Canape – Dicing ESXi into Byte Size Portions
On the 21st October Context consultant Alex Chapman will be presenting at the Ruxcon conference in Melbourne. Alex will be describing how to inspect, manipulate and exploit the main remote...
View ArticleSAP Parameter Injection - No Space for Arguments
This blog post details a vulnerability that was found in SAP’s Host Control service. The vulnerability allows for 100% reliable full code execution as the SAP administrator from an unauthenticated...
View ArticleServer Technologies- Are You Using .NET Remoting? Stop it!
In May 2012 Microsoft released MS12-035 which was a security update for all versions of the .NET framework (including v4.0) based on some security research I performed over 12 months prior. It aimed to...
View ArticleMalware - Exploit Packs, Zeus and Ransomware
In the last blog post, we looked at the processes and steps involved in a successful malware campaign. The series covered the Trojan Carberp and the many aspects to its functionality that resulted in a...
View ArticleSAP Exploitation – Part 3
In this post of the series, I will go into some detail on the various mitigations and configuration changes required to be made to your SAP environment to help protect against the attacks described in...
View ArticleDirty Disks Raise New Questions About Cloud Security
During our research last year into Cloud Node security here here we identified a security vulnerability affecting some customers at Rackspace and at VPS.NET, which were two out of the four providers we...
View ArticleFramesniffing against SharePoint and LinkedIn
In this blog post, I'll describe the Frame Leak Attack technique and show how it can be used by a remote attacker to steal sensitive information from users through their web browser. I'll demonstrate...
View ArticleMalware 2 - From Infection to Persistence
In my previous posting, a malicious PDF was analysed that originated from a targeted email campaign that exposed a number of users to infection. The PDF file implemented standard exploitation...
View ArticleServer Technologies - HTTPS BEAST Attack
A number of our clients have asked for advice regarding the HTTPS BEAST attack. This blog is intended to give a more realistic overview of what the attack means to those who are concerned with the...
View ArticleMalware Analysis - Dark Comet RAT
A Remote Administration Tool (otherwise known as a RAT) is a piece of software designed to provide full access to remote clients. Capabilities often include keystroke logging, file system access and...
View ArticleServer Technologies - Reverse Proxy Bypass
In this blog I will describe a new type of security vulnerability which can allow full internal system access from the internet from an unauthenticated perspective. This technique exploits insecurely...
View ArticleSAP Exploitation – Part 2
This is the second in a series of posts about SAP infrastructure security, specifically related to RFC vulnerabilities and common misconfigurations that can be exploited by an attacker to gain...
View ArticleSAP Exploitation – Part 1
In this series of posts I aim to cover in depth some of the publically known infrastructure vulnerabilities that affect SAP systems, how to use public domain tools to test your current deployments for...
View ArticleWebGL – More WebGL Security Flaws
In this blog post Context demonstrates how to steal user data through web browsers using a vulnerability in Firefox’s implementation of WebGL. This is a continuation of our research into serious design...
View ArticleUPDATE: WebGL FAQ
Due to the high level of interest in Context’s blog posting on the Security issues within WebGL we are releasing the following further information to aid in the understanding of the issues.
View ArticleWebGL - A New Dimension for Browser Exploitation
Context is currently undergoing a research project into the new WebGL technology and have uncovered serious security flaws. WebGL provides web pages with the functionality to access the lower level...
View ArticleServer Technologies - SSL2: Should it keep you awake at night?
One of the issues Context encounters time and time again is web servers supporting version 2 of the SSL protocol. The weaknesses in SSL2 have been known for fifteen years, and could aid an attacker in...
View ArticleSmartPhones - Can you Trust your USB Charger?
Context is asked on a regular basis to evaluate the security of current mobile devices, especially smart phones, for use in the enterprise environment. Data security is of the upmost importance to our...
View ArticleServer Technologies - JBoss RMI Twiddling
Context encounters a wide range of server technologies during the course of penetration testing, often there are known vulnerabilities that can be used to exploit them, other times Context create new...
View ArticleMalware 1 - From Exploit to Infection
Context encounters numerous malware samples on a daily basis and this series of malware posts intends to provide a detailed analysis of the threats posed by malicious software that affect business...
View Article