Subscribe via feed.

Zed Attack Proxy 2.4.2 Mac OS X Release

Posted by deepcore under Apple (No Respond)

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing. ZAP provides automated scanners […]

Tags: , ,

Disconnect.me 2.0 Local Root Exploit

Posted by deepcore under Apple (No Respond)

Disconnect.me versions 2.0 and below suffer from a local privilege escalation vulnerability on Mac OS X.

Tags: , ,

OS X x64 /bin/sh Shellcode

Posted by deepcore under Apple (No Respond)

34 bytes small NULL byte free OS X x64 /bin/sh shellcode.

Tags: , ,

PayPal Authentication Bypass

Posted by deepcore under Apple (No Respond)

The Vulnerability Laboratory Core Research Team discovered a restriction filter bypass in the official PayPal Inc Mobile API for Apple iOS.

Tags: , ,

Apple OS X Entitlements Rootpipe Privilege Escalation

Posted by deepcore under Apple (No Respond)

This Metasploit module exploits the rootpipe vulnerability and bypasses Apple’s initial fix for the issue by injecting code into a process with the ‘admin.writeconfig’ entitlement.

Tags: , ,

Apple Security Advisory 2015-08-20-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-08-20-1 – QuickTime 7.7.8 is now available and addresses arbitrary code execution and memory corruption issues.

Tags: , ,

Apple Security Advisory 2015-08-13-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-08-13-1 – Safari 8.0.8, Safari 7.1.8, and Safari 6.2.8 is now available and addresses interface spoofing, arbitrary code execution, and various other vulnerabilities.

Tags: , ,

Apple Security Advisory 2015-08-13-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-08-13-2 – OS X Yosemite 10.10.5 and Security Update 2015-006 is now available and addresses vulnerabilities in Apache, the OD plug-in, IOBluetoothHCIController, and more.

Tags: , ,

Apple Security Advisory 2015-08-13-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-08-13-3 – iOS 8.4.1 is now available and addresses vulnerabilities in the afc command, AirTraffic, symlinks, and more.

Tags: , ,

Apple Security Advisory 2015-08-13-4

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2015-08-13-4 – OS X Server v4.1.5 is now available and addresses a BIND related denial of service vulnerability.

Tags: , ,