Since November I have been releasing details on all vulnerabilities I
found in web-browsers that I had not released before. I will try to
continue to publish all my old vulnerabilities, including those not in
web-browser, as long as I can find some time to do so. If you find this
information useful, you can help me make some time available by donating
bitcoin to 183yyxa9s1s1f7JBpPHPmzQ346y91Rx5DX.
Product
=======
(Taken from http://foundation.zurb.com/sites/docs/v/5.5.3/)
Foundation is the most advanced, responsive front-end framework in the
world. The framework is mobile
friendly and ready for you to customize it any way you…
After previous Cross-Site Request Forgery and Cross-Site Scripting
vulnerabilities, here are new ones. There are Cross-Site Request Forgery
vulnerabilities in D-Link DAP-1360 (Wi-Fi Access Point and Router).
————————-
Affected products:
————————-
Vulnerable is the next model: D-Link DAP-1360, Firmware 1.0.0. This model
with other firmware versions also must be vulnerable.
# Vulnerability Description:
# When the Eagle Speed software is installed a service with name ZDServ is
installed.
# The service itself has the right permissions which do not allow to
reconfigure the binary
# but the path the binary is writable by any authenticated user.
#
# C:Userslowpriv>sc qc zdserv
# [SC] QueryServiceConfig SUCCESS
#
# SERVICE_NAME: zdserv
# TYPE : 110 WIN32_OWN_PROCESS (interactive)
#…
Posted by Pierre-David Oriol – Northsec Conference on Dec 01
www.nsec.io – northsec.eventbrite.ca
NorthSec 2017, one of the biggest applied security event in Canada,
coming up in Montreal in May 2017:
May 16-17 – Professional Training Sessions – Syllabus Announced Soon
May 18-19 – Security Conference & Workshops
May 19-21 – The biggest 48H on-site CTF in North America, with 350+ attendees
As I am sure you are by now well aware, in November I decided to start
releasing details on all vulnerabilities I found in web-browsers that I
had not released before. As I was unable to publish all of them within a
single month, I will try to continue to publish all my old
vulnerabilities, including those not in web-browser, as long as I can
find some time to do so. If you find this information useful, you can
help me make some time available by…
Throughout November, I plan to release details on vulnerabilities I
found in web-browsers which I’ve not released before. This is the
twenty-second entry in that series. Unfortunately I won’t be able to
publish everything within one month at the current rate, so I may
continue to publish these through December and January.
Due to the recent Firefox 0-day, I’ve selected a very old and not so
interesting bug for today, so you can…
Throughout November, I plan to release details on vulnerabilities I
found in web-browsers which I’ve not released before. This is the
twenty-first entry in that series. Unfortunately I won’t be able to
publish everything within one month at the current rate, so I may
continue to publish these through December and January.