NSX-T is a Software-Defined-Networking (SDN) solution of VMware which, as its
basic functionality, supports spanning logical networks across VMs on
distributed ESXi and KVM hypervisors. The central controller of the SDN is the
NSX-T Manager Cluster which is responsible for deploying the network
configurations to the hypervisor hosts.
This summer, I looked into the mechanism which is used to add new KVM hypervisor
nodes to the SDN via the NSX-T Manager. By tracing what happens on the KVM host,
I discovered that the KVM hypervisor got instructed to download the NSX-T
software packages from the NSX-T Manager via unencrypted HTTP and install them
without any verification. This enables a Man-in-the-Middle (MITM) attacker on
the network path to replace the downloaded packages with malicious ones and
compromise the KVM hosts.
Recently, I had a brief look at the Froala WYSIWYG HTML Editor (v3.2.0) as there
was a
post
about it on the Full Disclosure mailing list.
When targeting a HTML Editor, I guess one of the first things that everybody
does is to check for XSS vulnerabilities. So I tried the usual XSS payloads (a
great resource for XSS payloads is the
XSS cheat sheet
by PortSwigger) within the editor’s code view, but did not have much luck with
the common payloads as they were filtered. However, using the HTML object tag,
it was possible to trigger an XSS.
Microsoft has released a set of
privacy settings
for Office, one of which enables users to configure the type and amount of
diagnostic (i.e., telemetry) data that Office may send to Microsoft. When
deployed, it is available in the form of a group policy setting. It allows users
to configure one of the following diagnostic data levels: required,
optional, or neither. The report we produced:
I have started to have a look at my local installed helpers on macOS. These
helpers are used as an interface for applications to perform privileged
operations on the system. Thus, it is quite a nice attack surface to search for
Local Privilege Escalations.
Forklift is an advanced dual pane file manager for macOS. It is well known under
macOS power users.
As part of my investigation I identified vulnerabilities in Forklift allowing
local privilege escalation.
TLDR: This blogpost presents devi, a tool that
can help you devirtualize virtual calls in C++ binaries. It uses Frida to trace
the execution of a binary and uncover the call sources and destinations of
virtual calls. The collected information can then be viewed in IDA Pro, Binary
Ninja, or Ghidra. The plugin adds the respective control-flow edges allowing
further analysis (using different plugins) or simply providing more comfort when
analyzing C++ binaries.
Some time ago, we carried out an evaluation of the Digital Health Applications
Ordinance (Digitale-Gesundheitsanwendungen-Verordnung, DiGAV) for the Federal
Chamber of Psychotherapists in Germany (Bundespsychotherapeutenkammer, BPtK)
focusing on the security of digital health applications, often referred to as
apps on prescription.
The audit was intended to determine to which extent security guidelines,
security objectives, and best practices are adhered to by the requirements
formulated by the ordinance, thus enabling the foundations to securely operate
digital health applications. The main subject of the examination is whether
requirements, including procedural requirements defined in the ordinance are
sufficient to ensure security of digital health applications. The examination
has shown that the requirements can be seen as positive. However, in order to be
able to make reliable statements about the IT security of digital healthcare
applications, further details and mechanisms should be clarified within the
ordinance, which I would like to present in the following.
OpenSIS is an open source student information system.
Recently, it was affected by several vulnerabilities such as SQL injections,
local file inclusions and incorrect access controls
(CVE-2020-13380,
CVE-2020-13381,
CVE-2020-13382,
CVE-2020-13383).
That is why I got interested and also had a quick look at the application.
As part of this investigation, I discovered two vulnerabilities, an XSS
vulnerability (CVE-2020-27409) in the file SideForStudent.php that got quickly
fixed after being reported (see commit
edca085
for the details; the commit is included in release v7.5) and some incorrect
(i.e. non-existent) access controls for the password change functionality
(CVE-2020-27408). In this blog post, I would like to focus on the second
vulnerability and describe the tedious disclosure process that – in the end –
lead to nothing but the implementation of some ineffective obfuscation
mechanism.
Recently I discovered some vulnerabilities in
GNU Readline. These bugs
have been
fixed
in GNU Readline version 8.1.
The case of identifying the vulnerabilities was rather interesting. I wanted to
fuzz another program and wrote a quick harness to test if my setup works. This
test harness used GNU Readline to read input from stdin and passed the data
along to the function under test. I left the fuzzer running while I started to
improve the harness (which would also mean getting rid of GNU Readline as it is
relatively slow for the use-case at hand). However, AFL showed the first crashes
and upon inspection, the vulnerabilities where not in the code I actually wanted
to fuzz but in my systems GNU Readline.
Arrroooo… Bloodhound Crew!! Heard the news? CypherDog 4.0 is out and
it’s full of new features…
Now a couple of you might be thinking “Hey there, wait a minute… didn’t
CypherDog 3.0 come out not that long ago..??”, and I am happy to see some of you
are paying attention…
Indeed, when Bloodhound 3 came out, I quickly updated CypherDog 2 to CypherDog 3
to be compatible with it.
But Bloodhound 3 is compatible with neo4j 3 and 4, however the neo4j REST API
has been deprecated in neo4j 4 and CypherDog 3 relied on it.
Long story short, CypherDog 4.0 is a full rewrite compatible with the new
neo4j 4 HTTP API, and since I was refactoring the whole thing, I added some
cool new features to the tool.
The idea was to be able to do more with less keystrokes, and to do it
server-side…
And so I made a meme.
With this blog post I am pleased to announce the publication of a new ERNW White
Paper [1]. The paper
is about severe vulnerabilities in an insulin pump we assessed during project
ManiMed and we are proud to publish this subset of the results today.
Manipulating Medical Devices
The German Federal Office for Information Security (BSI), in its role as the
Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and
the public regarding security risks of networked medical devices. In response to
the often fatal security reports and press releases of networked medical
devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
in 2019. In this project, a security analysis of selected products is carried
out through security assessments. In the context of this project, severe
vulnerabilities were identified during the assessment of the DANA Diabecare RS
system.