TL;DR: In the scope of academic research on printer security, various
vulnerabilities in network printers and MFPs have been discovered. This
is advisory 5 of 6 of the `Hacking Printers’ series. Each advisory
discusses multiple issues of the same category. This post is about
resetting a printer to factory defaults through ordinary print jobs,
therefore bypassing all protection mechanisms like user-set passwords.
The attack can be performed…
Affected Products
Tested with
OPSI Server 4.0.7.26
OPSI ClientAgent 4.0.7.10-1
(older releases have not been tested)
According to the vendor all server instances that use a python-opsi version lower
than 4.0.7.28-4 are affected
We’ve released the new BlackArch Linux ISOs along with many
improvements. They include more than 1620 tools now. The armv6h,
armv7h and aarch64 repositories are filled with about 1550 tools.
A short ChangeLog of the Live-ISOs:
– add 20 new tools
– update blackarch installer to 0.3.2 (bugfixes)
– fix shadow permissions (thx to ldionmarcil)
– fix f*cking ruby tools (wpscan, metasploit, etc.)
– include linux kernel…
Privilege Escalation in VirtualBox (CVE-2017-3316)
== [ Overview ] ===
System affected: VirtualBox
Software-Version: prior to 5.0.32, prior to 5.1.14
User-Interaction: Required
Impact: A Man-In-The-Middle could infiltrate an
Extension-Pack-Update to gain a root-shell
=== [ Detailed description ] ===
In my research about update mechanism of open-source software I found
vulnerabilities in Oracle’s VirtualBox. It’s…
PasswordAuthentication is reset to yes in /etc/ssh/sshd_config when using ssh key authentication given the following
scenario:
When creating a new droplet from a snapshot where ssh key authentication “PasswordAuthentication” in
/etc/ssh/sshd_config was previosly set to no, “PasswordAuthentication” is reset to yes.
I am not sure how common this scenario is but for me I often…
——————————————
CALL FOR PAPERS DigitalSec2017 – Malaysia
——————————————
You are invited to participate in The Fourth International Conference on
Digital Security and Forensics (DigitalSec2017) that will be held in Kuala
Lumpur, Malaysia, on July 11-13, 2017. The event will be held over three
days, with presentations delivered by researchers from the international
community, including…