Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: World

» Topic:  Man uses networked 'crazy' toaster to hack PC

» Added by:  John Leyden

» Date:  19.12.2007

  The more paranoid among us have long been wary of the possibility that networked fridges might spontaneously turn off, perhaps after becoming infected with a computer virus, ruining milk in the process. Other networked appliances might also pose a danger of sorts, security boffins have shown.

A security expert from Check Point demonstrated at the recent ClubHACK 2007 conference in India how a networked toaster might be used to hack a computer. The party piece, carried out by Check Point's Dror Shalev, turns the more conventional use of computers in vending machines and computerised household appliances (such as DVD players) on its head.

Shalev said he developed the networked toaster hack in response to a statement from a senior scientist from Google that there was no need to be afraid of a toaster at home. "But as a hacker, I came up with a toaster that could actually hack a computer," Shalev explained. "I call it a ‘Crazy Toaster'."

Details on Shalev's quixotic hack are sparse, but it is said to involve the development of software that interacted with a networked toaster. "As soon as the toaster is plugged (in), the software is activated before it breaks into the user’s computer system. The same software prototype can be networked with any home appliance for stealing the Web secrets," Shalev said. "With wireless technology available, there is no need for connecting the appliance with the computer," he chillingly added.

Shalev said the hack demonstrated that users should avoid blindly trusting any networked device, even a toaster. "As the usage of computers and the internet goes up, we will need to be cautious about every object in our surroundings," he warned.

In the future, people should purchase home appliances only from trusted outlets, he advised. "If an appliance or home device comes as a gift, accept it only if it is from someone you trust," Shalev noted, we suspect shortly before retiring to his private bunker somewhere on the outskirts of the Negev desert.

Source : http://www.theregister.co.uk/



Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

» Apache-SSL memory
   disclosure

PHP rss

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

» PHP 5.2.5 cURL safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.