<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Advisory on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/advisory/</link>
    <description>Recent content in Advisory on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 02 Sep 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/advisory/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vulnerability Disclosure: Stealing Emails via Prompt Injections</title>
      <link>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</link>
      <pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</guid>
      <description>&lt;p&gt;With the rise of AI assistance features in an increasing number of products, we&#xA;have begun to focus some of our research efforts on refining our internal&#xA;detection and testing guidelines for LLMs by taking a brief look at the new AI&#xA;integrations we discover.&lt;/p&gt;&#xA;&lt;p&gt;Alongside the rise of applications with LLM integrations, an increasing number&#xA;of customers come to ERNW to specifically assess AI applications. Our colleagues&#xA;&lt;a href=&#34;https://www.linkedin.com/in/fgrunow&#34;&gt;Florian Grunow&lt;/a&gt; and&#xA;&lt;a href=&#34;https://www.linkedin.com/in/hannesmohr/&#34;&gt;Hannes Mohr&lt;/a&gt; analyzed the novel attack&#xA;vectors that emerged and presented the results at&#xA;&lt;a href=&#34;https://troopers.de/troopers24/talks/vnwhm8/&#34;&gt;TROOPERS24&lt;/a&gt; already.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory: Airoha-based Bluetooth Headphones and Earbuds</title>
      <link>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</link>
      <pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Important note:&lt;/strong&gt; Some media coverage on this topic falsely or inaccurately&#xA;depicts the attack conditions. To be clear: Any vulnerable device can be&#xA;compromised if the attacker is in Bluetooth range. That is the only&#xA;precondition.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;During our research on Bluetooth headphones and earbuds, we identified several&#xA;vulnerabilities in devices that incorporate Airoha Systems on a Chip (SoCs). In&#xA;this blog post, we briefly want to describe the vulnerabilities, point out their&#xA;impact and provide some context to currently running patch delivery processes as&#xA;described at this year’s&#xA;&lt;a href=&#34;https://troopers.de/troopers25/talks/fbnb8y/&#34;&gt;TROOPERS Conference&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Multiple Vulnerabilities in X.Org X server prior to 21.1.17 and Xwayland prior to 24.1.7</title>
      <link>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</link>
      <pubDate>Tue, 17 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</guid>
      <description>&lt;p&gt;The X11 Window System has been used since September 1987 for Unix desktop&#xA;systems, allowing applications to display their windows. Today, one of the&#xA;server implementations of the protocol is the X.Org X server and XWayland, which&#xA;both use the same codebase. While reviewing the X server, several legacy&#xA;security issues were identified. These appear to originate from earlier design&#xA;stages when security considerations were less prominent. Despite the project’s&#xA;maturity and widespread use, some of these issues have persisted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Input Validation Vulnerabilities in Microsoft Bookings</title>
      <link>https://insinuator.net/2025/05/disclosure-input-validation-vulnerabilities-in-microsoft-bookings/</link>
      <pubDate>Thu, 08 May 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/05/disclosure-input-validation-vulnerabilities-in-microsoft-bookings/</guid>
      <description>&lt;p&gt;In a recent customer project, we discovered vulnerabilities in Microsoft&#xA;Bookings, an online appointment scheduling tool integrated into Microsoft 365,&#xA;allowing companies to have customers book meetings in available times&#xA;themselves. The findings originate from insufficient input validation on the&#xA;public meeting scheduling endpoint. Although Microsoft has largely mitigated&#xA;this vulnerability, our analysis provides important insights into potential&#xA;risks and areas for improvement.&lt;/p&gt;&#xA;&lt;h2 id=&#34;introduction--context&#34;&gt;Introduction &amp;amp; Context&lt;/h2&gt;&#xA;&lt;p&gt;Microsoft Bookings is a service that allows organizations to manage appointments&#xA;and meetings via a web interface. With integration to services such as Microsoft&#xA;Teams, the security of the booking process is critical. This blog post outlines&#xA;our technical analysis of the vulnerability, including proof-of-concept details&#xA;and an overview of the vendor response.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Full Disclosure: Multiple Rundeck Job Command Injections</title>
      <link>https://insinuator.net/2025/05/full-disclosure-multiple-rundeck-job-command-injections/</link>
      <pubDate>Mon, 05 May 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/05/full-disclosure-multiple-rundeck-job-command-injections/</guid>
      <description>&lt;p&gt;During a red-teaming-style customer project, we managed to get access to an&#xA;&lt;a href=&#34;https://www.rundeck.com/&#34;&gt;Rundeck&lt;/a&gt; API token. Rundeck is a job scheduler and&#xA;runbook automation platform designed to automate routine IT tasks across&#xA;multiple systems. At first, we were excited about this API token because if we&#xA;could create new Rundeck jobs, we could execute arbitrary code on the Rundeck&#xA;nodes and move laterally from there. However, it turned out that with this token&#xA;we only had permissions to run existing jobs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2024-11035: Minor Security Issues in VMware Carbon Black Cloud</title>
      <link>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</link>
      <pubDate>Mon, 31 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</guid>
      <description>&lt;p&gt;We recently conducted a security assessment of VMware Carbon Black Cloud, a&#xA;unified SaaS solution that integrates endpoint detection and response (EDR),&#xA;anti-virus, and vulnerability management capabilities. As part of our&#xA;evaluation, we tested the solution’s ability to detect and prevent malicious&#xA;activity on Windows and Linux systems. Our analysis focused on the Carbon Black&#xA;agents for these platforms, and although we did not identify any critical&#xA;vulnerabilities, we want to share some of the findings in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Command Injection in Kemp LoadMaster Load Balancer (CVE-2024-7591)</title>
      <link>https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/</link>
      <pubDate>Wed, 27 Nov 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/</guid>
      <description>&lt;p&gt;While conducting security research, I identified a critical vulnerability in Kemp’s LoadMaster Load Balancer. This vulnerability is a &lt;a href=&#34;https://owasp.org/www-community/attacks/Command_Injection&#34;&gt;Command Injection&lt;/a&gt; and allows full system compromise. It requires no authentication and can be exploited remotely by having access to the Web User Interface (WUI). Kemp found that all LoadMaster versions up to and including version 7.2.60.0 and also the multi-tenant hypervisors up to and including version 7.1.35.11 are affected.&lt;/p&gt;&#xA;&lt;p&gt;Kemp LoadMaster is a widely used Load Balancing Application that can commonly be seen in customer engagements. Therefore, we decided to take a closer look as part of our regular research projects.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory: Achieving PHP Code Execution in ILIAS eLearning LMS before v7.30/v8.11/v9.1</title>
      <link>https://insinuator.net/2024/05/security-advisory-achieving-php-code-execution-in-ilias-elearning-lms-before-v7.30/v8.11/v9.1/</link>
      <pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/security-advisory-achieving-php-code-execution-in-ilias-elearning-lms-before-v7.30/v8.11/v9.1/</guid>
      <description>&lt;p&gt;During my Bachelor’s thesis, I identified several XSS vulnerabilities and a PHP Code Execution vulnerability via an insecure file upload in the learning management system (LMS) ILIAS. The XSS vulnerability can be chained with the code execution vulnerability so that attackers with tutor privileges in at least one course can perform this exploit chain.&lt;/p&gt;&#xA;&lt;p&gt;The Bachelor’s thesis was motivated by the ever-increasing number of compromised universities in Germany&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:5&#34;&gt;&lt;a href=&#34;#fn:5&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;5&lt;/a&gt;&lt;/sup&gt;. The thesis analyzed the importance of LMS systems in that context, as those services are often exposed to the internet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lua-Resty-JWT Authentication Bypass</title>
      <link>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</link>
      <pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</guid>
      <description>&lt;p&gt;I was writing some challenges for PacketWars at&#xA;&lt;a href=&#34;https://troopers.de/&#34;&gt;TROOPERS22&lt;/a&gt;. One was intended to be a JWT key confusion&#xA;challenge where the public key from an RSA JWT should be recovered and used to&#xA;sign a symmetric JWT. For that, I was searching for a library vulnerable to JWT&#xA;key confusion by default and found &lt;em&gt;lua-resty-jwt&lt;/em&gt;. The original repository by&#xA;&lt;em&gt;SkyLothar&lt;/em&gt; is not maintained and different from the library that is installed&#xA;with the LuaRocks package manager. The investigated library is a&#xA;&lt;a href=&#34;https://github.com/cdbattags/lua-resty-jwt&#34;&gt;fork&lt;/a&gt; of the original repository,&#xA;maintained by &lt;em&gt;cdbattags&lt;/em&gt; in version 0.2.3 and was downloaded more than&#xA;&lt;a href=&#34;https://luarocks.org/modules/cdbattags/lua-resty-jwt&#34;&gt;4.8 million times&lt;/a&gt;&#xA;according to LuaRocks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jenkins – Groovy Sandbox breakout (SECURITY-1538 / CVE-2019-10393, CVE-2019-10394, CVE-2019-10399, CVE-2019-10400)</title>
      <link>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</link>
      <pubDate>Fri, 20 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</guid>
      <description>&lt;p&gt;Recently, I discovered a sandbox breakout in the Groovy Sandbox used by the Jenkins script-security Plugin in their Pipeline Plugin for build scripts. We responsibly disclosed this vulnerability and in the current version of Jenkins it has been fixed and the according &lt;a href=&#34;https://jenkins.io/security/advisory/2019-09-12/&#34;&gt;Jenkins Security Advisory 2019-09-12&lt;/a&gt; has been published. In this blogpost I want to report a bit on the technical details of the vulnerability.&lt;/p&gt;&#xA;&lt;h1 id=&#34;description&#34;&gt;Description&lt;/h1&gt;&#xA;&lt;p&gt;The groovy sandbox transforms some AST nodes of the script to add security checks. For example&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Cisco ACI</title>
      <link>https://insinuator.net/2019/07/security-advisories-for-cisco-aci/</link>
      <pubDate>Thu, 04 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/security-advisories-for-cisco-aci/</guid>
      <description>&lt;p&gt;Again, Cisco released security advisories for their software-defined networking (SDN) solution called Application Centric Infrastructure (ACI). As before (see blog post &lt;a href=&#34;https://insinuator.net/2019/05/security-advisory-for-cisco-nexus-9000-series-fabric-switches-in-aci-mode/&#34;&gt;here&lt;/a&gt;), the published advisories originated from research performed in our ACI lab.&lt;/p&gt;&#xA;&lt;p&gt;The following advisories have been published:&lt;/p&gt;&#xA;&lt;p&gt;Cisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-n9kaci-bypass&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-n9kaci-bypass&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 7.4&lt;/p&gt;&#xA;&lt;p&gt;Cisco Application Policy Infrastructure Controller REST API Privilege Escalation Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-ccapic-restapi&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-ccapic-restapi&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 7.2&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Nexus Repository Manager</title>
      <link>https://insinuator.net/2018/11/multiple-vulnerabilities-in-nexus-repository-manager/</link>
      <pubDate>Wed, 14 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/multiple-vulnerabilities-in-nexus-repository-manager/</guid>
      <description>&lt;p&gt;Recently, we identified security issues in the Nexus Repository Manager software developed by Sonatype. The tested versions were OSS 3.12.1-01 and OSS 3.13.1-01.&lt;/p&gt;&#xA;&lt;p&gt;The following issues could be identified:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Multiple Cross-Site Scripting (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789893-CVE-2018-16619-Nexus-Repository-Manager-XSS-October-17-2018&#34;&gt;CVE-2018-16619&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Missing Access Controls (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789453-CVE-2018-16620-Nexus-Repository-Manager-Missing-Access-Controls-October-17-2018?_ga=2.232570207.1112299337.1542137786-592006867.1539786845&#34;&gt;CVE-2018-16620&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Java Expression Language Injection (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789153-CVE-2018-16621-Nexus-Repository-Manager-Java-Injection-October-17-2018?_ga=2.232570207.1112299337.1542137786-592006867.1539786845&#34;&gt;CVE-2018-16621&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;The vulnerabilities are fixed in version 3.14.0. See the &lt;a href=&#34;https://help.sonatype.com/repomanager3/release-notes/2018-release-notes#id-2018ReleaseNotes-RepositoryManager3.14.0&#34;&gt;release notes&lt;/a&gt; and &lt;a href=&#34;https://support.sonatype.com/hc/en-us/sections/203012668-Security-Advisories&#34;&gt;security advisories&lt;/a&gt;  for further information.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;We identified a Java Expression Language Injection in the role and user creation function. In order to exploit this issue, the attacker needs to be authenticated with high privileges, the standard anonymous user is not sufficient.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security of Busch-Jaeger IP Gateway</title>
      <link>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</link>
      <pubDate>Wed, 16 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</guid>
      <description>&lt;p&gt;IoT is everywhere right now and there are a lot of products out there. I have been looking at an IP Gateway lately and found some serious issues. The &lt;a href=&#34;https://www.busch-jaeger.de/en/products/systems/door-communication/abb-welcome-ip-gateway-app-and-myabb-livingspace/&#34;&gt;Busch-Welcome IP-Gateway from Busch-Jaeger&lt;/a&gt; is one of the devices that bridges the gap between sensors and actors in your smart home and the network/Internet. It enables the communication to a door control system that implements various smart home functions. The device itself is offering an HTTP service to configure it, which is protected by a username and password. Some folks even actually expose the device and its login to the Internet. I tried to configure one of these lately and stumbled upon some security issues that I would like to discuss in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory for VMware vRealize Automation Center</title>
      <link>https://insinuator.net/2018/04/security-advisory-for-vmware-vrealize-automation-center/</link>
      <pubDate>Fri, 13 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/security-advisory-for-vmware-vrealize-automation-center/</guid>
      <description>&lt;p&gt;During a recent customer project we identified several vulnerabilities in the VMware vRealize Automation Center such as a DOM-based cross-site scripting and a missing renewal of session tokens during the login. The vulnerabilities have been disclosed to VMware on November 20th, 2017. A security advisory for the vulnerabilities has been made available &lt;a href=&#34;https://www.vmware.com/security/advisories/VMSA-2018-0009.html&#34;&gt;here&lt;/a&gt; on April 12th, 2018.&lt;/p&gt;&#xA;&lt;p&gt;Just a few words regarding the cross-site scripting vulnerability. This vulnerability is present within a GET request to the URL &lt;em&gt;/vcac/gadgets/ifr&lt;/em&gt; because of certain URL parameters whose values are directly passed to an &lt;em&gt;eval&lt;/em&gt; function call. The vulnerable parameters are &lt;em&gt;gwt:onLoadErrorFn&lt;/em&gt; and &lt;em&gt;gwt:onPropertyErrorFn&lt;/em&gt;. It seems that these parameters are actually never used by the application and we only found them by looking at the source code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Follow-Up on CVE-2016-1409 – IPv6 NDP DoS Vulnerability</title>
      <link>https://insinuator.net/2016/08/follow-up-on-cve-2016-1409-ipv6-ndp-dos-vulnerability/</link>
      <pubDate>Sun, 21 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/follow-up-on-cve-2016-1409-ipv6-ndp-dos-vulnerability/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/kafetzj&#34;&gt;Jed Kafetz&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;After seeing &lt;a href=&#34;https://www.insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/&#34;&gt;Christopher’s post&lt;/a&gt; I decided to create a proof using GNS3 and Virtualbox.&lt;br&gt;&#xA;The aim is to perform the exact attacking using Antonios Atlasis’ &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;Chiron tools&lt;/a&gt; and run a Wireshark packet capture to prove the hop limit drops below 255.&lt;/p&gt;&#xA;&lt;p&gt;The following topology is used in GNS3:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/08/nw_diagram.png&#34; alt=&#34;nw_diagram&#34;&gt;The routers used are Cisco C372 and the machine labled Ubuntu is running 14.04 LTS Ubuntu Desktop, default installation. F0/0 is on the right and F0/1 is on the left.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jenkins Remoting RCE II – The return of the ysoserial</title>
      <link>https://insinuator.net/2016/07/jenkins-remoting-rce-ii-the-return-of-the-ysoserial/</link>
      <pubDate>Fri, 01 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/jenkins-remoting-rce-ii-the-return-of-the-ysoserial/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/06/headshot.png&#34; alt=&#34;Jenkins Logo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://jenkins-ci.org/&#34;&gt;Jenkins&lt;/a&gt; is a continuous integration server, widely used in Java environments for building automation and deployment. The project recently disclosed an unauthenticated remote code execution vulnerability discovered by Moritz Bechler. Depending on the development environment, a Jenkins server can be a critical part of the infrastructure: It often creates the application packages that later will be deployed on production application servers. If an attacker can execute arbitrary code, s/he can easily manipulate those packages and inject additional code. Another scenario would be that the attacker stealing credentials, like passwords, private keys that are used for authentication in the deployment process or similar.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some infos about SAP Security Note 2258786</title>
      <link>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</link>
      <pubDate>Thu, 30 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</guid>
      <description>&lt;p&gt;On the 8th of March SAP released the security note for a vulnerability we reported during an assessment of a SAP landscape. The issue affects the SAP NetWeaver Web Administration Interface.  By knowing a special URL a malicious user can acquire version information about the services enabled in the SAP system as well as the operating system used.  We wanted to share some details on the issue.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerability is a bypass of the HTTP Basic Authorization for the &lt;a href=&#34;https://help.sap.com/saphelp_nw73/helpdata/en/4b/c1cd5cfb0050e9e10000000a15822b/content.htm?frameset=/en/48/3e191a252f72d0e10000000a42189c/frameset.htm&amp;amp;current_toc=/en/62/d678c5330a4992bc6fe927e6137c9d/plain.htm&amp;amp;node_id=155&amp;amp;show_children=false&#34;&gt;SAP Web Administration Interface&lt;/a&gt;. It discloses version information about the system respectively operating system, a brief SAP patch level overview and running services including their corresponding ports.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2016-1409 – IPv6 NDP DoS Vulnerability in Cisco Software</title>
      <link>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</link>
      <pubDate>Mon, 30 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</guid>
      <description>&lt;p&gt;Dear readers,&lt;/p&gt;&#xA;&lt;p&gt;As you may have already noticed, Cisco released an urgent &lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6&#34;&gt;security advisory&lt;/a&gt; describing an IPv6 Neighbor Discovery DoS Vulnerability in several flavors of Cisco’s operating systems. Currently IOS-XR, XE and NX-OS are affected while ASA and “classic” IOS are under investigation. At first glance, it might look like yet another IPv6 DoS vulnerability. Looking closer, Cisco is mentioning an unauthenticated, remote attacker due to insufficient processing logic for crafted IPv6 NDP packets that are sent to an affected device. Following the public discussion about the vulnerability, it seems that these packets will reach the, probably low rate-limited, &lt;a href=&#34;https://supportforums.cisco.com/document/93456/asr9000xr-local-packet-transport-services-lpts-copp&#34;&gt;LPTS&lt;/a&gt; filter/queue on IOS XR devices “crowding” out legitimate NDP packets resulting in a DoS for IPv6 traffic, or in general a high CPU load as these packets will be processed by the CPU. More details are currently not available, but this might indicate the affected systems aren’t doing proper message validation checks on NDP packets (in addition to the LPTS filter/queue problem).&lt;/p&gt;</description>
    </item>
    <item>
      <title>WPAD Name Collision Vulnerability (TA16-144A)</title>
      <link>https://insinuator.net/2016/05/wpad-name-collision-vulnerability-ta16-144a/</link>
      <pubDate>Tue, 24 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/wpad-name-collision-vulnerability-ta16-144a/</guid>
      <description>&lt;p&gt;Yesterday the US-CERT released a &lt;a href=&#34;https://www.us-cert.gov/ncas/alerts/TA16-144A&#34;&gt;Technical Alert&lt;/a&gt; (TA16-144A) about the recently found WPAD Name Collision Vulnerability. We will give you a summary about the vulnerability as well as the basic mechanisms here.&lt;/p&gt;&#xA;&lt;h2 id=&#34;wpad&#34;&gt;WPAD&lt;/h2&gt;&#xA;&lt;p&gt;The Web Proxy Auto-Discovery Protocol is used to auto-configure the proxy for web browsers. So when joining the according network the browser can use DHCP and DNS methods to find a specific configuration file (typically named wpad.dat), which is loaded and applied to the browser’s settings. Therefore, there is no need to configure each browser in your environment individually/manually.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BMC BladeLogic Vulnerabilities PoCs</title>
      <link>https://insinuator.net/2016/05/bmc-bladelogic-vulnerabilities-pocs/</link>
      <pubDate>Mon, 23 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/bmc-bladelogic-vulnerabilities-pocs/</guid>
      <description>&lt;p&gt;Hi everyone!&lt;/p&gt;&#xA;&lt;p&gt;A quick update: earlier in our blog we released &lt;a href=&#34;https://www.insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/&#34;&gt;BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543&lt;/a&gt; vulnerabilities. Now the exploits are also available in our &lt;a href=&#34;https://github.com/ernw/insinuator-snippets/tree/master/bmc_bladelogic&#34;&gt;github&lt;/a&gt; if you want to check your systems 😉&lt;/p&gt;&#xA;&lt;p&gt;Have a nice week,&lt;br&gt;&#xA;Olga&lt;/p&gt;</description>
    </item>
    <item>
      <title>BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543</title>
      <link>https://insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;Hope those of you who attended Troopers16 enjoyed it as much as we did! In this post I want to summarize my &lt;a href=&#34;https://www.troopers.de/events/troopers16/648_one_tool_to_rule_them_all_-_and_what_can_it_lead_to/&#34;&gt;Troopers16 talk&lt;/a&gt; and provide you with some details about freshly assigned CVE-2016-1542 and CVE-2016-1543 related to BMC BladeLogic software.&lt;/p&gt;&#xA;&lt;p&gt;To start with, BMC Software Inc. is an American company specializing in business service management software; they develop software used for multiple functions, including IT service management, data center automation, performance management, virtualization lifecycle management and cloud computing management. Among other products they have developed a BladeLogic suite that includes Database Automation, Middleware Automation, Server Automation, and Network Automation tools. The one under our focus was BladeLogic Server Automation (BSA).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Xen XSA 155: Double fetches in paravirtualized devices</title>
      <link>https://insinuator.net/2015/12/xen-xsa-155-double-fetches-in-paravirtualized-devices/</link>
      <pubDate>Thu, 17 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/xen-xsa-155-double-fetches-in-paravirtualized-devices/</guid>
      <description>&lt;p&gt;As part of my research on the security of paravirtualized devices, I reported a number of vulnerabilities to the Xen security team, which were patched &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-155.html&#34;&gt;today&lt;/a&gt;. All of them are double fetch vulnerabilities affecting the different backend components used for paravirtualized devices. While the severity and impact of these bugs varies heavily and is dependent on a lot of external factors, I would recommend patching them as soon as possible. In the rest of this blog post I’ll give a short teaser about my research with full details coming out in the first quarter of 2016 .&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMware did it again: vCenter Remote Code Execution</title>
      <link>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</link>
      <pubDate>Fri, 02 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</guid>
      <description>&lt;p&gt;Yesterday 7Elements released &lt;a href=&#34;https://www.7elements.co.uk/resources/blog/cve-2015-2342-remote-code-execution-within-vmware-vcenter/&#34;&gt;the description&lt;/a&gt; of a Remote Code Execution vulnerability in VMware vCenter. The information came in at a good point as I’m at the moment drafting a follow-up blogpost for &lt;a href=&#34;https://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;this one&lt;/a&gt; which will summarize some of our approaches to virtualization security. The vCenter vulnerability is both quite critical and particularly interesting in several ways:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Once there is proper network isolation &amp;amp; restriction, the vulnerability should not be exploitable from the overall corporate network (or maybe even the Internet — a quick inaccurate shodan search for “vcenter” returned about 1800 results and at random checks actually revealed vCenter systems). It should also not be exploitable from ESXi hosts managed through the vCenter: ESXi hosts need to be able to connect to the vCenter for heartbeat messages, however “only” on ports 443 and 902 — the vulnerability exploits a service running on TCP ports &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2051575&#34;&gt;9875 – 9877&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;It is questionable whether the exploited Java RMI functionality is really required for the operation of VMware infrastructures. This &lt;a href=&#34;http://www.accuvant.com/blog/exploiting-jmx-rmi&#34;&gt;blogpost&lt;/a&gt; provides further detail on the known type of vulnerability in Java applications. VMware had a similar issue back in 2010, where &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1034175&#34;&gt;their workaround&lt;/a&gt; to fix a vulnerability was to just disable the affected component, resulting in the impression that it wasn’t even required in the first place. Let’s see whether the future will bring up more vulnerabilities which could have been prevented by implementing more thorough hardening of all components (e.g. following the &lt;em&gt;minimal machine&lt;/em&gt; principle). Furthermore in 2011 there was a similar 3^(rd) party component vulnerability in vCenter which we covered &lt;a href=&#34;https://www.insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/&#34;&gt;in this blogpost&lt;/a&gt;. The totality of our posts on VMware security can be found &lt;a href=&#34;https://www.insinuator.net/tag/vmware/&#34;&gt;here&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;For high-security environments we have been recommending for some time to use a dedicated vCenter per hypervisor cluster (i.e. if you have two hypervisor clusters, one for internal and one for DMZ systems, you should use two separate vCenter systems). Vulnerabilities like these illustrate the need for that, given that the ESXi hosts need to be able to access the vCenter on the network level.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Happy patching &amp;amp; stay tuned,&lt;/p&gt;</description>
    </item>
    <item>
      <title>General Pr0ken Filesystem – Hacking IBM’s GPFS</title>
      <link>https://insinuator.net/2015/04/general-pr0ken-filesystem-hacking-ibms-gpfs/</link>
      <pubDate>Sun, 12 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/general-pr0ken-filesystem-hacking-ibms-gpfs/</guid>
      <description>&lt;p&gt;&lt;em&gt;This post is a short wrap-up of our Troopers talk about the research we did on IBM’s General Parallel File System. If you are interested in all the technical details take a look at our &lt;a href=&#34;https://www.troopers.de/media/filer_public/69/81/69812750-49b0-4631-a3e6-fb402c88adf3/fwfggpfs_troopers15.pdf&#34; title=&#34;slides&#34;&gt;slides&lt;/a&gt; or the &lt;a href=&#34;https://www.youtube.com/watch?v=rmWMEdA-3Qs&#34;&gt;video recording&lt;/a&gt;. We will also give an updated version of this talk at the &lt;a href=&#34;http://www.phdays.com/&#34;&gt;PHDays&lt;/a&gt; conference in Moscow next month.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;The IBM General Parallel File System is a distributed file system used in large scale enterprise environments, high performance clusters as well as some of the worlds largest super computers. It is considered by many in the industry to be the most feature rich and production hardened distributed file system currently available. GPFS has a long and really interesting history, going back to the Tiger Shark file system created by IBM 1993.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XML External Entity (XXE) Injection in Apache Batik Library [CVE-2015-0250]</title>
      <link>https://insinuator.net/2015/03/xml-external-entity-xxe-injection-in-apache-batik-library-cve-2015-0250/</link>
      <pubDate>Sat, 21 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/xml-external-entity-xxe-injection-in-apache-batik-library-cve-2015-0250/</guid>
      <description>&lt;p&gt;During one of our latest web application code review projects I came across a vulnerability for which I think it is worth to speak about. It is an injection based attack against XML parsers which uses a rarely required feature called external entity expansion. The XML specification allows XML documents to define entities which reference resources external to the document and parsers typically support this feature by default. If an application parses XML input from untrusted sources and the parsing routine is not properly configured this can be exploited by an attacker with a so called XML external entity (XXE) injection. A successful XXE injection attack could allow an attacker to access the file system, cause a DoS attack or inject script code (e.g. Javascript to perform an XSS attack).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Revisiting Xen’s x86 Emulation: Xen XSA 123</title>
      <link>https://insinuator.net/2015/03/revisiting-xens-x86-emulation-xen-xsa-123/</link>
      <pubDate>Tue, 10 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/revisiting-xens-x86-emulation-xen-xsa-123/</guid>
      <description>&lt;p&gt;In my &lt;a href=&#34;http://www.insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/&#34; title=&#34;The Dangers of x86 Emulation: Xen XSA 110 and 105&#34;&gt;last blog post&lt;/a&gt;, I gave an overview about recent vulnerabilities discovered in the x86 emulation layer of Xen. While both of the discussed vulnerabilities only allow for guest privilege escalation, the complexity of the involved code seemed to indicate that even more interesting bugs could be discovered. So I spent some time searching for memory corruption issues and discovered a very interesting bug that resulted in &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-123.html&#34;&gt;XSA 123&lt;/a&gt; . This post gives an overview about the root cause of the bug and a short description of exploitation challenges. A follow-up post will describe possible exploitation strategies in more detail.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Dangers of x86 Emulation: Xen XSA 110 and 105</title>
      <link>https://insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/</link>
      <pubDate>Mon, 23 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/02/xen-300x81.png&#34; alt=&#34;Xen Logo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Developing a secure and feature rich hypervisor is no easy task. Recently, the open source Xen hypervisor was affected by two interesting vulnerabilities involving its x86 emulation code: &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-110.html&#34;&gt;XSA 110&lt;/a&gt; and &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-105.html&#34;&gt;XSA 105&lt;/a&gt;. Both bugs show that the attack surface of hypervisors is often larger than expected. XSA 105 was &lt;a href=&#34;//labs.bitdefender.com/wp-content/uploads/downloads/2014/10/Gaining-kernel-privileges-using-the-Xen-emulator.pdf&#34;&gt;originally reported&lt;/a&gt;) by Andrei Lutas from BitDefender. The patch adds missing privilege checks to the emulation routines of several critical system instructions including LGDT and LIDT. The vulnerable code can be reached from unprivileged user code running inside hardware virtual machine (HVM) guests and can be used to escalate guest privileges. XSA 110 was reported by Jan Beulich from SUSE and concerns insufficient checks when emulating long jumps, calls or returns.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitHub Enterprise 2.0.0 Fixes Multiple Vulnerabilities</title>
      <link>https://insinuator.net/2014/11/github-enterprise-2.0.0-fixes-multiple-vulnerabilities/</link>
      <pubDate>Mon, 17 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/github-enterprise-2.0.0-fixes-multiple-vulnerabilities/</guid>
      <description>&lt;p&gt;Recently we had the pleasure to take a look at GitHub’s Enterprise appliance. The appliance allows one to deploy the excellent GitHub web interface locally to host code on-site. Besides the well known interface, which is similar to the one hosted at &lt;a href=&#34;https://github.com/&#34;&gt;github.com&lt;/a&gt;, the appliance ships with a separate interface called the management console, which is used for administrative tasks like the configuration of the appliance itself. This management interface is completely decoupled from the user interface.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Own a Router – Fritz!Box AVM Vulnerability Analysis</title>
      <link>https://insinuator.net/2014/03/how-to-own-a-router-fritzbox-avm-vulnerability-analysis/</link>
      <pubDate>Tue, 11 Mar 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/03/how-to-own-a-router-fritzbox-avm-vulnerability-analysis/</guid>
      <description>&lt;p&gt;&lt;em&gt;The below post was originally written on February 9th as a little educational exercise &amp;amp; follow-up to my &lt;a href=&#34;http://www.insinuator.net/2013/07/reverse-engineering-tools/&#34;&gt;BinDiff&lt;/a&gt; post. (This research was actually triggered by a relative asking about that strange Fritz!Box vulnerability he heard about on the radio). Once we realized the full potential of the bug we decided against publishing the post and contacted several parties instead. Amongst others this contributed to the German BSI &lt;a href=&#34;https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2014/Fritz-Box-Update_11022014.html&#34;&gt;press release&lt;/a&gt;. Given the &lt;a href=&#34;http://www.heise.de/security/meldung/Hack-gegen-AVM-Router-Fritzbox-Luecke-offengelegt-Millionen-Router-in-Gefahr-2136784.html&#34;&gt;cat is out of the bag&lt;/a&gt; now anyway, we see no reason to hold it back. We will further take this as an opportunity to lay out our basic vulnerability disclosure principles in a future post. This topic will also be discussed in the panel “Ethics of Security Work &amp;amp; Research” at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analyzing a CVE-2013-3346/CVE-2013-5065 Exploit with peepdf</title>
      <link>https://insinuator.net/2014/02/analyzing-a-cve-2013-3346/cve-2013-5065-exploit-with-peepdf/</link>
      <pubDate>Mon, 10 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/analyzing-a-cve-2013-3346/cve-2013-5065-exploit-with-peepdf/</guid>
      <description>&lt;p&gt;This is a guest post from Jose Miguel Esparza (&lt;a href=&#34;https://twitter.com/EternalTodo&#34;&gt;@EternalTodo&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;There are already some good blog posts talking about this exploit, but I think this is a really good example to show how &lt;a href=&#34;http://peepdf.eternal-todo.com/&#34;&gt;&lt;em&gt;peepdf&lt;/em&gt;&lt;/a&gt; works and what you can learn if you attend the workshop &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-1-day-workshop-squeezing-exploit-kits-and-pdf-exploits/index.html&#34;&gt;&lt;em&gt;“Squeezing Exploit Kits and PDF Exploits”&lt;/em&gt;&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/troopers14/index.html&#34;&gt;Troopers14&lt;/a&gt;.  The mentioned exploit was using the &lt;a href=&#34;http://www.zerodayinitiative.com/advisories/ZDI-13-212/&#34;&gt;Adobe Reader ToolButton Use-After-Free&lt;/a&gt; vulnerability to execute code in the victim’s machine and then the &lt;a href=&#34;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5065&#34;&gt;Windows privilege escalation 0day&lt;/a&gt; to bypass the &lt;a href=&#34;http://cansecwest.com/slides/2013/Adobe%20Sandbox.pdf&#34;&gt;Adobe sandbox&lt;/a&gt; and execute a new payload without restrictions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS in SAP Netweaver</title>
      <link>https://insinuator.net/2014/01/xss-in-sap-netweaver/</link>
      <pubDate>Fri, 24 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/xss-in-sap-netweaver/</guid>
      <description>&lt;p&gt;We just got &lt;a href=&#34;http://scn.sap.com/docs/DOC-8218&#34; title=&#34;Acknowledgments to Security Researchers&#34;&gt;credits&lt;/a&gt; for a flaw we found in SAP Netweaver. The issue is a reflected &lt;a href=&#34;https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_%28XSS%29&#34; title=&#34;OWASP Top 10 - XSS&#34;&gt;Cross-Site Scripting&lt;/a&gt; (XSS). It can be triggered in the administrative interface for the Internet Communication Manager (ICM) and Web Dispatcher. This means that the targets for this XSS will definitely be users with administrative privileges. This makes it especially juicy for an attacker.&lt;/p&gt;&#xA;&lt;p&gt;SAP rated the vulnerability with CVSS and a Base Score of 4.3 having a Base Vector of &lt;code&gt;AV:N/AC:M/AU:N/C:N/I:P/A:N&lt;/code&gt;. Which again opens the discussion on how to rate the impact of XSS by using CVSS. CVSS &lt;a href=&#34;http://www.first.org/cvss/cvss-guide#i3.1.1&#34; title=&#34;CVSS rating XSS&#34;&gt;states&lt;/a&gt; that XSS “&lt;em&gt;should be scored with no impact to confidentiality or availability, and partial impact to integrity&lt;/em&gt;“, which is clearly arguable. Especially when thinking of the impact on confidentiality. As you might know by now, we tried to tackle the problem of rating vulnerabilities ourselves with the &lt;a href=&#34;http://www.insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/&#34; title=&#34;ERRS&#34;&gt;ERNW Rapid Rating System&lt;/a&gt; (ERRS) and it was not an easy task. 😉 However, SAP states that this is a correction with high priority, so you should apply the patches as soon as possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploiting Hyper-V: How We Discovered MS13-092</title>
      <link>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</link>
      <pubDate>Tue, 14 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</guid>
      <description>&lt;p&gt;During a recent research project we performed an in-depth security assessment of Microsoft’s virtualization technologies, including Hyper-V and Azure. While we already had experience in discovering security vulnerabilities in other virtual environments (e.g. &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;), this was our first research project on the Microsoft virtualization stack and we took care to use a &lt;a href=&#34;http://www.insinuator.net/2013/05/analysis-of-hypervisor-breakouts/&#34;&gt;structured evaluation strategy&lt;/a&gt; to cover all potential attack vectors.&lt;br&gt;&#xA;Part of our research concentrated on the Hyper-V hypervisor itself and we discovered a critical vulnerability which can be exploited by an unprivileged virtual machine to crash the hypervisor and potentially compromise other virtual machines on the same physical host. This bug was recently patched, see &lt;a href=&#34;https://technet.microsoft.com/en-us/security/bulletin/ms13-092&#34;&gt;MS13-092&lt;/a&gt; and our &lt;a href=&#34;http://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;corresponding post&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of Rails XML Parameter Parsing Vulnerability</title>
      <link>https://insinuator.net/2013/01/analysis-of-rails-xml-parameter-parsing-vulnerability/</link>
      <pubDate>Tue, 08 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/analysis-of-rails-xml-parameter-parsing-vulnerability/</guid>
      <description>&lt;p&gt;This post tries to give an overview about the background and impact of the &lt;a href=&#34;https://groups.google.com/forum/#!topic/rubyonrails-security/61bkgvnSGTQ/discussion&#34;&gt;new Rails XML parameter parsing vulnerability patched today&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-bug&#34;&gt;The bug&lt;/h2&gt;&#xA;&lt;p&gt;The root cause of the vulnerability is Rails handling of formatted parameters. In addition to standard GET and POST parameter formats, Rails can handle multiple different data encodings inside the body of POST requests. By default JSON and XML are supported. While support for JSON is widely used in production, the XML functionality does not seem to be known by many Rails developers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection in Cisco MeetingPlace</title>
      <link>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</link>
      <pubDate>Thu, 08 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</guid>
      <description>&lt;p&gt;Cisco has released a &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mp&#34;&gt;security advisory&lt;/a&gt; for a vulnerability we discovered last year.&lt;br&gt;&#xA;For comparison here is our original advisory to cisco:&lt;/p&gt;&#xA;&lt;h5 id=&#34;security-advisory-for-cisco-unified-communications-solution&#34;&gt;Security Advisory for Cisco Unified Communications Solution&lt;/h5&gt;&#xA;&lt;h5 id=&#34;release-date-1182012-author-daniel-mende&#34;&gt;Release Date: 11/8/2012 Author: Daniel Mende&lt;/h5&gt;&#xA;&lt;h5 id=&#34;1-summary-multiple-critical-sql-injections-exist-in-cisco-unified-meeting-place&#34;&gt;1 SUMMARY Multiple critical SQL injections exist in Cisco unified meeting place.&lt;/h5&gt;&#xA;&lt;h5 id=&#34;2-affected-products-the-following-products-have-been-tested-as-vulnerable-so-far-cisco-unified-meetingplace-with-the-following-modules--meetingplace-agent-7119--meetingplace-audio-service-7118--meetingplace-gateway-sim-7112--meetingplace-replication-service-7119--meetingplace-master-service-7118--meetingplace-extension-7118--meetingplace-authentication-filter-7118&#34;&gt;2 AFFECTED PRODUCTS The following Products have been tested as vulnerable so far: Cisco Unified Meetingplace with the following modules: • MeetingPlace Agent 7.1.1.9 • MeetingPlace Audio Service 7.1.1.8 • MeetingPlace Gateway SIM 7.1.1.2 • MeetingPlace Replication Service 7.1.1.9 • MeetingPlace Master Service 7.1.1.8 • MeetingPlace Extension 7.1.1.8 • MeetingPlace Authentication Filter 7.1.1.8&lt;/h5&gt;&#xA;&lt;h5 id=&#34;3-details-the-following-parameters-are-affected-httpipmpwebscriptsmpxdll-post-parameter-wcrecurmtgid&#34;&gt;3 DETAILS The following parameters are affected: http://$IP/mpweb/scripts/mpx.dll [POST Parameter wcRecurMtgID]&lt;/h5&gt;&#xA;&lt;h5 id=&#34;4-vulnerability-scoring-the-severity-rating-based-on-cvss-version-2-base-vector-avn--acl--aus--cp--ip--ap-cvss-version-2-score-65-severity-low&#34;&gt;4 VULNERABILITY SCORING The severity rating based on CVSS Version 2: Base Vector: (AV:N / AC:L / Au:S / C:P / I:P / A:P) CVSS Version 2 Score: 6.5 Severity: Low&lt;/h5&gt;&#xA;&lt;h5 id=&#34;5-proof-of-concept-post-mpwebscriptsmpxdll-http11-host-10xxx-user-agent-mozilla50-accept-texthtmlapplicationxhtmlxmlapplicationxmlq09q08-accept-language-en-usenq05-accept-encoding-gzip-deflate-accept-charset-iso-8859-1utf-8q07q07-proxy-connection-keep-alive-referer-http10xxxmpwebscriptsmpxdll-cookie-cookiestrue-content-type-applicationx-www-form-urlencoded-content-length-571&#34;&gt;5 PROOF OF CONCEPT POST /mpweb/scripts/mpx.dll HTTP/1.1 Host: 10.X.X.X User-Agent: Mozilla/5.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Proxy-Connection: keep-alive Referer: http://10.X.X.X/mpweb/scripts/mpx.dll Cookie: cookies=true Content-Type: application/x-www-form-urlencoded Content-Length: 571&lt;/h5&gt;&#xA;&lt;h5 id=&#34;sessionida40490a1-ab17-4c1e-ba4a-e3c5c90f62ca1ed59e5c-a774-4546-8683--aeb15d6fbd0d55931857-6296-48ec-9434-3231c683c47dadadfjadlkenmfhmplaihgkddg-wcmeetingidwcrecurmtgid-or-11-url0wcbasetpltxt0startseiteurl1-txt1url2txt2url3txt3url4txt4url5txt5mtgcattosearch-28all2bcategories29ml_publicpostedyesmtgidtosearch0000007schedulerid-wcrequestwchashformtypelistmeetingswcstate3stplwcfindmtgtplftpl-wcfindmtgtplml_listmt_todayml_endtime_monthml_endtime_dayml_end-time_yearml_showcontmtgsyessp_vlanguagelang999i00&#34;&gt;SessionID=A40490A1-AB17-4C1E-BA4A-E3C5C90F62CA.1ED59E5C-A774-4546-8683- AEB15D6FBD0D.55931857-6296-48ec-9434-3231c683c47d.ADadfjadlkeNmFhmplaihgkdDg &amp;amp;wcMeetingID=&amp;amp;wcRecurMtgID=‘ or 1=1 —&amp;amp;URL0=wcBase.tpl&amp;amp;TXT0=Startseite&amp;amp;URL1=&amp;amp; TXT1=&amp;amp;URL2=&amp;amp;TXT2=&amp;amp;URL3=&amp;amp;TXT3=&amp;amp;URL4=&amp;amp;TXT4=&amp;amp;URL5=&amp;amp;TXT5=&amp;amp;MtgCatToSearch= %28all%2Bcategories%29&amp;amp;ML_PublicPosted=Yes&amp;amp;MtgIDToSearch=0000007&amp;amp;SchedulerID= &amp;amp;wcRequest=&amp;amp;wcHash=&amp;amp;FormType=listmeetings&amp;amp;wcState=3&amp;amp;STPL=wcFindMtg.tpl&amp;amp;FTPL= wcFindMtg.tpl&amp;amp;ML_List=MT_Today&amp;amp;ML_EndTime_Month=&amp;amp;ML_EndTime_Day=&amp;amp;ML_End Time_Year=&amp;amp;ML_ShowContMtgs=Yes&amp;amp;SP_VLanguage=lang999i00&lt;/h5&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Update: Microsoft Advisory 2757760 Windows Internet Explorer Vulnerability</title>
      <link>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</link>
      <pubDate>Thu, 20 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</guid>
      <description>&lt;p&gt;Microsoft takes this vulnerability quite serious and was acting fast. The Microsoft Security Response Center announced the availability of a fix last night in the &lt;a href=&#34;http://blogs.technet.com/b/msrc/archive/2012/09/19/internet-explorer-fix-it-available-now-security-update-scheduled-for-friday.aspx&#34;&gt;MSRC Blog&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The fix will be available via Windows Update on friday, the 21st of september. So it’s time to get ready for this update ;-).&lt;/p&gt;&#xA;&lt;p&gt;Have a nice day&lt;br&gt;&#xA;Michael&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Advisory 2757760: Windows Internet Explorer Zero-Day Vulnerability</title>
      <link>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</link>
      <pubDate>Wed, 19 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</guid>
      <description>&lt;p&gt;Actually a Windows Vulnerability (&lt;a href=&#34;http://technet.microsoft.com/en-us/security/advisory/2757760&#34;&gt;Microsoft Advisory 2757760&lt;/a&gt;) related to the Internet Explorer Version 7, 8 and 9 is in the news. Microsoft is aware of the problem, but there’s no patch available yet. We call this a 0-Day :-). Making the problem even worse, on monday reliable &lt;a href=&#34;https://community.rapid7.com/community/metasploit/blog/2012/09/17/lets-start-the-week-with-a-new-internet-explorer-0-day-in-metasploit&#34;&gt;exploit code&lt;/a&gt; was released within the Metasploit project, so exploit code is already in the wild.&lt;/p&gt;&#xA;&lt;p&gt;Basically Microsoft suggests two workarounds:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Usage of EMET &lt;a href=&#34;http://support.microsoft.com/kb/2458544&#34;&gt;(Enhanced Mitigation Experience Toolkit&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Disabling Active X and Active Scripting in the Internet Settings&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;But both of them have some impact: EMET must be deployed before any usage (btw. EMET can be configured via Group Policies) and disabling Active X and Active Scripting might break some business relevant web sites (that can be added to the “Trusted Sites” Zone, but might produce major operational effort).&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMSA-2011-0005: VMware vCenter Orchestrator remote code execution vulnerability</title>
      <link>https://insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/</link>
      <pubDate>Mon, 14 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/</guid>
      <description>&lt;p&gt;Reading &lt;a href=&#34;http://www.vmware.com/security/advisories/VMSA-2011-0005.html&#34;&gt;this advisory&lt;/a&gt; I’m quite tempted to emit another rant on the relationship of heavy use of 3rd party components, lack of (security) quality assurance and services running at times where they’re not needed (see second workaround &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1034175&#34;&gt;here&lt;/a&gt;). I’ll refrain  from that for today. Just wanted to let you know that the &lt;a href=&#34;http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html&#34;&gt;underlying vulnerability&lt;/a&gt; in Struts2 was initially discovered by Meder Kydyraliev who gives &lt;a href=&#34;http://www.troopers.de/troopers11/agenda/milking-a-horse-or-executing-remote-code-in-modern-java-web-frameworks/&#34;&gt;this talk&lt;/a&gt; at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; in two weeks. He’ll certainly describe the inner workings of this one, and others… 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>MS10-063, Prevention</title>
      <link>https://insinuator.net/2010/09/ms10-063-prevention/</link>
      <pubDate>Wed, 15 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/ms10-063-prevention/</guid>
      <description>&lt;p&gt;One of the four vulnerabilities rated “critical” from yesterday’s MS patchday, that is &lt;a href=&#34;http://www.microsoft.com/technet/security/bulletin/MS10-063.mspx&#34;&gt;MS10-063&lt;/a&gt;, has an interesting “Workarounds” section as for MS Internet Explorer. There it’s stated:&lt;/p&gt;&#xA;&lt;p&gt;“Disabling the support for the parsing of embedded fonts in Internet Explorer prevents this application from being used as an attack vector.”&lt;/p&gt;&#xA;&lt;p&gt;which, according to the advisory, should/can be done by setting the “Font Downloading” parameter to “Disable”.&lt;/p&gt;&#xA;&lt;p&gt;Which is exactly what &lt;a href=&#34;http://www.ernw.de/content/e15/e28/e1497/download1499/ERNW_Newsletter_31_Secure_IE8_Configuration_en_ger.pdf&#34;&gt;this document&lt;/a&gt; suggests. So taking a preventive approach, once more, might have saved some concerns (“Will we be targeted by this one”) and patch/testing time…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Just a Quick Note on the Library Loading / Binary Planting Stuff</title>
      <link>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</link>
      <pubDate>Tue, 24 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</guid>
      <description>&lt;p&gt;For those of you who missed it: Microsoft released the &lt;a href=&#34;http://www.microsoft.com/technet/security/advisory/2269637.mspx&#34;&gt;associated advisory&lt;/a&gt; yesterday, together with a &lt;a href=&#34;http://support.microsoft.com/?kbid=2264107&#34;&gt;hotfix&lt;/a&gt; introducing a new registry key that allows users to control the DLL search path algorithm. For a detailed explanation of the problem we refer to &lt;a href=&#34;http://arstechnica.com/microsoft/news/2010/08/new-windows-dll-security-flaw-everything-old-is-new-again.ars&#34;&gt;the excellent article on Ars Technica&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For the record: no, AV (anti-virus software) will – in most cases – not protect you from security problems related to this one. And, no, there is no easy patch for this one either.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
