New User, Welcome!     Login

RedTeam Pentesting GmbH

[RT-SA-2010-002] Geo++(R) GNCASTER: Insecure handling of NMEA-data

-------------------------------------------------------------------
#!/usr/bin/env ruby
######################################
#                                    #
#  RedTeam Pentesting GmbH           #
#  kontakt@redteam-pentesting.de     #
#  http://www.redteam-pentesting.de  #
#                                    #
######################################


RE: TLS Renegotiation Vulnerability: Proof of Concept Code (Python)

-----Original Message-----
From: Barry Raveendran Greene [mailto:bgreene@senki.org] 
Sent: Monday, December 21, 2009 9:16 PM
To: 'RedTeam Pentesting GmbH'; bugtraq@securityfocus.com
Subject: RE: TLS Renegotiation Vulnerability: Proof of Concept Code
(Python)

Also, can you change this:


[RT-SA-2011-001] nostromo nhttpd directory traversal leading to arbitrary command execution

------------------------------------------------------------------------
#!/bin/sh
######################################
#                                    #
#  RedTeam Pentesting GmbH           #
#  kontakt@redteam-pentesting.de     #
#  http://www.redteam-pentesting.de  #
#                                    #
######################################


[RT-SA-2009-001] IceWarp WebMail Server: Cross Site Scripting in Email View

2009-04-28 CVE number assigned
2009-05-05 Vendor publishes fixed version
2009-05-05 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting is offering individual penetration tests, short
pentests, performed by a team of specialised IT-security experts.
Hereby, security weaknesses in company networks or products are

[RT-SA-2010-003] Geo++(R) GNCASTER: Faulty implementation of HTTP Digest Authentication

2009-07-14 Meeting with customer
2009-12-01 Vendor releases fixed version
2010-01-27 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be

RE: TLS Renegotiation Vulnerability: Proof of Concept Code (Python)

Thanks,

Barry

> -----Original Message-----
> From: RedTeam Pentesting GmbH [mailto:release@redteam-pentesting.de]
> Sent: Monday, December 21, 2009 5:04 AM
> To: bugtraq@securityfocus.com
> Subject: TLS Renegotiation Vulnerability: Proof of Concept Code
> (Python)
> 

Alcatel-Lucent OmniPCX Remote Command Execution

http://www1.alcatel-lucent.com/psirt/statements.htm
reference number 2007002


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting is offering individual penetration tests, short
pentests, performed by a team of specialised IT-security experts.
Hereby, security weaknesses in company networks or products are

[RT-SA-2010-001] Geo++(R) GNCASTER: Insecure handling of long URLs

2009-07-14 Meeting with customer
2009-12-01 Vendor releases fixed version
2010-01-27 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be

[RT-SA-2009-005] Papoo CMS: Authenticated Arbitrary Code Execution

References
==========

[0] http://www.papoo.de/cms-news-und-infos/security/papoo-sicherheitsmeldung-07-2009.html

RedTeam Pentesting GmbH
=======================

RedTeam Pentesting is offering individual penetration tests, short
pentests, performed by a team of specialised IT-security experts.
Hereby, security weaknesses in company networks or products are

[RT-SA-2011-002] SugarCRM list privilege restriction bypass

2011-02-09 Vendor confirmed the vulnerability
2011-03-10 Vendor releases fix
2011-03-15 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be

[RT-SA-2011-004] Client Side Authorization ZyXEL ZyWALL USG Appliances Web Interface

RedTeam Pentesting likes to thank ZyXEL for the fast response and
professional collaboration.


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be

[RT-SA-2011-003] Authentication Bypass in Configuration Import and Export of ZyXEL ZyWALL USG Appliances

[2] http://www.unix-ag.uni-kl.de/~conrad/krypto/pkcrack.html
[3] http://www.elcomsoft.com/archpr.html
[4] http://httpd.apache.org/docs/2.0/mod/core.html#acceptpathinfo


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be

[RT-SA-2009-002] IceWarp WebMail Server: User-assisted Cross Site Scripting in RSS Feed Reader

2009-04-28 CVE number assigned
2009-05-05 Vendor publishes fixed version
2009-05-05 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting is offering individual penetration tests, short
pentests, performed by a team of specialised IT-security experts.
Hereby, security weaknesses in company networks or products are

[RT-SA-2009-003] IceWarp WebMail Server: SQL Injection in Groupware Component

2009-04-28 CVE number assigned
2009-05-05 Vendor publishes fixed version
2009-05-05 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting is offering individual penetration tests, short
pentests, performed by a team of specialised IT-security experts.
Hereby, security weaknesses in company networks or products are

[RT-SA-2009-004] IceWarp WebMail Server: Client-Side Specification of "Forgot Password" eMail Content

2009-04-28 CVE number assigned
2009-05-05 Vendor publishes fixed version
2009-05-05 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting is offering individual penetration tests, short
pentests, performed by a team of specialised IT-security experts.
Hereby, security weaknesses in company networks or products are

Advisory: SQL-Injections in Mapbender

2008-01-17 CVE number assigned
2008-03-10 Vendor releases fixed version
2008-03-11 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting is offering individual penetration tests, short
pentests, performed by a team of specialised IT-security experts.
Hereby, security weaknesses in company networks or products are

New Paper: MitM Attacks against the chipTAN comfort Online Banking System

The full paper is available in German and English at

http://www.redteam-pentesting.de/publications/MitM-chipTAN-comfort

-- 
RedTeam Pentesting GmbH                    Tel.: +49 241 963-1300
Dennewartstr. 25-27                        Fax : +49 241 963-1304
52068 Aachen                    http://www.redteam-pentesting.de/
Germany                         Registergericht: Aachen HRB 14004
Geschftsfhrer: Patrick Hof, Jens Liebchen, Claus R. F. Overbeck


TLS Renegotiation Vulnerability: Proof of Concept Code (Python)

to raise awareness for the vulnerability and its potential impact. Furthermore,
it shall give interested persons the opportunity to analyse applications
employing TLS for further vulnerabilities.

-- 
RedTeam Pentesting GmbH                    Tel.: +49 241 963-1300
Dennewartstr. 25-27                        Fax : +49 241 963-1304
52068 Aachen                    http://www.redteam-pentesting.de/
Germany                         Registergericht: Aachen HRB 14004
Geschftsfhrer: Patrick Hof, Jens Liebchen, Claus R. F. Overbeck


[RT-SA-2011-006] Owl Intranet Engine: Information Disclosure and Unsalted Password Hashes

2011-10-31 Vendor notified
2011-11-30 Vendor releases new version that does not fix the issue
2011-12-15 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be

[RT-SA-2011-005] Owl Intranet Engine: Authentication Bypass

2011-10-31 Vendor notified
2011-11-30 Vendor released fixed version and notifies customer base
2011-12-15 Advisory released


RedTeam Pentesting GmbH
=======================

RedTeam Pentesting offers individual penetration tests, short pentests,
performed by a team of specialised IT-security experts. Hereby, security
weaknesses in company networks or products are uncovered and can be



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!