Showing posts with label day zero exploit. Show all posts
Showing posts with label day zero exploit. Show all posts

Thursday, 17 January 2013

Security Hole found in Cisco Linksys Routers

Security company DefenseCode Ltd has disclosed a video showing a proof of concept exploit that allows root access to millions of Cisco Linksys routers in their default installation.

The company says they have contacted Cisco about a remote preauth (root access) vulnerability in default installation of their Linksys routers, including detailed vulnerability description along with the PoC (proof of concept) exploit for the vulnerability.

The exploit shown in this video has been tested on Cisco Linksys WRT54GL, but DefenseCode says other Linksys models could also be affected.

Cisco Linksys is a popular router. Still according to the company Cisco claims this vulnerability was already fixed in latest firmware release but further tests show that the latest official Cisco Linksys firmware 4.30.14, and all previous versions are still vulnerable.

Sunday, 30 December 2012

Internet Explorer hit by zero-day exploit, temporary fix issued



Web site for the Council on Foreign Relations was compromised and recently hit by a drive-by attack that was detected earlier this week. Hacker are suspected to be from China , who are exploiting a zero day  Internet Explorer vulnerability for Cyber Espionage attack against one of American most elite foreign policy web groups.

Poison Ivy exploits a “use-after-free vulnerability” in IE that enables a hacker to create an image URL referencing uninitialized memory. This corrupts the memory and once completely executed gives the attacker remote access with the same permissions as the current user.
Once the system compromised, hackers look for valuable information from their computers. FBI was notified of the attack and is said to be investigating. Firm also confirm that the malicious code was planted on the server using Mandarin Chinese language. In description parameter of MD5 of malicious files, they found simplified Chinese <文件说明> , that translates to <File Description>.

Microsoft is urging users of Internet Explorer to download a free security tool, enhanced Mitigation Experience Toolkit (EMET), as an interim measure against a previously unknown zero-day exploit in its web browser software that is under active malware attack by hackers.
The vulnerability affects computers running all versions of Internet Explorer from IE6 to IE9, on every single OS release since Windows XP right through to Windows 7 and Server 2008. Interestingly though, Microsoft’s IE 10 running on Windows 8 and Server 2008 are not affected according to Microsoft’s Security Advisory
Microsoft says a fix is in the works and may be released during its normal monthly update cycle, or in a separate security update, depending on customers' needs..