what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 76 RSS Feed

Files from Thierry Zoller

Email addressthierry at zoller.lu
First Active2005-10-25
Last Active2020-03-02
McAfee Generic Evasions
Posted May 1, 2009
Authored by Thierry Zoller

The McAfee parsing engine can be bypassed by a specially crafted and formatted RAR (Headflags and Packsize) or ZIP (Filelenght) archive.

tags | advisory
SHA-256 | ea6b4633d140cbe430fe0b6edb6bb33bbd4a99f3c81428950542a31c2a9d70f3
Trendmicro RAR/CAB/ZIP Bypass
Posted Apr 29, 2009
Authored by Thierry Zoller

The Trendmicro parsing engine can be bypassed by specially crafted and formatted ZIP, RAR, and CAB archives.

tags | advisory
SHA-256 | abed09554259c2e3388a70a248472bb87093766b256b9972dcf7ee400e610a4b
ESET Nod32 CAB Bypass
Posted Apr 29, 2009
Authored by Thierry Zoller

The ESET Nod32 parsing engine can be bypassed by a specially crafted and formatted CAB archive.

tags | advisory
SHA-256 | 1c69319e78e7b2c5cc45a466ee1778e1e75bb147ad1ae4612f28dc3cc03020ce
Aladdin eSafe Evasion
Posted Apr 28, 2009
Authored by Thierry Zoller

The Aladdin eSafe parsing engine can be bypassed by a specially crafted and formatted archive file.

tags | advisory
SHA-256 | bd8bc62ccc20c7336a31c7fa6429f28146402aba1afd6d44405f7bc420581150
Comodo Antivirus Evasion
Posted Apr 28, 2009
Authored by Thierry Zoller

The Comodo Antivirus parsing engine can be bypassed by a specially crafted and formatted RAR archive.

tags | advisory
SHA-256 | 18b393059b9194ffe44de9030e73d9f2b01ee62075973b7408323109bf2feb1f
Avira Antivir Bypass
Posted Apr 28, 2009
Authored by Thierry Zoller

The Avira Antivirus parsing engine can be bypassed by a specially crafted and formatted CAB archive.

tags | advisory
SHA-256 | 9b038c8e5f10a03ac624831a08698ba08315d147290d5e5bb33799922ee5499f
Sun Java Remote Code Execution
Posted Apr 22, 2009
Authored by Thierry Zoller

Sun Java VM versions 6 update 1 and 6 update 2 are susceptible to a remote code execution vulnerability.

tags | advisory, java, remote, code execution
SHA-256 | cc9f245448e9d2a35b3c826e7f61f75d2e36861758f1b13f2c26789140c20c84
Fortinet Bypass And Evasion
Posted Apr 17, 2009
Authored by Thierry Zoller

The parsing engine in Fortinet can be bypassed by a specially crafted and formated archive file. The bug results in denying the engine the possibility to inspect code within the archive. There is no inspection of the content at all.

tags | advisory
SHA-256 | 7330e5a1ce82e9df459efa7a72231861338a5a8b8faa3988279a52bfc3e70f47
Nod32 Bypass And Evasion
Posted Apr 17, 2009
Authored by Thierry Zoller

The parsing engine in Nod32 can be bypassed by a specially crafted and formated RAR archive. The bug results in denying the engine the possibility to inspect code within the RAR archive. There is no inspection of the content at all.

tags | advisory
SHA-256 | d16a3930303232da6c6000c0a2a401a46a80e757ad3095cd2dae73fd1b647c35
AVAST Generic Evasion
Posted Apr 17, 2009
Authored by Thierry Zoller

The parsing engine in AVAST can be bypassed by a specially crafted and formated RAR archive. The bug results in denying the engine the possibility to inspect code within the RAR archive. There is no inspection of the content at all.

tags | advisory
SHA-256 | 71d1ca5d2a352a58e67248f0d06a4195472337d5f22e84e988c377d1a10de562
Bitdefender Bypass And Evasion
Posted Apr 17, 2009
Authored by Thierry Zoller

The parsing engine in Bitdefender can be bypassed by a specially crafted and formatted CAB archive. The bug results in denying the engine the possibility to inspect code within the CAB archive. There is no inspection of the content at all.The parsing engine in Bitdefender can be bypassed by a specially crafted and formatted CAB archive. The bug results in denying the engine the possibility to inspect code within the CAB archive. There is no inspection of the content at all.

tags | advisory
SHA-256 | ddecd2cf5fc9845db8845c9acc356945dc8128e6106ec9e79fbafd2c19b5fdd0
F-PROT ZIP Method Evasion
Posted Apr 2, 2009
Authored by Thierry Zoller

The parsing engine in F-PROT can be bypassed by manipulating the ZIP method field. It is as easy as opening a ZIP file in an editor and typing a number greater than 15 on your keyboard. This is a four year old vulnerability that they still have not patched.

tags | advisory
advisories | CVE-2005-3499
SHA-256 | 32f11246969d4155068655689ca4f9c6ab515a0c2d759dc6e70b8a523521f060
IBM / ISS Proventia Evasion
Posted Apr 2, 2009
Authored by Thierry Zoller

The parsing engine in IBM ISS Proventia can be bypassed by manipulating RAR archives in a certain way that the IBM engine cannot extract the content but the end user is able to.

tags | advisory
SHA-256 | 886d00514b2f82efe2ac88764af3dbf921d459eedb7677dd4ebbc80781b7f291
ClamAV Evasion
Posted Apr 2, 2009
Authored by Thierry Zoller

The parsing engine in Clam AntiVirus versions below 0.95 can be bypassed by manipulating RAR archives in a certain way that ClamAV cannot extract the content but the end user is able to.

tags | advisory
SHA-256 | 1ad9a4ac9d3a2014ada24abfdc78454052f88645c0a7e7f90b20fe8a14b687f4
Avira Antivirus Privilege Escalation
Posted Jan 16, 2009
Authored by Thierry Zoller

Avira Antivirus suffers from a privilege escalation vulnerability that achieves SYSTEM access.

tags | advisory
SHA-256 | 5d9c944c45aa3bc86141cdbb88a4b1912da345c75110c1c830b3814ad67079ca
Avira Antivirus Division By Zero
Posted Jan 15, 2009
Authored by Thierry Zoller

Avira Antivirus suffers from division by zero / null pointer dereferencing vulnerabilities when handling a malformed RAR archive.

tags | advisory, vulnerability
SHA-256 | 3e074bda1d6c4131f956074250da30e305fd5f819946441e5497bdd2e6b9a43e
n.runs-SA-2008.008.txt
Posted Oct 21, 2008
Authored by Thierry Zoller | Site nruns.com

A remote code execution vulnerability exists in Internet Explorer due to accesses to uninitialized memory in certain cases of DTML constructs. As a result, memory may be corrupted in such a way that an attacker could execute arbitrary code in the context of the logged-on user.

tags | advisory, remote, arbitrary, code execution
SHA-256 | 63f11a575a512f09a4c59bdac83e1c1fd7a29a172f4f6cffa5c7ba94519fb9fd
n.runs-SA-2008.001.txt
Posted Jun 23, 2008
Authored by Thierry Zoller, Frank Dick | Site nruns.com

Jscape Secure FTP Applet does not perform SSH host key verification allowing man in the middle attacks.

tags | advisory
SHA-256 | faae475df15c9545776b1f8e33f497ed17c8c899a7b8c58535a164d5dafe252d
iframeicash.txt
Posted Mar 14, 2007
Authored by Thierry Zoller | Site secdev.zoller.lu

The Iframe-Cash/Iframe-Dollars Adware company does not only rootkit your machine, it also keystroke logs your banking details. Lovely.

tags | advisory
SHA-256 | b1813e4a381860177beb2d4841d451719bde3e5627d9a8789ebccc36b67d6ec0
23c3_Bluetooh_revisited.pdf
Posted Jan 5, 2007
Authored by Kevin Finisterre, Thierry Zoller

Presentation given at 23C3 called Bluetooth Hacking Revisited.

tags | paper
SHA-256 | 62cb81e204ee1879c82113f8ffc4c4c8fa9b539abcf6a25d3af5d29d73336577
TZO-072006-Xampp.txt
Posted May 22, 2006
Authored by Thierry Zoller | Site secdev.zoller.lu

XAMPP version 1.5.2 is susceptible to multiple privilege escalation flaws and a rogue autostart vulnerability.

tags | advisory
SHA-256 | 7297df138d18e6eb6c7c38264ddf0a821e1cc6c91cdd646bca96f9ef24a832d5
TZO-042006-Zango.txt
Posted May 21, 2006
Authored by Thierry Zoller | Site secdev.zoller.lu

ZangoCash is susceptible to an insecure auto-update and file execution flaw.

tags | advisory
SHA-256 | f4814f729712c71d4dbcb9c9ef8b53cb1a76f9656a661d5952b8194aa57cc854
TZO-062006.txt
Posted Feb 20, 2006
Authored by Thierry Zoller | Site secdev.zoller.lu

TZO-062006-SafenSec - Insecure File execution and Auto-startup

tags | advisory
SHA-256 | d74e41285a6e36ab1423145edffb11a10cf1d1c911e75311f125375c6e4e6021
TZO-012006-Checkpoint.txt
Posted Jan 25, 2006
Authored by Thierry Zoller | Site secdev.zoller.lu

TZO-012006 - Checkpoint VPN-1 SecureClient insecure usage of CreateProcess()

tags | advisory
SHA-256 | ddfa7039151f9be7a466fc3ee6130bce6ca4b3302873a8f391f1cfe7ff9151f2
TZO-012005-Fprot.txt
Posted Nov 3, 2005
Authored by Thierry Zoller | Site thierry.sniff-em.com

The F-Prot engine fails to decompress ZIP files that have a version header greater then 15. The consequence is that the F-prot Engine is unable to scan the virus/malware inside and consequently flags it as harmless. If used as an Email Gateway solution the offending Emails will slip through.

tags | advisory, virus
SHA-256 | 84a0def1156ec4829f01d470e51e93f26500ba11e4fc5b0989eaa0d50dedd25a
Page 3 of 3
Back123Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close