Latest YouTube Video

Wednesday, May 13, 2015

[FD] Multiple Vulnerabilities in Openlitespeed <= 1.3.10 - CVE-b045-73d a.k.a. Analbleed.

This is an irresponsible disclosure of the vulnerability, which will bring large parts of the Internet into its knees - CVE-b045-73d a.k.a Analbleed. Obviously you can find the fancy logo for it below (officially approved by the security community and industry worldwide). You can also listen to the O.S.T. on the vuln's official website free of charge (as for now) here at http://analbleed.com. If you are interested in purchasing t-shirts, cups, stickers etc. visit our on-line shop on the same page. Special offer includes also a vademecum treating about all logo branded vulns released so far. You can now focus on studying their names, logos and more instead of actually doing your own research. Knowing life the logo formatting will break;P But not to worry my friend. Visit the official web page to please your eyes with it. http://ift.tt/1Pkdlzn.: May 2013 : It is used by 2% of all websites according to W3Techs,[9] making it the 4th most popular web servers. Yup, whatever. Please, think of the kittens - http://ift.tt/Ygd84T Ok, here comes the Analbleed pain... +` `+++, .+++++: :+++++++' ++++++++++' +++++++++++++ +++++++++++++++ +++++++++++++++++ +++++++++++++++++++ +++++++++++++++++++++ +++++++++++++++++++++++ +++++++++++++++++++++++++` `+++++++++++++++++++++++++++, `+++++++++++++++++++++++++++++. .+++++++++++++++++++++++++++++++: :++++++++++++++++ ++++++++++++++++: ;++++++++++++++++ ++++++++++++++++; '++++++++++++++++ ++++++++++++++++; +++++++++++++++++ ++++++++++++++++; +++++++++++++++++ ++++++++++++++++' +++++++++++++++++ '+++++++++++++++' ++++++++++++++++' '+++++++++++++++' ++++++++++++++++: :+++++++++++++++' `++++++++++++++++, ,++++++++++++++++ `++++++++++++++++` `++++++++++++++++ ,++++++++++++++++ ++++++++++++++++ ,++++++++++++++++ `,,` ++++++++++++++++ ,++++++++++++++++ :++++++' ++++++++++++++++ ,++++++++++++++++ ++++++++++` ++++++++++++++++ :++++++++++++++++ +++++++++++' ++++++++++++++++ ,++++++++++++++++ ,++++++++++++. ++++++++++++++++ ,++++++++++++++++ +++++++++++++: ++++++++++++++++ ,++++++++++++++++ ;+++++++++++++: ++++++++++++++++ `++++++++++++++++ ++++++++++++++. '+++++++++++++++ `+++++++++++++++' +++++++++++++' '+++++++++++++++ +++++++++++++++' :+++++++++++++` '+++++++++++++++ +++++++++++++++' ++++++++++++: '+++++++++++++++ +++++++++++++++' ++++++++++` '+++++++++++++++ +++++++++++++++' ++++++++++ '+++++++++++++++ +++++++++++++++' ++++++++++ '+++++++++++++++ '++++++++++++++' `++++++++++ '+++++++++++++++ :+++++++++++++++ ,+++++++++; '++++++++++++++: `+++++++++++++++ ;+++++++++. +++++++++++++++` +++++++++++++++ '+++++++++` +++++++++++++++ +++++++++++++++ '+++++++++` +++++++++++++++ '++++++++++++++ ++++++++++ +++++++++++++++ .++++++++++++++ ++++++++++ ++++++++++++++. ++++++++++++++` ++++++++++ ++++++++++++++ ++++++++++++++: ++++++++++ ,++++++++++++++ .+++++++++++++' ++++++++++ '+++++++++++++, ++++++++++++++ ++++++++++ ++++++++++++++ '+++++++++++++ ++++++++++ ++++++++++++++ +++++++++++++` ++++++++++` +++++++++++++ +++++++++++++' '+++++++++` '+++++++++++++ +++++++++++++ '+++++++++` +++++++++++++` +++++++++++++ ;+++++++++. +++++++++++++ ++++++++++++' ,+++++++++, '++++++++++++ +++++++++++++ `+++++++++; +++++++++++++ ++++++++++++, `++++++++++ ,++++++++++++ `++++++++++++ ++++++++++ ++++++++++++, ++++++++++++, ++++++++++ .++++++++++++ ++++++++++++ ++++++++++ ++++++++++++ +++++++++++' ++++++++++` '+++++++++++ .+++++++++++ '+++++++++: +++++++++++. ;+++++++++++ .++++++++++ +++++++++++; ++++++++++++ ++++++++++ ++++++++++++ ++++++++++++ ++++++++++ ++++++++++++ +++++++++++; ++++++++++. ;+++++++++++ +++++++++++, '+++++++++' ,+++++++++++ +++++++++++, .++++++++++ .+++++++++++ +++++++++++. ++++++++++ .+++++++++++ +++++++++++. ++++++++++' .+++++++++++ +++++++++++, ;++++++++++ .+++++++++++ +++++++++++; `+++++++++++ :+++++++++++ ++++++++++++ ++++++++++++ ++++++++++++ ++++++++++++ '+++++++++++, ++++++++++++ ;+++++++++++ ++++++++++++ +++++++++++; .+++++++++++ +++++++++++++ +++++++++++. +++++++++++' +++++++++++++++ '+++++++++++ ++++++++++++ +++++++++++++++++ ++++++++++++ ++++++++++++: +++++++++++++++++++ ,++++++++++++ `++++++++++++ +++++++++++++++++++++ ++++++++++++. +++++++++++++ .+++++++++++++++++++++++, +++++++++++++ '++++++++++++' '+++++++++++++++++++++++++' '+++++++++++++ ++++++++++++++ +++++++++++++++++++++++++++++ '+++++++++++++ +++++++++++++++ '++++++++++++++++++++++++++++++++ +++++++++++++++ ++++++++++++++++ '+++++++++++++++++++++++++++++++++++' '+++++++++++++++ '+++++++++++++++++` `++++++++++++++++++++`++++++++++++++++++++. `+++++++++++++++++' ++++++++++++++++++++',...,+++++++++++++++++++++++ +++++++++++++++++++++++,...,'++++++++++++++++++++ +++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++++++++++++++ `+++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++++++++++++. ,+++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++++: ,++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++++++++++, +++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++++++++++++++++++++++` ++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++++++++ ,++++++++++++++++++++++++++++++++++++++ +++++++;+++++++++++++++++++++++++++++++, ;+++++++++++++++++++++++++++'++++++++ +++++++ '+++++++++++++++++++++++++++; :+++++++++++++++++++++++: ++++++++ +++++++ :+++++++++++++++++++++++: '+++++++++++++++++++ ++++++++ +++++++ '+++++++++++++++++' .;+++++++++;` +++ ++++++++ +++++++ `;+++++++++'. +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ +++ ++++++++ +++++++ +++ ++++++++ +++++++ +++ ++++++++ +++++++ +++ ++++++++ +++++++ +++ ++++++++ +++++++ +++ ++++++++ +++++++ +++ ++++++++ +++++++ +++ ++++++++ +++++++ +++ +++++++ +++++++ +++ ++++++ +++++++ +++ + +++++++ +++ +++++++ +++ +++++++ +++ +++++++ +++ +++++++ ++ +++++++ +++++++ +++++++ +++++++ +++++++ ++++++ ++++++ ++++ Bigger the better. Don't you think? source: ======= int Appender::append(LoggingEvent *pEvent) { char achBuf[9000]; char *pMessage = achBuf; int len; if (!pEvent) return -1; Layout *pLayout; if (pEvent->m_pLayout) pLayout = pEvent->m_pLayout; else pLayout = m_pLayout; ; this path is taken, m_pLayout is on overwritten heap if (pLayout) len = pLayout->format(pEvent, pMessage, sizeof(achBuf)); ; SIGSEGV here else { pMessage = (char *)pEvent->m_pMessageBuf; len = pEvent->m_iMessageLen; } return append(pMessage, len); } gdb (aftermath): ================ Program received signal SIGSEGV, Segmentation fault.

Source: Gmail -> IFTTT-> Blogger

No comments: