EnCase Forensic Imager buffer overflow vulnerability
Автор: SEC Consult
Загружено: 2017-05-11
Просмотров: 5949
Описание:
Guidance Software EnCase Forensic Imager is used by computer forensic experts to gather evidence from storage media. Due to a buffer overflow flaw in this product an attacker can manipulate a storage medium to execute arbitrary malicious code on the investigator's machine.
A series of ROP chains ultimately lead to a meterpreter reverse shell that connects to the attacker's computer. From there, the attacker deploys an FTP server as an example (arbitrary code can be executed) and forwards the necessary ports to his local machine. An FTP client can then be used to conveniently browse the investigator's machine.
A more detailed description can be found here:
Technical advisory:
https://www.sec-consult.com/fxdata/se...
Blog post:
http://blog.sec-consult.com/2017/05/c...
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SEC Consult Vulnerability Lab
SEC Consult
Bangkok - Berlin - Linz - Luxembourg - Montreal - Moscow
Kuala Lumpur - Singapore - Vienna (HQ) - Vilnius - Zurich
About SEC Consult Vulnerability Lab
The SEC Consult Vulnerability Lab is an integrated part of SEC Consult. It ensures the continued knowledge gain of SEC Consult in the field of network and application security to stay ahead of the attacker. The SEC Consult Vulnerability Lab supports high-quality penetration testing and the evaluation of new offensive and defensive technologies for our customers. Hence our customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Interested to work with the experts of SEC Consult?
Send us your application https://www.sec-consult.com/en/Career...
Interested in improving your cyber security with the experts of SEC Consult?
Contact our local offices https://www.sec-consult.com/en/About/...
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Mail: research at sec-consult dot com
Web: https://www.sec-consult.com
Blog: http://blog.sec-consult.com
Twitter: / sec_consult
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: