Mozilla Prism v1.0b2 – Stack Buffer Overflow Vulnerability

This week I audited the new Mozilla PRISM what is usually called as a secure browser engine & used by a lot of software(Zimbra|Desktop). Prism is an application that lets users split web applications out of their browser and run them directly on their desktop in a secure mode. Mozilla Developers have produced 1 application (standalone)of Prism what is stable running & 1 addon for Mozilla Fireox browser.

Weiterlesen »


PandoraFMS Monitoring v2.x – SQL Injection Vulnerability

GESEC Team(~smash & ~rem0ve) discover a SQL Injection Vulnerability on Pandora FMS Monitoring. Attackers can manipulate the application DBMS over a remote sql-injection vulnerability.

weiterlesen »


Barracuda IMFirewall – Input Validation Vulnerability

In this week we discovered multiple Input Validation Vulnerabilities on Barracuda IM Firewall Appliance. A remote attacker is able to get sensitive customer sessions or can implement evil script routines(JS;PHP) & malicious codes(server-side).  A Input Validation Vulnerability is detected on server-side(persistent) of IMFW 620.

weiterlesen »


Global-Evolution