2Cents about Cyber Security

Recent Posts

Luigi Vezzoso's Avatar'

CRYPTSHARE ā€“ StoredĀ XSS

Exploit Title: [CRYPTSHARE ā€“ Stored XSS] Date: [13-May-2016] Exploit Author: [Luigi Vezzoso] Vendor Homepage: [https://www.cryptshare.com] Version: [3.10.1.2] Tested on: [OPENSUSE 13.2] CVE : [CVE-2016-XXXX] Ā  OVERVIEW Is possible to inject arbitrary code into the logs simply from the authentication form of the administrative appliance interface. In particular we found the is possible ...

Exploit Title: [CRYPTSHARE ā€“ Stored XSS] Date: [13-May-2016] Exploit Author: [Luigi Vezzoso] Vendor Homepage: [https://www.cryptshare.com] Version: [3.10.1.2] Tested on: [OPENSUSE 13.2] CVE : [CVE-2016-XXXX] Ā  OVERVIEW Is possible to inject arbitrary code into the logs simply from the au...

Luigi Vezzoso's Avatar'

Donā€™t open links on yourĀ smartphone!

An other Ramsonware is spreading into the wild targeting ANDROID devices!!! Be carefu opening links from your mobile phone because those evil link will try to install a custom APK with the ramsonware. There is a list of bad link (tks to Lukas Stefanko ā€“ bad sites apk list ) Active Android Ransomware http://kavssporn.ru/xx/down.php http://poornkz.ru/xx/down.php http://superovoeporevo.ru/xx...

An other Ramsonware is spreading into the wild targeting ANDROID devices!!! Be carefu opening links from your mobile phone because those evil link will try to install a custom APK with the ramsonware. There is a list of bad link (tks to Lukas Stefanko ā€“ bad sites apk list ) Active Android Rans...

Luigi Vezzoso's Avatar'

Never take candy fromĀ strangers

In these days Iā€™m testing some tools used to evade antivirus (both client AV and gateway AV). The result is very impressive: the basic tools can evade most of antivirus. One of the tool is shellter. Shellter is a dynamic code injector inside PE windows file From the shellter project website: Shellter takes advantage of the original structure of the PE file and doesnā€™t apply any modification...

In these days Iā€™m testing some tools used to evade antivirus (both client AV and gateway AV). The result is very impressive: the basic tools can evade most of antivirus. One of the tool is shellter. Shellter is a dynamic code injector inside PE windows file From the shellter project website: ...

Luigi Vezzoso's Avatar'

[CVE-2014-2084] - SKYBOX Security ā€“ Multiple Information Disclosure

Date: [22-Jan-2014] Exploit Author: [Luigi Vezzoso] Vendor Homepage: [http://www.skyboxsecurity.com] Version: [Skybox View Appliances with ISO versions: 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, 6.4.46-2.57] Tested on: [Centos 6.4 kernel 2.6.32] CVE : [CVE-2014-2084] #OVERVIEW A vulnerability has been found in some Skybox View Appliancesā€™ Admin interfaces which would allow a po...

Date: [22-Jan-2014] Exploit Author: [Luigi Vezzoso] Vendor Homepage: [http://www.skyboxsecurity.com] Version: [Skybox View Appliances with ISO versions: 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, 6.4.46-2.57] Tested on: [Centos 6.4 kernel 2.6.32] CVE : [CVE-2014-2084] #OVERVIEW A ...

Luigi Vezzoso's Avatar'

[CVE-2014-2085] - SKYBOX Security - DDOS

Exploit Title: [SKYBOX Security - DDOS] Date: [22-Jan-2014] Exploit Author: [Luigi Vezzoso] Vendor Homepage: [http://www.skyboxsecurity.com] Version: [Skybox View Appliances with ISO versions: 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, 6.4.46-2.57] Tested on: [Centos 6.4 kernel 2.6.32] CVE : [CVE-2014-2085] #OVERVIEW A vulnerability has been found in some Skybox View Appliances...

Exploit Title: [SKYBOX Security - DDOS] Date: [22-Jan-2014] Exploit Author: [Luigi Vezzoso] Vendor Homepage: [http://www.skyboxsecurity.com] Version: [Skybox View Appliances with ISO versions: 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, 6.4.46-2.57] Tested on: [Centos 6.4 kernel 2.6....