Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.
Monthly Archives: August 2015
Firefox PDF.js Privileged Javascript Injection
This Metasploit module gains remote code execution on Firefox 35-36 by abusing a privilege escalation bug in resource:// URIs. PDF.js is used to exploit the bug. This exploit requires the user to click anywhere on the page to trigger the vulnerability.
Microsoft Security Bulletin Revision Increment For August, 2015
This bulletin summary lists one bulletin that has undergone a major revision increment for August, 2015.
Logstash 1.5.3 Man-In-The-Middle
Logstash 1.5.3 and prior versions are vulnerable to a SSL/TLS security issue which allows an attacker to successfully implement a man in the middle attack. This vulnerability is not present in the initial installation of Logstash. This insecurity is exposed when users configure Lumberjack output to connect two Logstash instances. In such deployments, a Logstash instance is used to collect logs from a webserver and securely transmit them to a central Logstash instance to perform additional filtering and storing.
Apple Security Advisory 2015-08-20-1
Apple Security Advisory 2015-08-20-1 – QuickTime 7.7.8 is now available and addresses arbitrary code execution and memory corruption issues.
WordPress Googmonify 0.8.1 Cross Site Request Forgery / Cross Site Scripting
WordPress Googmonify plugin version 0.8.1 suffers from cross site request forgery and cross site scripting vulnerabilities.
VLC 2.2.1 Arbitrary Pointer Dereference
VLC versions 2.2.1 and below suffer from an arbitrary pointer dereference vulnerability.
UBNT Script Insertion
Ubiquiti Networks Community online service web application allows for malicious script code to be inserted in the filename.
CVE-2015-2018
IBM Integration Bus 9 and 10 before 10.0.0.1 and WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.7 do not ensure that the correct security profile is selected, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVE-2015-2872
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allow remote attackers to inject arbitrary web script or HTML via (1) crafted input to index.php that is processed by certain Internet Explorer 7 configurations or (2) crafted input to the widget feature.