Showing posts with label Execute Arbitrary Code. Show all posts
Showing posts with label Execute Arbitrary Code. Show all posts

Tuesday, 10 November 2015

Vulnerability In Popular SSH Client PuTTY Poem


There is a new version of the popular SSH client PuTTY appeared in which a vulnerability is closed through which attackers could execute at worst arbitrary code with the rights of the logged on user systems.

For this, a user had to connect to the server of the attacker. The cause of the problem in the terminal emulator was an escape sequence whereby the terminal code of PuTTY read the wrong memory and possibly could describe well, which could lead to an integer overflow. PuTTY and pterm version 0:54 to 0.65 are vulnerable. Users therefore be advised to version 0.66 to upgrade.

Tuesday, 10 February 2015

HackerOne Bug Fixes Serious Platform For Bug Reports


HackerOne, the platform for reporting vulnerabilities in various software projects and applications, has itself had to deal with a serious vulnerability that attackers may have access to unpublished bug reports from other investigators could get.

Cross Site Scripting (XSS) issue exists was caused by the way HackerOne the "\" character tried left harmless. Therefore could allow an attacker to execute code on a webpage, which could help again in a phishing attack, says researcher Daniel LeCheminant who discovered the problem.

He suspects that an attacker could also add arbitrary HTML to bug reports in order to gain unauthorized access to the bug reports and data from other researchers. It is the first time that an XSS problem was discovered in HackerOne. A day after LeCheminant administrators had informed the vulnerability was corrected and he got a reward of $ 5,000. An amount that is only for serious bugs reserved .