we

Advantech WebAccess dvs.ocx GetColor Buffer Overflow

This Metasploit module exploits a buffer overflow vulnerability in Advantec WebAccess. The vulnerability exists in the dvs.ocx ActiveX control, where a dangerous call to sprintf can be reached with user controlled data through the GetColor function. This Metasploit module has been tested successfully on Windows XP SP3 with IE6 and Windows 7 SP1 with IE8 and IE 9.




we

Advantech WebAccess 7.2 Stack-Based Buffer Overflow

Core Security Technologies Advisory - Advantech WebAccess version 7.2 is vulnerable to a stack-based buffer overflow attack, which can be exploited by remote attackers to execute arbitrary code, by providing a malicious html file with specific parameters for an ActiveX component.




we

Advantech WebAccess 8.0 / 3.4.3 Code Execution

Using Advantech WebAccess SCADA Software and attacker can remotely manage industrial control systems devices like RTU's, generators, motors, etc. Attackers can execute code remotely by passing a maliciously crafted string to ConvToSafeArray API in ASPVCOBJLib.AspDataDriven ActiveX.




we

UltraVNC Viewer 1.2.4.0 Denial Of Service

UltraVNC Viewer version 1.2.4.0 VNCServer denial of service proof of concept exploit.






we

Were Oslo's Terror Blasts Caused By Car Bombs?




we

Norweigian Oil And Defense Industries Are Hit By A Major Cyber Attack




we

Soca Website Attack: Norway Arrests Two Youths




we

KeeWeb 1.14.0 HTML Injection

KeeWeb version 1.14.0 suffers from an html injection vulnerability.





we

42: The Answer To Life, The Universe, And How Many Cisco Products Have Struts Bugs




we

Web Tools Create XSS Headaches




we

Scripting Bugs Blight Security Giants' Websites




we

Attention Symantec - There Is A Bug Crawling On Your Website




we

MoD Website Outflanked By XSS Flaws




we

Anti-Virus Vendor Trio Plug Website Flaws







we

Hackers Shut Down NDDC Website Over Presidential Inauguration




we

Nigerian Prince Swaps The Sweet Talk For Keyloggers And Exploits











we

Satellite Weather Forecast: Cloudy WIth A Chance Of p0wnage




we

Satnav Spoofing Attacks: Why These Researchers Think They Have The Answer




we

Hack A Nintendo DS To Make An Awesome Digital Sketchbook




we

Hacker Owes Nintendo $1.3M












we

Hacking ASP/ASPX Websites Manually

This is a whitepaper that goes into detail on hacking ASP/ASPX websites manually.




we

ASP Webshell For IIS 8

ASP webshell backdoor designed specifically for IIS 8.




we

AfterLogic WebMail Pro ASP.NET Account Takeover / XXE Injection

AfterLogic WebMail Pro ASP.NET versions prior to 6.2.7 suffer from an administrator account takeover via an XXE injection vulnerability.




we

Defending Islam, Hacker Defaces Thousands Of Dutch Websites