Archive

Posts Tagged ‘0day’

0day on TM Billion ADSL Modem/Router

February 6th, 2010

Quick update

Here is my short update. I was playing around with the ‘nice’ modem and I found 2 vulnerability

1) Remote code execution
2) DoS

Tested on Firmware Version : 2.10.5.0(UE0.C2C)3.7.6.1

I’m looking forward to play around with Riger Corporation’s modem that came with “Enhanced by TM R&D Malaysia” label on it :)

xanda IT Related , , , , , , , , ,

CVE-2010-0249 – Aurora IE 0day Exploit :: DEP bypassed

January 19th, 2010

:: Quick update ::

Today, I’ve been working on a video on the Aurora IE 0day exploit PoC that really mimics the original Aurora’s exploit on Google.

However, the original exploit gonna fail if you enable DEP on the machine.

A few minutes back, someone ping and inform me on the new PoC that gonna bypass the DEP. If true, enabling DEP wont protect IE users anymore ;)

But you are still safe if you disable Active Script / JavaScript support for your IE

Here is how you can disable the Active Shit/JavaShit Active Script / JavaScript support in your IE: Advisory

xanda IT Related , , , , , , , , , ,

Vulnerability in IIS

December 28th, 2009

I’ve received the ‘feed’ regarding the IIS vulnerability on the 23rd December, but due to busy (preparing for examination) week, the advisory for the vulnerability is still pending.

From my observation, IIS 7 and IIS 7.5 are not vulnerable to the bug.. I already have a few working workaround for the 0day and all of them will be compiled in my upcoming advisory.. soon.. :P

cheers!

** [Updated on Tue Dec 29 01:26:39 MYT 2009]

Done! Sent to webmaster. Waiting to be published

** [Updated on Tue Dec 29 21:33:20 MYT 2009]

Published :)

xanda IT Related , , ,

Yet Another Adobe Bug

October 9th, 2009

Nothing much but YES to agree with Didier Stevens with his statement:

PDF + JS = OMG

Yerp.. there is another vulnerability (CVE-2009-3459) in Adobe Reader and Acrobat today (GMT +8) and so far it is still 0 day..

*panic panic* What to do?

  1. Disable JavaScript support in Adobe Reader and Acrobat
  2. Enable DEP (for Windows)
  3. Use NoScript
  4. Use alternative PDF reader like Foxit, Gnome Document Viewer, yada yada..
  5. Don’t be a lame by opening unknown PDF attachment

xanda IT Related , , , , , ,

Critical Memory Corruption Vulnerability Fixed in Mozilla Firefox 3.5.1

July 17th, 2009

The critical memory corruption vulnerability has finally fixed in Mozilla Firefox 3.5.1. Beside security issues, several stability issues and issue that was making Firefox take a long time to load on some Windows systems were also fixed in this release. The complete changelog is HERE

Download / Update now

xanda IT Related , , , ,