Published: January 7, 2017
Despite the never ending proclamations of the end of memory corruption vulnerabilities, modern software continues to fall to exploits taking advantage of these bugs. Current operating systems incorporate a battery of exploit mitigations making life significantly more complex for attackers turning these bugs into attacks. Additionally, developers are becoming increasingly aware of the security implications […]
Read More
Published: January 1, 2016
Authors: Ted Harrington
The research results from our assessment of 12 healthcare facilities, 2 healthcare data facilities, 2 active medical devices from one manufacturer, and 2 web applications that remote adversaries can easily deploy attacks that target and compromise patient health. We demonstrated that a variety of deadly remote attacks were possible within these facilities, of which four […]
Read More
Published: January 12, 2013
Authors: Ted Harrington
To improve the security posture of digital systems, progressive organizations engage third party security experts to assess risk and provide hardening guidance. The most suitable approach for most industries is white box vulnerability assessment. However, confusion about different security approaches has led IT executives to commonly request the notably ineffective approach of black box penetration […]
Read More
Published: January 1, 2013
Internet of Things (IoT) devices have always been vulnerable to a variety of security issues. In 2013, Independent Security Evaluators (ISE) performed research on IoT devices that showed how rich feature sets could be leveraged to compromise devices. Today, we show that security controls put in place by device manufacturers are insufficient against attacks carried […]
Read More
Published: January 1, 2013
Authors: Jacob Thompson
July 12, 2017 Most web browsers, historically, were cautious about caching content delivered over an HTTPS connection to disk—to a greater degree than required by the HTTP standard. In recent years, in response to the increased use of HTTPS for non-sensitive data, and the proliferation of bandwidth-hungry AJAX and Web 2.0 sites, some browsers have […]
Read More
Published: January 1, 2011
Small office/home office (SOHO) routers are a staple networking appliance for millions of consumers. They are often the single point of ingress and egress from a SOHO network, manage domain name resolution, firewall protections, dynamic addressing, wireless connectivity, and of course, routing. Their heavy use in the consumer market and targeted demographic of non-computer savvy […]
Read More
Published: January 1, 2010
July 12, 2017 Analysts at ISE have identified and exploited a security vulnerability in the Android operating system allowing a remote adversary to gain control on the device with the same permissions as the web browser application. A successful attacker will have access to information such as cookies used for accessing sites, information put into […]
Read More
Published: January 1, 2008
July 12, 2017 ISE security researchers uncovered two security vulnerabilities present in the popular online games, Age of Conan and Anarchy Online. These vulnerabilities allow an attacker to read arbitrary files off of a victim’s computer, crash the games during online play, and in the case of Anarchy Online, fully compromise a victim’s machine giving […]
Read More
Published: January 1, 2007
July 12, 2017 ISE security researchers successfully discovered a vulnerability in the iPhone, developed a toolchain for working with the iPhone’s architecture (which also includes some tools from the #iphone-dev community), and created a proof-of-concept exploit capable of delivering files from the user’s iPhone to a remote attacker. UPDATE: Apple has patched the vulnerabilities we reported. UPDATE: Dr. Charlie […]
Read More
Published: January 1, 2007
July 12, 2017 ISE and outside researchers discovered an exploit for Second Life that grants control of one character to a malicious character. This allows the adversary to perform actions that may have real-world consequences such as stealing the in-game currency known as Linden dollars, or controlling the player’s machine. Update: This vulnerability was patched in QuickTime 7.3.1 […]
Read More