gh

cabrightstor_disco.pm

The CA BrightStor Discovery Service overflow exploit is a perl module exploits a vulnerability in the CA BrightStor Discovery Service which occurs when a large request is sent to UDP port 41524, triggering a stack overflow. Targets include Win32, win2000, winxp, and win2003. More information available here.




gh

cabrightstor_disco_servicepc.pm

CA BrightStor Discovery Service SERVICEPC Overflow for Win32, win2000, winxp, and win2003 which exploits a vulnerability in the TCP listener on port 45123. Affects all known versions of the BrightStor product. More information available here.




gh

Intel Patches High-Severity Flaws In Media SDK, Mini PC





gh

Intel CMSE Bug Is Worse Than Previously Thought




gh

Intel Fixes High-Severity Flaws In NUC, Discontinues Buggy Compute Module








gh

Packet Storm Exploit 2013-1022-1 - Microsoft Silverlight Invalid Typecast / Memory Disclosure

This exploit leverages both invalid typecast and memory disclosure vulnerabilities in Microsoft Silverlight 5 in order to achieve code execution. This exploit code demonstrates remote code execution by popping calc.exe. It was obtained through the Packet Storm Bug Bounty program. Google flags this as malware so only use this if you know what you are doing. The password to unarchive this zip is the word "infected".




gh

Packet Storm Advisory 2013-1022-1 - Microsoft Silverlight Invalid Typecast / Memory Disclosure

Microsoft Silverlight 5 suffers from invalid typecast and memory disclosure vulnerabilities that, when leveraged together, allow for arbitrary code execution. A memory disclosure vulnerability exists in the public WriteableBitmap class from System.Windows.dll. This class allows reading of image pixels from the user-defined data stream via the public SetSource() method. BitmapSource.ReadStream() allocates and returns byte array and a count of array items as out parameters. These returned values are taken from the input stream and they can be fully controlled by the untrusted code. When returned "count" is greater than "array.Length", then data outside the "array" are used as input stream data by the native BitmapSource_SetSource() from agcore.dll. Later all data can be viewed via the public WriteableBitmap.Pixels[] property. Exploitation details related to these findings were purchased through the Packet Storm Bug Bounty program.












gh

MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python

This Metasploit module exploits a vulnerability found in Windows Object Linking and Embedding (OLE) allowing arbitrary code execution, bypassing the patch MS14-060, for the vulnerability publicly known as "Sandworm", on systems with Python for Windows installed. Windows Vista SP2 all the way to Windows 8, Windows Server 2008 and 2012 are known to be vulnerable. However, based on our testing, the most reliable setup is on Windows platforms running Office 2013 and Office 2010 SP2. Please keep in mind that some other setups such as those using Office 2010 SP1 may be less stable, and may end up with a crash due to a failure in the CPackage::CreateTempFileName function.





gh

Random Number Bug Blights FreeBSD










gh

Linux Command-Line Editors Vulnerable To High Severity Bug





gh

Latvia highlights anti-money laundering efforts

FDI into Latvia has recovered in recent years as the Baltic state has implemented stricter anti-money laundering procedures. Latvian minister of economics Ralfs Nemiro talks to Alex Irwin-Hunt about the progress made.




gh

Viewpoint: In emerging states, more investment isn’t enough

Emerging states must re-orientate their investment efforts to increasingly target those with an outsized social impact




gh

UK regions fight for a share of inward investment

The UK’s prime minister has pledged to rebalance the UK economy away from a dominant London. However, this might require greater incentives for foreign investment in the regions outside of the capital, which are underperforming. 




gh

Finance minister seeks to keep Serbia in FDI spotlight

Serbia’s minister of finance, Siniša Mali, explains why the country is one of Europe's economic stars, and how its FDI levels have risen on the back of this.




gh

Spotlight: Serbian free zones

Serbia’s 15 free zones are driving forward an ongoing flurry of foreign investment in the country’s buoyant manufacturing scene, especially in automotives.





gh

Frankfurt (Oder) looks to get the incentives mix right

The federal state of Brandenburg is committed to ensuring investors are welcomed into Frankfurt (Oder) through a string of generous incentives.




gh

Afghanistan seeks pioneers to reap rewards of its risks

Despite recurrent challenges, Afghanistan’s business environment is improving. Now the authorities are working to persuade investors the rewards are worth the risk through a series of economic and legal reforms. 




gh

Industry minister seeks to put Afghanistan back in business

Ajmal Ahmady, Afghanistan's minister of industries and commerce, outlines government efforts to make the country more conducive to business.




gh

Pakistan’s UK high commissioner hails land of opportunity

Mohammad Nafees Zakaria, Pakistan’s UK high commissioner, talks about his country’s potential for foreign investors.




gh

Chinese investment to Europe at record high

Sino-European foreign direct investment is converging, according to data from fDi Markets.




gh

A new high for FDI in Spain in 2018

Successive annual increases of FDI inflows to Spain culminated in a record year in 2018. Alex Irwin-Hunt reports.




gh

Cyprus sees FDI high in 2018

Cyprus’s record-breaking 2018 was driven by tourism and second-tier cities. 




gh

FDI into Canada reaches four-year high of $41.9bn

Canada has seen a four-year peak in FDI, with the technology, real estate and aerospace sectors enjoying substantial growth. Zara Fennell reports.




gh

Too much water or too little: hydropower fights wild weather

The Kariba Dam has towered over one of Africa’s mightiest rivers for 60 years, forming the world’s largest reservoir and providing reliable electricity to Zambia and Zimbabwe.




gh

Massachusetts approves contracts for hydroelectricity through NECEC project

The Massachusetts Department of Public Utilities has issued an order approving long-term contracts for 9,554,940 MWh annually of hydropower between H.Q. Energy Services (U.S.) Inc. and the Commonwealth’s electric distribution companies through the New England Clean Energy Connect 100% Hydro project (NECEC Hydro).




gh

Minnesota utilities weigh energy storage as substitute for peaker plants

Gas peaker plants may be among the first casualties of a new Minnesota law requiring utilities to include energy storage as part of their long-range plans.




gh

The 150,000-square-meter sky bridge of Shanghai’s 'Rafael Gallery' will be covered in solar

Solar company Hanergy announced that its thin-film solar modules will cover the 150,000 square meter roof of the ‘Rafael Gallery’ located at a Tech City in Shanghai.




gh

Study: Fossil fuels are far less efficient than previously thought

Fossil fuels, long regarded for their high-energy return on investment, are not as efficient as once thought. In fact, their final yields are not much better than those of renewable options, according to a new study.