RCE Using Caller ID - Multiple Vulnerabilities in FusionPBX
Aon’s Cyber Solutions has recently discovered several vulnerabilities in FusionPBX, an open-source VoIP PBX application that runs on top of the FreeSWITCH VoIP switch. These vulnerabilities allow for...
View ArticleSSRF and XXE Vulnerabilities in PDFreactor
Aon’s Cyber Solutions recently discovered two vulnerabilities in RealObjects PDFreactior prior to version 10.1.10722 in the default configuration. The identified vulnerabilities allow attackers to...
View ArticleUnauthenticated Remote Code Execution in Kentico CMS
Aon’s Cyber Solutions Security Testing team recently discovered a vulnerability, CVE-2019-10068, in the Kentico CMS platform versions 12.0.14 and earlier. This issue allows for unauthenticated remote...
View ArticleRemote Code Execution in BlogEngine.NET
Aon’s Cyber Solutions Security Testing team recently discovered a vulnerability, CVE-2019-6714, in the BlogEngine.NET blogging software platform affecting versions 3.3.6.0 and earlier. This issue...
View ArticleWowza Streaming Engine Manager Directory Traversal and Local File Inclusion
HTTP/1.1 200 OK Server: Winstone Servlet Engine v1.0.5 Content-Type: application/octet-stream Content-Disposition: attachement; filename=”shadow.zip” Connection: Close Date: Thu, 17 May 2018 18:11:09...
View ArticleCUPS Local Privilege Escalation and Sandbox Escapes
Gotham Digital Science has discovered multiple vulnerabilities in Apple’s CUPS print system affecting macOS 10.13.4 and earlier and multiple Linux distributions. All information in this post has been...
View ArticleBreaking Randomness in the Ethereum Universe [part 1]
It is widely acknowledged that generating secure random numbers on the Ethereum blockchain is difficult due to its deterministic nature. Each time a smart contract’s function is called inside of a...
View ArticleJolokia Vulnerabilities - RCE & XSS
Recently, during a client engagement, Gotham Digital Science found a couple of zero-day vulnerabilities in the Jolokia service. Jolokia is an open source product that provides an HTTP API interface for...
View ArticleSkybox Vulnerabilities
Overview Gotham Digital Science (GDS) recently discovered multiple vulnerabilities that affect the Skybox Manager Client Application and the Skybox Server. These consist of user privilege elevation,...
View ArticleRemote Code Execution in BlackBerry Workspaces Server
Overview Gotham Digital Science (GDS) has discovered a vulnerability affecting BlackBerry Workspaces Server (formerly WatchDox). Prior to being patched, it was possible to remotely execute arbitrary...
View ArticlePentesting Fast Infoset based web applications with Burp
If you run into a .NET application you sometimes end up with some not very well known protocols like WCF Binary protocol or, in a recent case, a Fast Infoset binary encoding - a binary encoding of the...
View ArticleReviewing Ethereum Smart Contracts
Ethereum has been in the news recently due to a string of security incidents affecting smart contracts running on the platform. As a security engineer, these stories piqued my interest and I began my...
View ArticleLinux based inter-process code injection without ptrace(2)
Using the default permission settings found in most major Linux distributions it is possible for a user to gain code injection in a process, without using ptrace. Since no syscalls are required using...
View ArticleWhitepaper: The Black Art of Wireless Post-Exploitation - Bypassing...
At DEF CON 25 we introduced a novel attack that can be used to bypass port-based access controls in WPA2-EAP networks. We call this technique an Indirect Wireless Pivot. The attack, which affects...
View ArticleCVE-2017-4971: Remote Code Execution Vulnerability in the Spring Web Flow...
Earlier this year, we approached Pivotal with a vulnerability disclosure relating to the Spring Web Flow framework caused by an unvalidated data binding SpEL expression that makes applications built...
View ArticleICS/SCADA Systems for Penetration Testers: A Typical Engagement
It’s no secret that the devices that comprise process control systems are generally vulnerable to attack. This point has been made through endless research and has even been the subject of countless...
View ArticleIntroduction to Attacking ICS/SCADA Systems for Penetration Testers
Since coming into use in the late 1960s, Industrial Control Systems (ICSs) have become prevalent throughout all areas of industry and modern life. Whether in utilities, energy, manufacturing or a...
View ArticleVMware vCenter Unauthenticated RCE using CVE-2017-5638 (Apache Struts 2 RCE)
<servlet-mapping> <servlet-name>StatsChartServlet</servlet-name> <url-pattern>/StatsChartServlet</url-pattern> </servlet-mapping>
View ArticleAn Analysis of CVE-2017-5638
At GDS, we’ve had a busy few weeks helping our clients manage the risk associated with CVE-2017-5638 (S2-045), a recently published Apache Struts server-side template injection vulnerability. As we...
View ArticleCryptographic Flaws in Skype for Business
GDS recently discovered and disclosed a vulnerability in Skype for Business caused by mishandling of cryptographic information. Improper use of string objects resulted in reduced entropy for database...
View Article