<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Mon, 09 Jul 2007 11:21:27 -0000</lastBuildDate><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322922</link><description>@Marcin:&lt;br&gt;&lt;br&gt;With that guarantee, it might be tricky.  Oh well, there's always the old-fashioned way of gathering free code auditing that vendors have been using for years: offending researchers with outlandish claims of having flawless security in a product and seeing what they come up with....</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">JohnGruberIsARobot</dc:creator><pubDate>Mon, 09 Jul 2007 11:21:27 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322921</link><description>@JohnGruberIsARobot:&lt;br&gt;&lt;br&gt;You can't get any better than this ;) /sarcasm&lt;br&gt;&lt;br&gt;Q: What guarantees will you give me about the reliability of the security researches listed on the market place?&lt;br&gt;A: Full guarantee. Every piece of security research is carefully analyzed and replicated in our own laboratories and eventually implemented with our own complementary research material before being placed on the market place.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Marcin</dc:creator><pubDate>Mon, 09 Jul 2007 10:55:16 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322920</link><description>Wow, judging by all the free code auditing done here and Daily Dave, it seems like vendors can get some good free auditing done just by posting a fake vuln on zeroBay and waiting til it's "reversed."</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">JohnGruberIsARobot</dc:creator><pubDate>Sat, 07 Jul 2007 15:35:43 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322919</link><description>Bee Binger I took your challenge ;)&lt;br&gt;&lt;br&gt;However gpg_ckMOD($MOD) is not of much use if it is used in this way:&lt;br&gt;&lt;br&gt;if (!isset($MOD) || !$MOD) {&lt;br&gt;   gpg_ckMOD($MOD);&lt;br&gt;}&lt;br&gt;&lt;br&gt;Therefore through gpg_pop_init.php you can include arbitrary files ;)&lt;br&gt;&lt;br&gt;The help system requires are btw. already fixed in their CVS version.&lt;br&gt;&lt;br&gt;And yes I was right through the "Decrypt Attachment" function arbitrary shell commands can be injected via the dlfilename parameter.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Stefan Esser</dc:creator><pubDate>Sat, 07 Jul 2007 09:52:30 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322918</link><description>From looking a few minutes onto the code and without a installed version of Squirrelmail I GUESS that there is some code execution through the filename of encrypted attachments.&lt;br&gt;&lt;br&gt;Atleast the very quick look lets me assume that the filename is copied into the shellcommand without escaping...&lt;br&gt;&lt;br&gt;lalalala...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Stefan Esser</dc:creator><pubDate>Fri, 06 Jul 2007 12:24:27 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322917</link><description>Not only does has that local Linux kernel memory leak vulnerability from March 2007 been assigned CVE-2007-1000, but PoC code was included in the *original* Linux Bugzilla posting, and is easily found with a moment of Googling.&lt;br&gt;&lt;br&gt;&lt;a href="http://bugzilla.kernel.org/show_bug.cgi?id=8134" rel="nofollow"&gt;http://bugzilla.kernel.org/show_bug.cgi?id=8134&lt;/a&gt;&lt;br&gt;&lt;br&gt;So some idiot might wastefully pay for that PoC code, which can be found for free, is old, likely patched and doesn't really have a high impact rating. Woohoo, that sites a great way to print Euros from recycling public domain code.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rhys Kidd</dc:creator><pubDate>Fri, 06 Jul 2007 11:52:39 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322916</link><description>grep require * | grep -i get&lt;br&gt;gpg_help.php:require_once (SM_PATH.'plugins/gpg/help/' . $_GET['help'] );&lt;br&gt;gpg_help_base.php:require_once (SM_PATH.'plugins/gpg/help/' . $_GET['help'] );&lt;br&gt;&lt;br&gt;------------&lt;br&gt;if you can break this function .. maybe a good challenge?&lt;br&gt;&lt;br&gt;function gpg_ckMOD($rMOD){&lt;br&gt;  if (strstr($rMOD, '.')&lt;br&gt;      || strstr($rMOD, '/')&lt;br&gt;      || strstr($rMOD, '%')&lt;br&gt;      || strstr($rMOD, "\\")){&lt;br&gt;    echo _("Cute.");&lt;br&gt;    exit;&lt;br&gt;  }&lt;br&gt;};&lt;br&gt;&lt;br&gt;then you would have command exec in these:&lt;br&gt;&lt;br&gt;gpg_options.php:require_once(SM_PATH."plugins/gpg/modules/$MOD.mod");&lt;br&gt;gpg_pop_init.php:require_once("modules/$MOD.mod");&lt;br&gt;&lt;br&gt;------&lt;br&gt;&lt;br&gt;$pre_pass =" $path_to_gpg --passphrase-fd 0 --armor --batch --no-tty --detach-sign --default-key $key_id&lt;br&gt;         --homedir $gpg_key_dir  $filename 2&amp;gt;&amp;amp;1";&lt;br&gt;  $cmd = "echo $passphrase|$pre_pass";&lt;br&gt;  exec($cmd,$output,$returnval);&lt;br&gt;&lt;br&gt;plus many of these user variables going to many different exec calls&lt;br&gt;&lt;br&gt;yea this is a joke .. I do not think you need stefan esser to pop these.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bee Binger</dc:creator><pubDate>Fri, 06 Jul 2007 10:51:45 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322915</link><description>@Fionnbharr:&lt;br&gt;&lt;br&gt;It is definitely true that the information isn't as directly valuable.  But knowing that something exists and what type of vulnerability definitely gives a competitive researcher a nice head start on finding the vulnerability.   If someone were selling an Apache bug, I can think of a couple of researchers who would double their efforts on Apache.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave G.</dc:creator><pubDate>Fri, 06 Jul 2007 10:17:01 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322914</link><description>That linux kernel vulnerability has a CVE #. Soooo its just an exploit for sale?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris R.</dc:creator><pubDate>Fri, 06 Jul 2007 08:10:18 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322913</link><description>But, according to the Wikipedia entry on Mr. T, "For about ten years, Mr. T was a bodyguard to the stars, protecting such well-known personalities as Muhammad Ali, Steve McQueen, Michael Jackson, Bruce Lee, Joe Frazier, and Diana Ross. He charged around $3,000 a day and his business card famously read, `Next to God, there is no greater protector than I'. He always boasts that he never lost a client, saying, `I got hurt worse growing up in the ghetto than working as a bodyguard'".&lt;br&gt;&lt;br&gt;Everybody loves Mr. T!  Come on!  You gotta love him!&lt;br&gt;&lt;br&gt;&lt;a href="http://securitybuddha.com/2007/06/28/strategy-culture-and-trendhunting/" rel="nofollow"&gt;Completely on topic&lt;/a&gt;&lt;br&gt;&lt;br&gt;Notice that I didn't even use the word "iPhone" or mention anyone by the initials "David Maynor" at all in this blog comment.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dre</dc:creator><pubDate>Fri, 06 Jul 2007 03:49:59 -0000</pubDate></item><item><title>Re: zeroBay Exists: Will The Juice Be Worth The Squeeze?</title><link>http://www.matasano.com/log/901/zerobay-exists-will-the-juice-be-worth-the-squeeze/#comment-2322912</link><description>Your post is true for smaller apps imo, but what about one of the other auctions up there now 'Local Linux kernel memory leak'. Pretty big target.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Fionnbharr Davies</dc:creator><pubDate>Fri, 06 Jul 2007 03:48:12 -0000</pubDate></item></channel></rss>