Subscribe via feed.

Apple Quicktime .pct Parsing Memory Corruption

Apple Quicktime does not properly parse .pct media files, which causes a corruption in module DllMain by opening a malformed file with an invalid value located in PoC repro01.pct at offset 0x20E. Quicktime Player version 7.7.1 (1680.42) on Windows XP SP 3 – PT_BR is confirmed affected.

Tags: , , , ,

Apple Security Advisory 2012-05-14-2

Apple Security Advisory 2012-05-14-2 – This update disables Adobe Flash Player if it is older than 10.1.102.64 by moving its files to a new directory.

Tags: , , ,

Apple Security Advisory 2012-05-14-1

Apple Security Advisory 2012-05-14-1 – This update runs a malware removal tool that will remove the most common variants of the Flashback malware. If the Flashback malware is found, it presents a dialog notifying the user that malware was removed. There is no indication to the user if malware is not found.

Tags: , , , ,

Apple Security Advisory 2012-05-07-1

Apple Security Advisory 2012-05-07-1 – A URL spoofing issue existed in Safari. This could be used in a malicious web site to direct the user to a spoofed site that visually appeared to be a legitimate domain. Multiple cross site scripting issues existed in WebKit along with a memory corruption issue.

Tags: , , , ,

[webapps / 0day] – DIY CMS v1.0 Poll Multiple Vulnerabilities

Posted by deepcore under exploit, m$, XSS (No Respond)

Link: [webapps / 0day] – DIY CMS v1.0 Poll Multiple Vulnerabilities

Tags: , , , ,

Vega Web Security Scanner 1.0 Beta Mac OS X 64 Bit

Posted by deepcore under Apple, OSX security tools, Security, XSS (No Respond)

Vega is a GUI-based, multi-platform, free and open source web security scanner that can be used to find instances of SQL injection, cross-site scripting (XSS), and other vulnerabilities in your web applications. Vega also includes an intercepting proxy for interactive web application debugging. Vega attack modules are written in Javascript, users can easily modify them or write their own

Tags: , , , ,

Vega Web Security Scanner 1.0 Beta Mac OS X 32 Bit

Posted by deepcore under Apple, OSX security tools, Security, XSS (No Respond)

Vega is a GUI-based, multi-platform, free and open source web security scanner that can be used to find instances of SQL injection, cross-site scripting (XSS), and other vulnerabilities in your web applications. Vega also includes an intercepting proxy for interactive web application debugging. Vega attack modules are written in Javascript, users can easily modify them or write their own.

Tags: , , ,