Node Browserify RCE vuln (= 4.2.0)

2014-07-15 Thread Cal Leeming [Simplicity Media Ltd]
Hello, Discovered an RCE vuln in Browserify =4.2.0. Maintainer patched upstream just 4 hours after responsible disclosure yesterday, now fixed as of 4.2.1. Summary and POC found here: http://iops.io/blog/browserify-rce-vulnerability/ Cal

Re: RPS/APS vulnerability in snom/yealink and others

2013-10-24 Thread Cal Leeming [Simplicity Media Ltd]
this fixed Cal On Wed, Oct 23, 2013 at 11:10 PM, Cal Leeming [Simplicity Media Ltd] cal.leem...@simplicitymedialtd.co.uk wrote: Hello, Discovered a vulnerability that allows for hundreds of thousands of SIP accounts to be compromised remotely. Found a year ago, partial vendor fixes but still

RPS/APS vulnerability in snom/yealink and others

2013-10-23 Thread Cal Leeming [Simplicity Media Ltd]
Hello, Discovered a vulnerability that allows for hundreds of thousands of SIP accounts to be compromised remotely. Found a year ago, partial vendor fixes but still vuln as of today, disclosed a few hours ago exclusively to the FreeSWITCH community - 23rd Oct 2013. Live disclosure can be seen

Re: [Full-disclosure] Linux kernel exploit

2010-12-08 Thread Cal Leeming [Simplicity Media Ltd]
Anyone tested this in sandbox yet? On 07/12/2010 20:25, Dan Rosenberg wrote: Hi all, I've included here a proof-of-concept local privilege escalation exploit for Linux. Please read the header for an explanation of what's going on. Without further ado, I present full-nelson.c: Happy hacking,