[Full-disclosure] Bypassing Export address table Address Filter (EAF)

2010-11-22 Thread Berend-Jan Wever
Hey list, If you're interested in a short analysis of Microsoft's new EAF pseudo-mitigation and how to bypass it, have a look here: http://skypher.com/index.php/2010/11/17/bypassing-eaf/ Cheers, SkyLined Berend-Jan Wever Delft, The Netherlands http://skypher.co

[Full-disclosure] Oracle Java OBJECT children property memory corruption

2010-10-13 Thread Berend-Jan Wever
Goedemiddag, Oracle has released a patch for a vulnerability in Java 6 that I reported to them. If you like to know more, you can read about it here: http://skypher.com/index.php/2010/10/13/issue-18-oracle-java-applet-childre/ Cheers, SkyLined Berend-Jan Wever Delft, The Netherlands http

[Full-disclosure] Microsoft Windows Media Player memory corruption

2010-10-13 Thread Berend-Jan Wever
com/index.php/2010/10/12/issue-21-wmp-memory-corruption-using-popups/> Berend-Jan Wever Delft, The Netherlands http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Host

Re: [Full-disclosure] Gödel and kernel backdoors

2010-09-19 Thread Berend-Jan Wever
nevermind the fact that a "good" program in your list may contain as yet unknown vulnerabilities which mean it's actually bad. On Sep 19, 2010 7:08 PM, "Georgi Guninski" wrote: > On Sun, Sep 19, 2010 at 06:21:35PM +0200, Pavel Kankovsky wrote: >> On the other hand, It is possible to "detect all ba

[Full-disclosure] Issue 17 - Msxml2.XMLHTTP.3.0 response handling memory corruption (ms10-051, CVE-2010-2561)

2010-08-10 Thread Berend-Jan Wever
: http://code.google.com/p/skylined/issues/detail?id=17 Cheers, SkyLined <http://skypher.com/> Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsore

Re: [Full-disclosure] Wordpad Command line argument vulnerability is it known ?

2010-03-18 Thread Berend-Jan Wever
exploit it, why don't you encode your shellcode to lowercase alphanumeric using ALPHA3? http://code.google.com/p/alpha3/ Berend-Jan Wever http://skypher.com/SkyLined On Wed, Mar 17, 2010 at 3:20 PM, sachin shinde wrote: > hi, > > > There is classic buffer/Stack overflow in wo

[Full-disclosure] To Ryan Naraine

2010-03-03 Thread Berend-Jan Wever
ndings, so if you read this, send me an email and I'll get you up to speed. Cheers and thanks, SkyLined Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.

Re: [Full-disclosure] Internet Exploiter 2 - bypassing DEP

2010-03-01 Thread Berend-Jan Wever
t being a native English speaker, I may inadvertently have said things completely wrong again. I look forward to correcting my mistakes as they show up on other news sites in the future. Cheers, SkyLined Berend-Jan Wever http://skypher.com/SkyLined On Mon, Mar 1, 2010 at 4:51 PM, Berend-Jan Wever

[Full-disclosure] Internet Exploiter 2 - bypassing DEP

2010-03-01 Thread Berend-Jan Wever
-exploiter-2-dep/ Cheers, SkyLined <http://skypher.com/index.php/2010/03/01/internet-exploiter-2-dep/> Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

[Full-disclosure] Google offers up to $1337 for select Chromium vulnerabilities

2010-01-29 Thread Berend-Jan Wever
High and Critical impact bugs*<http://dev.chromium.org/developers/severity-guidelines> *, but any clever vulnerability at any severity might get a reward. Obviously, your bug won't be eligible if you worked on the code or review in the area in question."* Cheers, SkyL

Re: [Full-disclosure] ZDI-10-011: Microsoft Internet Explorer Table Layout Col Tag Cache Update Remote Code Execution Vulnerability

2010-01-25 Thread Berend-Jan Wever
How about rebranding to ZID, as in Zero Information Disclosures? Berend-Jan Wever http://skypher.com/SkyLined On Thu, Jan 21, 2010 at 9:07 PM, ZDI Disclosures < zdi-disclosu...@tippingpoint.com> wrote: > ZDI-10-011: Microsoft Internet Explorer Table Layout Col Tag Cache Update >

[Full-disclosure] Two MSIE 6.0/7.0 NULL pointer crashes

2010-01-20 Thread Berend-Jan Wever
hes/> Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Download and LoadLibrary shellcode released

2010-01-11 Thread Berend-Jan Wever
For those interested in shellcode: download and LoadLibrary shellcode has some benefits over download & execute shellcode. Read more about it here: http://skypher.com/index.php/2010/01/11/download-and-loadlibrary-shellcode-released/ Cheers, SkyLined Berend-Jan Wever http://skypher.com/SkyL

[Full-disclosure] Testival released

2010-01-11 Thread Berend-Jan Wever
<http://code.google.com/p/alpha3/> for automatically testing if all the en-/decoders work. Testival requires SkyBuild <http://code.google.com/p/skybuild/> to automatically build all files. Cheers, SkyLined Berend-Jan Wever http://skypher.com/SkyLined __

[Full-disclosure] ALPHA3 released

2010-01-10 Thread Berend-Jan Wever
ode.com/files/ALPHA3.zip Cheers, SkyLined <http://skypher.com/index.php/2010/01/10/alpha3-released/> Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Countslide alphanumeric GetPC

2010-01-02 Thread Berend-Jan Wever
code into releasable shape. Cheers, SkyLined <http://skypher.com/index.php/2010/01/02/countslide-alphanumeric-getpc/> Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-d

[Full-disclosure] BETA3 released

2010-01-02 Thread Berend-Jan Wever
tp://www.milw0rm.com/exploits/656> . http://skypher.com/index.php/2010/01/02/beta3-released/ Cheers, SkyLined Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-

[Full-disclosure] MSIE Content-Encoding: deflate memory corruption vulnerability

2009-10-13 Thread Berend-Jan Wever
Microsoft bulletin: http://www.microsoft.com/technet/security/bulletin/MS09-054.mspx Short description and repro information: http://skypher.com/index.php/2009/10/13/ms09-054cve-2009-1547-data-stream-header-corruption-vulnerability/ Cheers, SkyLined Berend-Jan Wever http://skypher.com/SkyLined

[Full-disclosure] Memory corruption when loading/unloading Adobe objects through EMBED tag in Firefox

2009-10-13 Thread Berend-Jan Wever
/13/memory-corruption-when-loadingunloading-adobe-objects-through-embed-tag-in-firefox/> Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponso

Re: [Full-disclosure] Exploiting memory corruption vulnerabilities on Internet Explorer 8

2009-10-01 Thread Berend-Jan Wever
FYI: ASLR & DEP can be bypassed on x86, there's just nothing public at the moment. Cheers, SkyLined Berend-Jan Wever http://skypher.com/SkyLined On Thu, Oct 1, 2009 at 6:44 PM, Freddie Vicious wrote: > Yes, I am aware of the JVM and the Flash AVM heap spray techniques, no >

[Full-disclosure] Alphanumeric ASCII SEH GetPC for XP up to sp3

2009-06-12 Thread Berend-Jan Wever
): V34djPXP4Hd30V3v034dYV34014dZX4vP4v4PHPfh11DX5PRRRV34dNj334d3D241D24XXfX3D28f1D28jAXLX3Dqh3Tpl1Tpl96 Quick intro to GetPC code: http://skypher.com/wiki/index.php/Hacking/Shellcode/GetPC Thanks, SkyLined Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter

[Full-disclosure] MS09-014: MSIE EMBED element race condition memory corruption

2009-04-19 Thread Berend-Jan Wever
Some details + repro: http://skypher.com/index.php/2009/04/19/ms09-014-embed-element-memory-corruption/ Cheers, SkyLined Berend-Jan Wever http://skypher.com/SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

Re: [Full-disclosure] Firefox 3.0.8 remote DoS: 0-day exploit

2009-04-04 Thread Berend-Jan Wever
lightly modified) to milw0rm as his code as well (http://milw0rm.com/exploits/8219). Some say plagiarism is the sincerest form of flattery, so I guess I'll start obfuscating my repros into ASCII art that says "SkyLined" to prevent any more people from flattering me. Cheers, Sky B

[Full-disclosure] w32 SEH omelet shellcode stage

2009-03-16 Thread Berend-Jan Wever
title=Shellcode/w32_SEH_omelet_shellcode http://code.google.com/p/w32-seh-omelet-shellcode/ I have not had a chance to test this newer version in a live exploit, so do let me know if you have a chance to use it. Cheers, SkyLined B

Re: [Full-disclosure] Firefox 3.0.5 remote vulnerability via queryCommandState

2009-01-07 Thread Berend-Jan Wever
Berend-Jan Wever http://skypher.com On Wed, Jan 7, 2009 at 6:04 PM, Berend-Jan Wever wrote: > This bug was reported by me to Mozilla in September. It is DoS > only.<https://bugzilla.mozilla.org/show_bug.cgi?id=456727> > https://bugzilla.mozilla.org/show_bu

Re: [Full-disclosure] Firefox 3.0.5 remote vulnerability via queryCommandState

2009-01-07 Thread Berend-Jan Wever
..@xul!jvm_maybeshutdownliveconnect+0xdbe0/repro.html How about giving some credit where it's due? Cheers, SkyLined -------- Berend-Jan Wever http://skypher.com On Wed, Jan 7, 2009 at 4:

[Full-disclosure] MSIE screen[""] NULL ptr Read AV DoS details

2009-01-07 Thread Berend-Jan Wever
than offer it to me to write you an exploit? Then again, I do find your emails amusing... Cheers, SkyLined Berend-Jan Wever http://skyphe

[Full-disclosure] CVE-2008-2303 proof of concept and more

2009-01-05 Thread Berend-Jan Wever
Cheers, SkyLined ------------ Berend-Jan Wever http://skypher.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] List of security teams contact information

2008-12-17 Thread Berend-Jan Wever
et me know. Cheers, SkyLined Berend-Jan Wever http://skypher.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-discl

[Full-disclosure] StumbleUpon XSS (fixed)

2008-08-12 Thread Berend-Jan Wever
e and their fix being online. In my experience that is really, really fast! Cheers, SkyLined Berend-Jan Wever <[EMAIL PROTECTED]> http://

[Full-disclosure] ASCII Art shellcode

2008-08-04 Thread Berend-Jan Wever
heers, SkyLined -------- Berend-Jan Wever <[EMAIL PROTECTED]> http://skypher.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html H

[Full-disclosure] Alphanumeric shellcode improvements

2008-07-01 Thread Berend-Jan Wever
Hi all, I've not had as much opportunity in the last three years to contribute, but I do have some new stuff: I've decided to pre-release some parts of ALPHA3, the upcoming new version of my alphanumeric shellcode encoder: * I've reduced the size of the mixedcase ascii decoder: http://skypher.com/

[Full-disclosure] First cross-domain XSS worm (not)

2007-07-16 Thread Berend-Jan Wever
Hi all, I recently stumbled upon this; http://ha.ckers.org/blog/20070709/nduja-cross-domainwebmail-xss-worm/ In short: It mentions a "new" kind of XSS worm; one that can infect multiple domains. I attempted to reply but my reply mysteriously never made it to the page. In an attempt to set the rec

[Full-disclosure] SMC Networks Inc security contact anyone?

2006-07-29 Thread Berend-Jan Wever
Hi all,   I'm looking for a way to contact SMC (www.smc.com) security people about a few vulnerabilities in their routers. Both [EMAIL PROTECTED] and [EMAIL PROTECTED] failed.   Cheers, SkyLined-- Berend-Jan Wever <[EMAIL PROTECTED]>http://spaces.msn.com/members/ber

[Full-disclosure] FireFox exploit updated

2005-09-22 Thread Berend-Jan Wever
http://www.milw0rm.com Somewhere I totally forgot to credit Tom Ferris for finding the vulnerability. I hate it when people forget credits and now I am one of them :(. Please update your copy if you have mirrored it on your site. Cheers, SkyLined -- Berend-Jan Wever <[EMAIL PROTECTED]>

[Full-disclosure] Internet Exploiter meets FireFox

2005-09-22 Thread Berend-Jan Wever
for this reason:   <[EMAIL PROTECTED]>:  ezmlm-reject: fatal: Sorry, I don't accept messages of MIME Content-Type 'multipart/alternative' (#5.2.3) I'm wondering if it's just me or everybody that uses gmail?-- Berend-Jan Wever <[EMAIL PROTECTED]>

Re: [Full-disclosure] Google Secure Access or "How to have peopledownload a trojan."

2005-09-22 Thread Berend-Jan Wever
is both a trojan and spyware.   Cheers,SkyLined-- Berend-Jan Wever <[EMAIL PROTECTED] >http://www.edup.tudelft.nl/~bjwever ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Google Secure Access or "How to have people download a trojan."

2005-09-21 Thread Berend-Jan Wever
licy with a shorter, less confusing version: Here's some candy, go play! Btw. All your base are belong to us.   Cheers, SkyLined   -- Berend-Jan Wever <[EMAIL PROTECTED]>http://www.edup.tudelft.nl/~bjwever ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Shazara security contact?

2005-09-18 Thread Berend-Jan Wever
Sorry for the noize, no usefull info in here.   Anybody knows a security contact for Shazara? They have forums and such, but you need to register, which I hate. I want to contact them through email anyway.   Cheers, SkyLined -- Berend-Jan Wever <[EMAIL PROTECTED]>http://www.edup.tude

[Full-disclosure] FireFox "Host:" Buffer Overflow is not just exploitable on FireFox

2005-09-11 Thread Berend-Jan Wever
ution Prevention), - Turn off _javascript_, - Switch to another browser, - Do not browse untrusted sites, - Do not browse the web at all, - Unplug your machine from the web, - Wear a tinfoil hat.   Cheers, SkyLined  On 9/10/05, Berend-Jan Wever <[EMAIL PROTECTED]> wrote: (Just a little heads up, no

[Full-disclosure] Mozilla Firefox "Host:" Buffer Overflow Exploit

2005-09-10 Thread Berend-Jan Wever
licly untill patches are out.   On a side note: it took only about 3 hours and 30 minutes to develop the exploit, so I might not be the only one able to write it.   Cheers, SkyLined-- Berend-Jan Wever <[EMAIL PROTECTED]>http://www.edup.tudelft.

[Full-disclosure] COM objects and MSIE vulnerabilities recap + additional fix

2005-08-18 Thread Berend-Jan Wever
Disclaimer:    The information in this email is distributed WITHOUT ANY WARRANTY, TO THE    EXTENT PERMITTED BY APPLICABLE LAW; without even the implied warranty of    CORRECTNESS or FITNESS FOR A PARTICULAR PURPOSE. You know the drill... Affected products:    Various COM objects when loaded in Mi

[Full-disclosure] Re: Mozilla Firefox InstallVersion->compareTo() vulnerability lowered severity status

2005-08-04 Thread Berend-Jan Wever
risk even more. Therefore, my suggestion to the Mozilla Foundation is to raise the severity status of the vulnerability to 'High' or 'Critical'. Best regards,Aviv Raff. -- Berend-Jan Wever <[EMAIL PROTECTED]>http://www.edup.tudelft.nl/~bjwever ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Re: alpha numeric exploitation

2005-05-30 Thread Berend-Jan Wever
ASCII-fy" it. See ALPHA2.   > Would dissembler do what you want? It should be able to squeeze the > ascii shellcode for you ;-) Nice tool ;) But printable characters are not all alphanumeric characters.   Cheers, SkyLined-- Berend-Jan Wever <[EMAIL PROTECTED]>http://www.edup.tudelf

Re: [Full-disclosure] #HACKPHREAK ADVISORY | BBQ CHICKEN WTF!

2005-04-13 Thread Berend-Jan Wever
I propose we up the age limit to post on full-disclosure to 14. Cheers, SkyLined ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Details and PoC for MS05-020 MSIE DHTML Object handling vulnerabilities

2005-04-12 Thread Berend-Jan Wever
. Cheers, SkyLined PS. I was pretty surprised nobody asked me why I went from Internet Exploiter 1 to Internet Exploiter 3 so now you know. .---, / Berend-Jan Wever aka SkyLined