Faraday 3.0

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.

Facebooktwittergoogle_plusredditpinterestlinkedinmail

LibRaw 0.18.11 Denial Of Service

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Secunia Research has discovered multiple vulnerabilities in LibRaw, which can be exploited by malicious people to cause a DoS (Denial of Service). An integer overflow error within the “parse_qt()” function (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop via a specially crafted Apple QuickTime file. An integer overflow error within the “identify()” function (internal/dcraw_common.cpp) can be exploited to trigger a division by zero via specially crafted NOKIARAW file. The vulnerabilities are confirmed in version 0.18.11. Prior versions may also be affected.

Facebooktwittergoogle_plusredditpinterestlinkedinmail

QNAP Q’Center change_passwd Command Execution

Facebooktwittergoogle_plusredditpinterestlinkedinmail

This Metasploit module exploits a command injection vulnerability in the change_passwd API method within the web interface of QNAP Q’Center virtual appliance versions prior to 1.7.1083. The vulnerability allows the ‘admin’ privileged user account to execute arbitrary commands as the ‘admin’ operating system user. Valid credentials for the ‘admin’ user account are required, however, this module also exploits a separate password disclosure issue which allows any authenticated user to view the password set for the ‘admin’ user during first install. This Metasploit module has been tested successfully on QNAP Q’Center appliance version 1.6.1075.

Facebooktwittergoogle_plusredditpinterestlinkedinmail