By
default JSON and XML are supported. While support for JSON is widely used in
production, the XML functionality does not seem to be known by many Rails
developers.
The CTL is basically a binary TLV file with 1 byte type, followed by 2 bytes
length and finally the data. But as this is far to easy, some special fields
omit the length field and just place the data after the type (I guess those are
fields with a fixed length). Here is an example CTL file:
Some of you may have heard the topic before, as we have spoken about on this
years BlackHat Europe, TROOPERS12 and HES12,
so this is nothing completely new, but as we’re done with responsible disclosure
(finally (-; ) and all the stuff should be fixed, we’re going to publish the
code that brought us there. I will split the topic into two blog posts, this one
will wrap up the setup, used components and protocols, the next one [tbd. till
EOY, hopefully] will get into detail on the tools and techniques we used to
break the enterprise grade security.
2 AFFECTED PRODUCTS The following Products have been tested as vulnerable so far: Cisco Unified Meetingplace with the following modules: • MeetingPlace Agent 7.1.1.9 • MeetingPlace Audio Service 7.1.1.8 • MeetingPlace Gateway SIM 7.1.1.2 • MeetingPlace Replication Service 7.1.1.9 • MeetingPlace Master Service 7.1.1.8 • MeetingPlace Extension 7.1.1.8 • MeetingPlace Authentication Filter 7.1.1.8
3 DETAILS The following parameters are affected: http://$IP/mpweb/scripts/mpx.dll [POST Parameter wcRecurMtgID]
4 VULNERABILITY SCORING The severity rating based on CVSS Version 2: Base Vector: (AV:N / AC:L / Au:S / C:P / I:P / A:P) CVSS Version 2 Score: 6.5 Severity: Low
Almost all of our presentations and write-ups on the VMDK File Inclusion
Vulnerability contained a slide stating something like
“we’re rather sure that DoS is possible as well ;-)”
including the following screenshot of the ESX purple screen of death:
So it seems like we still owe you that one — sorry for the delay! However the
actual attack to trigger this purple screen was rather simple: Just include
multiple VMDK raw files that cannot be aligned with 512 Byte blocks — e.g.
several files of 512 * X + [0 < Y < 512] Bytes. Writing to a virtual hard
drive composed of such single files for a short amount of time (typically one to
three minutes, this is what we observed in our lab) triggered the purple screen
on both ESXi4 and ESXi5 — at least for a patch level earlier than
Releasebuild-515841/March 2012: it seems like this vulnerability was patched in
Patch
ESXi500-201203201-UG.