There was a good article released by Joni on MS11-046 vulnerability based on a malware he analysed .
http://www.exploit-db.com/wp-content...docs/18712.pdf
So I taught of spending my staurday night building an exploit for this .
Windows [not sure about Win 7] lets Mapping of 0x00000000 in user space, and this particular vulnerability windows fix [Ms011-46] was by adding a simple check for Null Pntr in the AFD.sys, which I find odd, so I assume Win 7 it would
Am putting down Demo videos along with few important slides form my BlackHat 2012 presentation .
My presentation were in HTML 5 and am putting down Demo Presentations here. I will upload the HTML5 presentation some were or you could download them form
https://media.blackhat.com/bh-eu-12/...urity-Tool.zip
For Better understanding about these demos go through the html 5 slides
Main():
Java Webstart recently had critical security update in it's Webstart module Oracle Java Critical Patch Update - February 2012, that affects Firefox and IE, we will have few quick analysis of the vulnerable binary and few alternate ways to exploit them.
Little History and Introduction about the Bug:
Current bug is discovered and reported to Oracle by Vulnerability Research Team of TELUS Security Labs.
The vulnerability was similar
Open Source Time Travel Project
Hacking the time how, Time Travel is possible.
Introduction :.On what our concept is and what its not
Warning:
Before reading our concept you will have to erase form your memory all the graphical images that u might have acquired form various science fiction movies, this concept is nothing similar.
The sci-fi time machine concepts are those shown in movies are as follows. When a person is moving faster than
PDF:cocon_paper.pdf
Abstract: This paper provides insight on common web back doors and how simple manipulations could make them undetectable by AV and other security suits. Paper explains few techniques that could be used to render undetectable and unnoticed backdoor inside web applications.
This paper is mainly an update for an old paper of ours Effectiveness of Antivirus in Detecting Web Application Backdoors, which mainly questioned the effectiveness of AV with respect to
Duplicate RSA SeureID software...
Today, 10:15 AM in Reverse Engineering and Application Cracking