exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

TEHTRI-Security Multiple Advisories

TEHTRI-Security Multiple Advisories
Posted Jul 3, 2010
Authored by Laurent Oudot | Site tehtri-security.com

TEHTRI-Security has released advisories discussing a stack overflow inside the iPhone iOS4 CFNetwork API, a client-side attack for BlackBerry devices, a client-side attack for HTC Windows Mobile cellphones, a client-side attack for the iPad and security issues related to trains.

tags | advisory, overflow
systems | windows, apple, iphone
SHA-256 | 4b42d73c1aadeaf9de7a51b6a9001fd83e5cb88bb700f472dc1f03987ad68017

TEHTRI-Security Multiple Advisories

Change Mirror Download
Gents,

TEHTRI-Security was invited to give a talk called "Web In The Middle,
Attacking Clients", at the first Hack In The Box Europe, Amsterdam (
http://conference.hackinthebox.org/hitbsecconf2010ams/ ).

During our talk, we released multiple advisories and we explained many
issues related to some vulnerabilities. You can find more public
information through the slides available online. Here are some related
details that we wanted to share with you through this mailing list :

o CVE-2010-1752: TEHTRI-Security inside the iPhone iOS4
TEHTRI-Security found a stack overflow in CFNetwork API, through the
code used to handle URL. By visiting a maliciously crafted website, we
found that it might lead to an unexpected application termination or
arbitrary code execution. This issue has been addressed by Apple through
improved memory handling. CFNetwork is shared by most applications from
the App Store, that need to talk over the web. Check the User-Agent of
your applications to be sure (example: Facebook/3.12 *CFNetwork/459*
Darwin/10.0.0d3 ). Update to iOS4 to improve your security.
More information here:
CVE-2010-1752 in http://support.apple.com/kb/HT4225

o Security-Advisory: TEHTRI-SA-2010-028 - 0day on BlackBerry
TEHTRI-Security found a security issue, and created a client-side attack
0day for BlackBerry cellphone devices (Hotspot Browser). The code was
shared with RIM who handled this vulnerability quickly, so that a fix
might be added in a future release. It allows an attacker to crash the
remote web application. This was scored with a CVSS of 5.

o Security-Advisory: TEHTRI-SA-2010-027 - 0day on HTC
TEHTRI-Security found a security issue, and created a client-side attack
0day for HTC Windows Mobile cellphone devices (Opera). HTC was contacted.

o Security-Advisory: TEHTRI-SA-2010-026 - 0day on iPad
TEHTRI-Security found a security issue, and created a client-side attack
0day for the (awesome) iPad device. The code was shared with Apple who
handled this vulnerability quickly, so that a fix might be added to a
future release. A demo was done during our talk, without giving
dangerous details to the attendees. It was only shown for attendees of
HITB Europe. No further information will be shared to the public before
Apple release a patch.

o Security-Advisory: TEHTRI-SA-2010-026 - 0day on ThalysNet
TEHTRI-Security found some security issues on Thalys European trains,
with the Internet access on board. To us, many Internet access shared on
airports, stations, trains, in-flights, hotels, etc, are full of
security vulnerabilities, because no penetration test were organized
with IT Security experts before the service is open to the public.
Dealing with ThalysNet, it concerns half a million of end-users.
ThalysNet was contacted.

We also glanced at the differences related to the use of http and https
on worldwide web services like hotmail, yahoo, twitter, facebook,
linkedin, google mail, apple mobile me... A table on slide 32 might help
beginners who would like to check the current situation. Dealing with
https issues, as we said, we encourage you to have a look at initiatives
like the one from the EFF: https://www.eff.org/https-everywhere

Some of our security advisories were already covered by the local press
from NL:
http://www.tehtri-security.com/en/press.php

The HITB crew have put slides of our conference on their web site:
http://conference.hitb.org/hitbsecconf2010ams/materials/D1T1%20-%20Laurent%20Oudot%20-%20Web%20in%20the%20Middle.pdf

If you want to get more details & technical secrets from
TEHTRI-Security, feel free to join us "in real life" during our next
trainings sessions & talks, or feel free to contact us for specific
needs. We have public events planned next months (Asia, Europe).
Check-out our public agenda here:
http://www.tehtri-security.com/en/agenda.php

See you soon.
Thanks. Take care.

Laurent Oudot, founder & CEO of TEHTRI-Security
TEHTRI-Security, "This is not a game".
http://www.tehtri-security.com

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close