Monday, June 30, 2008

More Apple Bugs

I realize that it has been a while since I've written anything to our blog and I assure you its because our team has been busy. With that said, we've been sitting on a few vulnerabilities that were discovered a while ago waiting for the vendor to release patches. Those vulnerabilities are going to be released very shortly on Netragard's website and to the mailing lists, but here's a sneak peek.

1-) Funhouse vulnerability with exploit code.
2-) LP vulnerability, also with exploit code.

These should be posted within the next two weeks.

Wednesday, January 23, 2008

HackerSafe pwned

Back in early 2000, Kevin Finisterre and I were talking about HackerSafe and the risks that it posed to its customers. Primarly, if hackers monitor all HackerSafe websites they will know when to attack a site based on the presence of the HackerSafe logo. Another issue that we have with HackerSafe like services is that we feel that people are getting a false sense of security. Automated tools like the ones used by HackerSafe (scanalert) do not identify the security holes that most hackers use to break into networks, instead they only identify the known issues.

Don't get us wrong, there is value in the services that are being offered by ScanAlert. Their services help businesses keep up to date with patches and prevent businesses from missing the obvious and low hanging fruit. For that very reason services like HackerSafe have a very good ROI. Just don't feel 100% because you've got the logo, you're never 100%. Here's an article where our CTO commented on the recent HackerSafe pwnage.

Saturday, January 19, 2008

Hackers attack power companies

For quite some time I've been giving speeches and talking about the physical damages that malicious hackers could cause with a well crafted cyber attack. I've discussed how vulnerable our (the world's) core infrastructure is and how easily it could be disabled. As a result many people have called me a conspiracy theorist, or accused me of exaggerating. Well, unfortunately now I can say "I told you so." This isn't the first time that hackers have attacked this kind of technology, the US Department of Defense did it during the Aurora Generator Test.

Friday, January 11, 2008

ZDNet Australia

Netragard's CTO was quoted in the following article titled "2007: How was it for Apple". Here's the article and here's the quote:

Adriel Desautels, chief technology officer for security company Netragard and founder of the SNOSoft research team, said: "If OS X had the same installed base as Windows, Linux and other systems, it would be less secure or at the very most, as secure as the other systems ... It's just a matter of what [attackers] focus on."

Thursday, November 8, 2007

OpenBase 10.0.5 (All Platforms)

Netragard's SNOsoft Research Team discovered two critical vulnerabilities in the OpenBase SQL Relational Database that can lead to full system compromise.

The first vulnerability discovered is a command injection vulnerability that affects several of the default Stored Procedures. Specifically, it is possible to execute system commands as the root user by inserting a series of backticks into the pre-defined Stored Procedures.

The second vulnerability discovered in Buffer Overflow that causes heap corruption. This also has the potential to lead to the execution of arbitrary code or a Denial of Service condition.

Click here for the full advisory.

Netragard In The News

Apple patched two issues in Xcode Tools 2.5 on Tuesday, including one flaw that could allow remote code execution. Apple credited researcher Kevin Finisterre of Netragard for reporting both issues. Read the full article here.

Friday, September 14, 2007

Hackers Welcome - We're in forbes again.

When legitimate security researchers notify technology vendors about security flaws in their technology, the best thing that the vendor can do is to welcome the information with open arms. When a vendor reacts with hostility it appears as if the vendor is attempting quash the security research instead of resolving the vulnerabilities identified by the research. While the hostile reaction is usually an attempt to "save face" it usually does the opposite and sends a dangerous false message to the vendors customers. That message is "We care more about saving face than we do about your security." On the other hand... Vendors that work with security researchers in a positive and friendly manner send the message that they "care about the security of their customers". This Forbes article contains key examples of "Software Bug Blowups", in fact, it even covers the SNOsoft + HP + DMCA fiasco that happened back in early 2000.

Thursday, September 13, 2007

China Hacked by the US?

As the list of nations claiming they were targeted by Internet attacks emanating from China continues to grow, the world's most populous country has turned the mirror back on other governments.

In statements made in the Chinese Cadres Tribune, Vice Minister of Information Industry Lou Qinjian claimed that the United States and other "hostile" governments were attacking China's infrastructure, according to a news report carried by wire service Reuters. Lou recommended a collection of new measures to combat the attacks, including "toughened censorship, new security bodies and commercial controls," stated Reuters.

Click here for the full article.



Tuesday, September 4, 2007

Pentagon hacked by China?

For all of you who wanted "proof" about the cyberwar between China and the US, here's an article for you. Unfortunately I think that China is in a better technological position with their "Golden Shield" firewall than we are with our ad-hoc Internet infrastructure. Specifically if you consider that "Golden Shield" is rumored to be IPS capable.