Hackers to Hackers Conference III - Call for Papers

2006-08-30 Thread Rodrigo Rubira Branco (BSDaemon)
really simple. The attender must sent the form bellow by mail (attached using OpenDocument format or in the mail body). - Submission of articles The articles can be written in portuguese or english. . The proposal must be sent to Rodrigo Rubira Branco (BSDaemon) - rodrigo at kernelhacking.com

Hackers to Hackers Conference III - Call for Papers

2006-09-15 Thread Rodrigo Rubira Branco (BSDaemon)
really simple. The attender must send the form bellow by email (attached using OpenDocument format or in the email body). - Submission of articles The articles can be in portuguese or english. . The proposal must be sent to Rodrigo Rubira Branco (BSDaemon) - rodrigo at kernelhacking.com com o

NetBSD all versions FireWire IOCTL kernel integer overflow information disclousure

2006-11-15 Thread Rodrigo Rubira Branco (BSDaemon)
Filipe Balestra <[EMAIL PROTECTED]> and Rodrigo Rubira Branco (BSDaemon) <[EMAIL PROTECTED]> for the discovering, analysis and patch. Contact Information === You can reach the authors of this advisory by mail or visiting some websites: http:

DragonFlyBSD all versions FireWire IOCTL kernel integer overflow information disclousure

2006-11-15 Thread Rodrigo Rubira Branco (BSDaemon)
Filipe Balestra <[EMAIL PROTECTED]> and Rodrigo Rubira Branco (BSDaemon) <[EMAIL PROTECTED]> for the discovering, analysis and patch. Contact Information === You can reach the authors of this advisory by mail or visiting some websites:

TrustedBSD* all versions FireWire IOCTL kernel integer overflow information disclousure

2006-11-15 Thread Rodrigo Rubira Branco (BSDaemon)
Filipe Balestra <[EMAIL PROTECTED]> and Rodrigo Rubira Branco (BSDaemon) <[EMAIL PROTECTED]> for the discovering, analysis and patch. Contact Information === You can reach the authors of this advisory by mail or visiting some websites:

FreeBSD all versions FireWire IOCTL kernel integer overflow information disclousure

2006-11-15 Thread Rodrigo Rubira Branco (BSDaemon)
Filipe Balestra <[EMAIL PROTECTED]> and Rodrigo Rubira Branco (BSDaemon) <[EMAIL PROTECTED]> for the discovering, analysis and patch. Contact Information === You can reach the authors of this advisory by mail or visiting some websites: http:

CALL FOR PAPERS - Hackers 2 Hackers Conference 11th edition

2013-12-30 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CALL FOR PAPERS - Hackers 2 Hackers Conference 11th edition The call for papers for H2HC 11th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 18 to 19 of October 2014. Our public key is available at: https://w

H2HC 12th Edition - Call for Papers

2015-03-09 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CALL FOR PAPERS - Hackers 2 Hackers Conference 12th edition The call for papers for H2HC 12th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 22 to 27 October 2015. [ - Introduction - ] For the twelveth cons

Re: Fwd: 0-DAY XSS of cforms II is now fixed after a year and four months (was Re: cforms WordPress Plugin Cross Site Scripting Vulnerability - CVE-2010-3977)

2012-02-17 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Dear Kousuke, First of all, let me clarify that the disclosure process has been entirely coordinated by me, and thus, Wagner, Conviso and Check Point have no responsibilities over any mistake I eventually made. Anyway, just to clarify your points: >

Adobe Shockwave Player Remote Code Execution (CVE-2012-2029)

2012-05-10 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Qualys Vulnerability & Malware Research Labs (VMRL) http://www.dissect.pe Memory corruption when Adobe Shockwave Player parses .dir media file CVE-2012-2029 INTRODUCTION Adobe Shockwave Player is the Adobe plugin to many different browsers to view

Adobe Shockwave Player Remote Code Execution (CVE-2012-2030)

2012-05-10 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Qualys Vulnerability & Malware Research Labs (VMRL) http://www.dissect.pe Memory corruption when Adobe Shockwave Player parses .dir media file CVE-2012-2030 INTRODUCTION Adobe Shockwave Player is the Adobe plugin to many different browsers to view

Adobe Shockwave Player Remote Code Execution (CVE-2012-2031)

2012-05-10 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Qualys Vulnerability & Malware Research Labs (VMRL) http://www.dissect.pe Memory corruption when Adobe Shockwave Player parses .dir media file CVE-2012-2031 INTRODUCTION Adobe Shockwave Player is the Adobe plugin to many different browsers to view

Apple Quicktime Memory Corruption (CVE-2012-0671)

2012-05-16 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Qualys Vulnerability & Malware Research Labs (VMRL) http://www.qualys.com http://www.dissect.pe Memory corruption when Apple Quicktime parsers .pct file CVE-2012-0671 INTRODUCTION Apple Quicktime does not properly parse .pct media files, which caus

H2HC Brazil 9th Edition - Call for Papers

2012-05-18 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CALL FOR PAPERS - Hackers 2 Hackers Conference 9th edition The call for papers for H2HC 9th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 18 to 23 October 2012. [ - Introduction - ] For the ninth consecuti

H2HC Brazil (Hackers 2 Hackers Conference) 8th Edition - Call for Papers

2011-07-20 Thread Rodrigo Rubira Branco (BSDaemon)
CALL FOR PAPERS - Hackers 2 Hackers Conference 8th edition The call for papers for H2HC 8th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 29 to 30 October 2011. [ - Introduction - ] For the eighth consecutive year and past success we have been having,

Call For Papers - Hackers 2 Hackers Conference 7th Edition - Brazil

2010-07-26 Thread Rodrigo Rubira Branco (BSDaemon)
CALL FOR PAPERS - Hackers 2 Hackers Conference 7th edition The call for papers for H2HC 7th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 27 to 28 November 2010. [ - Introduction - ] For the seventh consecutive year and past success we have been havi

Call for Papers H2HC Cancun/Mexico and H2HC Sao Paulo/Brazil

2010-09-07 Thread Rodrigo Rubira Branco (BSDaemon)
CALL FOR PAPERS - Hackers 2 Hackers Conference 7th edition The call for papers for H2HC 7th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 27 to 28 November 2010 and this year for the first time also in Cancun, on 3 of December 2010. [ - Introduction -

H2HC São Paulo - Capture the Captcha

2010-09-07 Thread Rodrigo Rubira Branco (BSDaemon)
We would like to thank to our sponsors for making this game possible: Bonsai for hosting the game and Tenable for providing the prize! A Captcha is a type of challenge-response test used in computing to ensure that the response is not generated by a computer. It is a contrived acronym for "Compl

H2HC 2010 Sao Paulo - Capture the Flag

2010-09-13 Thread Rodrigo Rubira Branco (BSDaemon)
The game this year is entitled Capture the Captcha! A Captcha is a type of challenge-response test used in computing to ensure that the response is not generated by a computer. It is a contrived acronym for "Completely Automated Public Turing test to tell Computers and Humans Apart." The process

H2HC 2009 Videos Available!

2010-10-15 Thread Rodrigo Rubira Branco (BSDaemon)
Dear All, It is a pleasure to announce that the H2HC 2009 videos are finally available online! We had a very exciting conference with some 0day vulnerabilities affecting Microsoft Platforms released by Cesar Cerrudo. Those vulnerabilities have been later explained in Blackhat this year, which sh

H2HC Cancun - Registrations are open

2010-10-19 Thread Rodrigo Rubira Branco (BSDaemon)
Dear Lists, I'm happy (and proud) to announce that the registrations for H2HC Cancun are finally available online. This is the first year of the conference in Cancun/Mexico (on 3rd of december) and the 7th year of the Conference in São Paulo/Brazil (on 27-28 of november). We are growing fast an

H2HC 2010 - Final Speakers List Available

2010-11-01 Thread Rodrigo Rubira Branco (BSDaemon)
Dear All, The final list of speakers is available for H2HC 2010: http://www.h2hc.com.br/en/. It is my pleasure to announce that the final list of speakers is available for H2HC in São Paulo. The list for Cancun will be available soon (http://www.h2hc.com.br/cancun/)! It was a real challenge to

Malware Collections and Feed Exchange

2010-11-08 Thread Rodrigo Rubira Branco (BSDaemon)
Dear All, I'm really proud to announce that the first stage of the Dissect.pe project is in beta now! The idea of the project is to provide a free interface for malware analysis, similar to other existing projects, but with advances that will be announced when we start freely dissecting samples.

H2CSO (Hackers to CSO) debate second edition - Free Live Streaming

2010-11-19 Thread Rodrigo Rubira Branco (BSDaemon)
Dear All, I'm happy to announce that the H2CSO (Hackers to CSO) debate will happen again! We will broadcast the debate freely on the internet, in English. To subscribe just go to the link: http://www.decisionreport.com.br/securityleaders/Inscricao_ingles.html The Decision Report is organizi

H2HC Cancun - Free Entrance!

2010-11-22 Thread Rodrigo Rubira Branco (BSDaemon)
Dear All, I'm proud to announce that the H2HC Cancun entrance is now free - Thanks to our sponsors that helped us to make this happen: Microsoft, Nitro Security, Trustwave and others! As many of you already know, H2HC (Hackers to Hackers Conference) is been held for the 7th year in São Paulo, but

CVE-2010-4435 - Multiple Vendor Calendar Manager Remote Code Execution

2011-02-09 Thread Rodrigo Rubira Branco (BSDaemon)
Dear List, So finally all the vendors fixed this critical issue (remote code execution). As usual, here it goes the PoC to help in the exploitation. It works against all the affected vendors, so just adjust your payload and have fun! http://www.kernelhacking.com/rodrigo/exploits/cmsd_cve2010-44

Remote Vulnerability in AIX RPC.cmsd released by iDefense

2010-02-02 Thread Rodrigo Rubira Branco (BSDaemon)
http://www.kernelhacking.com/rodrigo/exploits/cmsd_exploit.c Regards, Rodrigo (BSDaemon). -- Rodrigo Rubira Branco (BSDaemon) "Kernel Hacking: If you really know, you can hack!"