Posts
2585
Following
629
Followers
1404
"I'm interested in all kinds of astronomy."
repeated

It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”

https://palant.info/2024/07/15/how-insecure-is-avast-secure-browser/

Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.

TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.

Some highlights:

  • Eleven pre-installed browser extensions but only two visible to users.
  • Two extensions unnecessarily relax Content-Security-Policy protection.
  • One of these two extensions also requesting all privileges possible, despite not actually using them.
  • Two extensions accept messages from any other extension and any Avast website, the latter without enforcing HTTPS connections.
  • One of these extensions, Privacy Guard (sic!), will expose information about your browser’s tabs via that messaging interface and provide updates as you browse the web.
  • The “onboarding” experience is designed as an extremely flexible way to nag you into using products that benefit Avast financially.
  • To make this “onboarding” work, the browser exposes internal APIs to a number of Avast domains that a huge number of third parties can put content on. Not only can each of these third parties abuse this access, a single XSS vulnerability will extend the access to any website on the internet (no effective CSP protection).

Enjoy!

2
5
0
repeated
[RSS] Linksys Velop Routers Caught Sending WiFi Creds in the Clear

https://hackaday.com/2024/07/15/linksys-velop-routers-caught-sending-wifi-creds-in-the-clear/
0
3
1
repeated

We love Open Source contributors.

If you are a significant contributor to an Open Source project, DM us, and we will give you a full briefings pass to BlackHat USA (absolutely free).

__
* Tickets handed out totally at our discretion;
** We only have a few tickets left;

0
3
0
repeated

fq 0.12.0 released 🥳 nothing fancy, REPL and jpeg fixes otherwise mostly update of dependencies.

https://github.com/wader/fq/releases/tag/v0.12.0

0
2
0
[oss-security] backtrace_symbols() misuse by Ceph and its supposedly-safe use

Interesting thread on safe crash handling in the light of signal handler races

https://www.openwall.com/lists/oss-security/2024/07/12/1
0
1
2
[RSS] [Internet Bug Bounty] high - important: Apache HTTP Server on WIndows UNC SSRF (CVE-2024-38472) (4920.00USD)

https://hackerone.com/reports/2585385
0
0
0
[RSS] [Internet Bug Bounty] high - important: Apache HTTP Server weakness with encoded question marks in backreferences (CVE-2024-38474) (4920.00USD)

https://hackerone.com/reports/2585381

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
0
0
0
[RSS] Resurrecting a dead Dune RTS game

https://wheybags.com/blog/emperor.html
0
7
7
repeated

Spent the last four days coordinating incident response for the Squarespace domain hijackings with @tay and @AndrewMohawk. Now that it seems to be resolved, we wrote a little postmortem/retrospective

https://securityalliance.notion.site/A-Squarespace-Retrospective-or-How-to-Coordinate-an-Industry-Wide-Incident-Response-fead693b66c14543a48283d85aec19ad

1
3
0
repeated

Starting from v0.10 (the next version), HyperDbg uses @keystone_engine as its assembler. ❤️

Thanks to our new team member @AbbasMasoumiG for adding it.

The following commands are added to assemble virtual and physical memory:

- https://docs.hyperdbg.org/commands/debugging-commands/a

- https://docs.hyperdbg.org/commands/extension-commands/a

1
1
1
repeated

Clever & fun technique to dump LSA secrets bypassing by @sensepost

Dumping LSA secrets: a story about task decorrelation

https://sensepost.com/blog/2024/dumping-lsa-secrets-a-story-about-task-decorrelation/

0
5
1
I almost felt guilty finding out the guy accidentally gave me two of these "original palestinian" scarves instead of one
0
0
2
[RSS] SSD Advisory – SonicWall SMA100 Stored XSS to RCE

https://ssd-disclosure.com/ssd-advisory-sonicwall-sma100-stored-xss-to-rce/
0
1
1
repeated

Introduction to the Wild West of Proof of Concept Code () aka SSHing the Masses

https://santandersecurityresearch.github.io/blog/sshing_the_masses.html

1
2
0
repeated
Edited 9 months ago
4
20
4
repeated

Everyone complains about meetings, but rarely anybody puts time before the meeting to do the work needed for the meeting to be useful.

6
2
1
Show older