<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title> TEHTRIS obtient le label France Cybersecurity pour son produit eGambit </title><description>2015-10-19 15:23:51 - TEHTRI Security RSS :   FR  Le 16 Octobre 2015, lors d'une cérémonie officielle présidée par le Directeur Général de l'ANSSI, qui termina la journée présentant la Stratégie Nationale pour la Sécurité du Numérique, TEHTRI-Security a obtenu le label France Cybersecurity pour son produit eGambit Ce label est la garantie pour les utilisateurs, que les produits et services associés, sont français et qu ils possèdent des fonctionnalités claires et bien définies, avec un niveau de qualité vérifié par un jury indépendant Sur 2015, le produit eGambit protège des infrastructures en France, en Europe, aux USA, en Chine, au Moyen-Orient et au Brésil, scrutant la moindre trace d'activité de cyber-espionnage en 24 24 7 7, et alertant les SOC CSIRT et les experts concernés </description><link>http://www.secuobs.com/revue/news/587218.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587218.shtml</guid></item>
<item><title> Label UBfriendly obtenu avec l'Université de Bordeaux</title><description>Secuobs.com : 2015-07-07 17:29:43 - TEHTRI Security RSS -   FR  La société TEHTRI-Security obtient le label UB Friendly auprès de l'Université de Bordeaux Ce label valorise les entreprises qui s'engagent aux côtés de l'Université Depuis notre installation en 2013 sur Pessac, notre société a encadré 12 stages sur des projets de recherche et d'innovation technologique Des tournois de hacking numérique furent aussi une très bonne occasion de rencontrer les étudiants intéressés par les métiers de la sécurité informatique TEHTRI-Security fait partie de cet écosystème des partenaires de l'Université de Bordeaux, qui affiche une vraie dynamique laissant entrevoir un avenir constructif </description><link>http://www.secuobs.com/revue/news/576392.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/576392.shtml</guid></item>
<item><title>  FR  1 Million de binaires Windows pour eGambit cette semaine </title><description>Secuobs.com : 2015-06-10 01:31:03 - TEHTRI Security RSS - Nos geeks du SOC CSIRT TEHTRIS ont analysé un million de binaires cette semaine Venez donc lire les informations complémentaires sur le lien proposé, si vous aussi vous souhaitez éviter les intrusions, infections, déplacements latéraux et autres soucis de sécurité dans vos machines Windows </description><link>http://www.secuobs.com/revue/news/573517.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/573517.shtml</guid></item>
<item><title> eGambit version 30 </title><description>Secuobs.com : 2015-04-08 10:16:59 - TEHTRI Security RSS - Our product called eGambit can monitor and improve your IT Security against complex threats like cyber-spy activities Last 3 years, eGambit caught billions of events related to security issues worldwide, in USA, Brazil, China and Europe Thanks to the tremendous skill and motivation of our consultants working on eGambit, the new version 30 is available for our partners, ready to fight This includes incredible features, like a Windows HIPS to identify and strike back against APT, a Web honeypot that might identify the real IP address of attackers using bounces, etc Yes, we did it  eGambit is definitely your defensive cyber-weapon system </description><link>http://www.secuobs.com/revue/news/566443.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566443.shtml</guid></item>
<item><title> NXLog   TEHTRI-Security   Partnership </title><description>Secuobs.com : 2015-03-23 16:29:53 - TEHTRI Security RSS - Our consultants at TEHTRI-Security recommend using NXLog Community Edition  NXLog CE , or NXLog Enterprise Edition  NXLog EE , as the preferred log collector to interact with our product called eGambit We've been using NXLog CE EE for a long a time, with tremendous technical results Before mid-2014, NXLog was already integrated in eGambit Now in 2015, NXLog and TEHTRI-Security will be partners around these security concepts For all TEHTRI-Security partners and customers, this implies that a move to NXLog technologies is highly suggested Direct help or support can be organized with NXLog or with TEHTRIS over eGambit Beyond the fact that NXLog is an awesome multiplatform log collector, there are many reasons why this is the preferred solution to interact with eGambit We have access to the source code, meaning that we can read and analyze or work easily around it The quality of the code is excellent, as you can check by yourself at least with the opensource NXLog Community Edition On top of this, NXLog have many strengths like high-performance i o, support of secure protocols, internationalization, real-time event classification, MS Windows family supported, etc So now, join us, and let's hunt evil attackers through your logs and beyond, by combining the powers of NXLog and eGambit </description><link>http://www.secuobs.com/revue/news/564511.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564511.shtml</guid></item>
<item><title> Security Advisory - Vulnerability on Twitter  spoof tweets on any account </title><description>Secuobs.com : 2015-01-23 11:13:12 - TEHTRI Security RSS -  We found a 0day on Twitter platform, allowing to do a kind of tweet spoofing against any account We sent an advisory, where we made a demonstration, showing that we could generate a kind of fake tweet on any already existing twitter account Though it's not that critical, we believe that this bird spoofing issue could be used by attackers in order to generate massive phishing attacks, or deception attacks with fake information, fake links, etc We will keep you updated </description><link>http://www.secuobs.com/revue/news/556265.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/556265.shtml</guid></item>
<item><title> New trends with SSH attacks found by eGambit </title><description>Secuobs.com : 2015-01-09 16:39:01 - TEHTRI Security RSS -  We recently detected new behaviors and methods used to attack SSH services This emphasizes the fact that even well-known services or protocols can still be sources of inspiration in order to commit new forms of cybercrime This improves the speed of their interactions Nothing is new in the protocol method, but this is a new trend currently Our honeypots recorded the full contents of their attack sessions This will help at digging on these logs  countries, IP addresses, methods, tools caught, etc Thanks to eGambit, in some situations, we already got the real IP address of attackers in 2014 Sometimes, we were able to steal tools of the attackers Life is SSHort Play harder </description><link>http://www.secuobs.com/revue/news/553829.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/553829.shtml</guid></item>
<item><title> Security Advisory - 0day in Rockwell Automation </title><description>Secuobs.com : 2014-12-30 16:52:10 - TEHTRI Security RSS -  We found 0days in Rockwell Automation products  Allen-Bradley  They allow a remote attacker to do evil actions against the device and its environment These products are usually found in environments like Industrial Computing, SCADA, etc Like many other security people, we do believe that IT in the industrial world is quite easy to penetrate, and that such intrusions would lead to catastrophic situations for States or big companies, with potential impacts on real life in the worst case </description><link>http://www.secuobs.com/revue/news/552369.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/552369.shtml</guid></item>
<item><title> Security Advisory - 0day in ThreatStream MHN </title><description>Secuobs.com : 2014-08-13 10:57:17 - TEHTRI Security RSS -  We found 0days in the product by ThreatStream called Modern Honeypot Network This allows a remote attacker using a CSRF technique, to do illegal actions on the global frontend of the honeypots An attacker can for example  add an administrator, modify the password of an administrator, delete the current administrators, etc After that, an attacker can have a global control of the honeypot fleet In some cases, it can allows to get a control on systems running honeypots  remote shell  The vendor and the US CERT were contacted There will be no CVE and no security bulletin by the US CERT </description><link>http://www.secuobs.com/revue/news/529676.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/529676.shtml</guid></item>
<item><title> Opensource Honeypots are insecure </title><description>Secuobs.com : 2014-08-12 01:54:59 - TEHTRI Security RSS -  We recently discovered many vulnerabilities on opensource honeypots allowing remote attackers to grab illegal information or to guess that a honeypot is running or to do illegal stuff This shows that opensource honeypots are a tremendous contributions for science, in order to learn computer security, etc But, opensource honeypots are not built to survive against skilled attackers It's always funny to see that with some search engines, we were able to find tons of honeypots IP addresses If you need statistics just for fun to play with hackers, then opensource honeypots are a good idea  but be careful  If you need to improve the security of your infrastructure, against real attackers, not just worms, etc, then you need real products More than 10 years ago, we gave many demonstrations about how to defeat honeypots Most of our advices are forgotten, and it's still easy to play against these kind of tools </description><link>http://www.secuobs.com/revue/news/529358.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/529358.shtml</guid></item>
<item><title> Cleaning and modifying our web site </title><description>Secuobs.com : 2014-07-22 20:57:34 - TEHTRI Security RSS -  Our web site remained almost the same for around 4 years, as we had no spare time to improve it Of course, we are not experts for marketing We just focus on our main goals  helping our customers to fight against attackers and threats It was time to clean our web site and to change the design a little bit </description><link>http://www.secuobs.com/revue/news/526432.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/526432.shtml</guid></item>
<item><title> Sponsoring grsecurity to celebrate a decade of deployment </title><description>Secuobs.com : 2012-12-27 17:42:35 - TEHTRI Security RSS -  For more than 10 years, our consultant used the power of grsecurity and PaX projects, created by genius geeks They provide real protection against zero-days threats thanks to containment, detection, RBAC, etc Most of the time, they have technical solutions years before they get  poorly  copied by commercial vendors We wanted to celebrate more than 10 years of re-compilation of Linux Kernels with grsecurity, and decided to sponsor this tremendous opensource activity, sharing tools and experience to harden your systems Long life to this project </description><link>http://www.secuobs.com/revue/news/418892.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/418892.shtml</guid></item>
<item><title> Security Advisory - 0day in Phraseanet Product  Remote Control</title><description>Secuobs.com : 2012-11-09 23:37:11 - TEHTRI Security RSS -  During a penetration test, TEHTRI-Security found remote vulnerabilities on Phraseanet This product is a complete answer to all kind of organizations that need to manage and distribute digital assets It is built with standard open source components, and the dev team quickly created security patches that would help at avoiding cyber-attacks You should upgrade to version 373 available on GitHub and Sourceforge if you want to get rid of these security issues Public exploits will not be shared because Phraseanet is widely used by big worldwide and national entities such as administrations, industry, TV channels, etc These 0days were remote pre-authenticated exploits with multiple sharp privilege escalations to finish with a remote control of the box We noticed the high quality and speed of the developpers to propose a security patch, compared to some non-opensource products </description><link>http://www.secuobs.com/revue/news/410675.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/410675.shtml</guid></item>
<item><title> Security Advisory - 0day in Vormetric Product  Local Priv Escalation </title><description>Secuobs.com : 2012-09-05 11:57:10 - TEHTRI Security RSS - TEHTRI-Security found a UNIX security issue on Vormetric 441 during a pentest in May 2012 This vulnerability was silently fixed in version 5 The local user nobody could become root because of local flaws in the product  permissions issues on secfsd  Vormetric Data Security allows enterprises to encrypt sensitive data, control access to that information, and report on who is accessing the protected data If you are not sure about the local security of your Vormetric installation, have a full security check in your vormetric DataSecurityExpert agent  directory BTW, We do believe that all vendors should ask for penetration tests and security assessments on their products, with IT Security experts who regularly find dangerous security bugs </description><link>http://www.secuobs.com/revue/news/397697.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/397697.shtml</guid></item>
<item><title> Security Advisory - 0days in McAfee EMM product  OTP</title><description>Secuobs.com : 2012-03-23 11:27:58 - TEHTRI Security RSS - McAfee Security Bulletin SB10021  During a penetration test, TEHTRI-Security created 0days against McAfee EMMPortal products When using McAfee EMM in OTP mode, a provisioning user must provide a one-time provisioning token In order to simplify this process for a user, the EMM administrator can provide an EMM user with a clickable URL that launches the McAfee EMM Agent and limits the amount of data a user must type into the device Due to the vulnerabilities of DNS SRV records upon which EMM depends for simplifying the user provisioning process, an attacker could retrieve a password of a user through a combination social engineering and fake EMM server attack McAfee EMM users should be cognizant of social engineering attacks and should avoid going to unknown sites The EMM Portal service through which these invalid authentication credentials are recorded should be protected via a web application firewall The AuthorizationFailure table within the EMM database can be monitored and truncated if an excessive number of rows are encountered McAfee EMM Agent 47 and earlier are affected McAfee recommends that all customers verify that they have applied the latest updates </description><link>http://www.secuobs.com/revue/news/365646.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/365646.shtml</guid></item>
<item><title> About Mobile Device Management and Security</title><description>Secuobs.com : 2012-03-23 11:27:58 - TEHTRI Security RSS - According to TEHTRI-Security, like most IT products, many Mobile Device Management products are not hardened properly, because big companies do not want to hire real external pentesters, that would be skilled enough to lay down 0days and pown their tools We are all vulnerable Most IT Products are not analyzed properly Economic crisis perhaps changed some rules, and vendors sadly do not have enough ressources to outsource this kind of analysis This kind of behaviours will definitely help the gurus from the dark side Hopefully, some vendors are able to create patches and remediation really quickly, which reduces the size of the surface of attack Live and let die </description><link>http://www.secuobs.com/revue/news/365645.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/365645.shtml</guid></item>
<item><title> Gmail App Security Issues on iPhone iPad iPod </title><description>Secuobs.com : 2012-01-28 11:42:41 - TEHTRI Security RSS -  TEHTRIS published humble thoughts related to vulnerabilities of Gmail App for iPhone iPad iPod Emails, contacts, etc, are cached in cleartext on the i-device Moreover, authentication data, like some famous cookies, are not stored through secure Keychains capabilities, which can lead to Gmail hijacking issues Read our blog for more information By the way, many applications from the Apple Store are vulnerable </description><link>http://www.secuobs.com/revue/news/354604.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/354604.shtml</guid></item>
<item><title> CERT VU 584363  Zenprise Device Manager CSRF   Powning a GSM fleet </title><description>Secuobs.com : 2011-11-21 18:21:06 - TEHTRI Security RSS -  The US-CERT released a vulnerability note VU 584363 explaining that the Zenprise Device Manager software is susceptible to a cross-site request forgery  CSRF  vulnerability that may result in the compromise of the fleet of mobile devices managed by the product Thanks to our exploits, a skilled attacker could get the control of a complete fleet of iPad, BlackBerry, Android, iPhones, Windows Mobile, Symbian, etc Some of our exploits could lead to a shred of the whole fleet of devices Others could help at spying on the end-users of these phones and tablets According to TEHTRI-Security, many big companies using Mobile Device Management tools could be attacked through these kind of vectors, because of lack of technical skilled penetration tests </description><link>http://www.secuobs.com/revue/news/341796.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/341796.shtml</guid></item>
<item><title> CVE-2011-3434  Our vuln was patched by Apple - iOS 5 Software update </title><description>Secuobs.com : 2011-10-13 10:28:28 - TEHTRI Security RSS -  TEHTRI-Security found a vulnerability on iPod iPhone iPad  CVE-2011-3434  Indeed, WiFi credentials were logged to a local file, including passphrases and encryption keys This was readable by applications on the system Apple resolved this problem by avoiding logging these credentials You should definitely update your devices This patch is available for iOS 30 through 435 for iPhone 3GS and iPhone 4, iOS 31 through 435 for iPod touch  3rd generation  and later, iOS 32 through 435 for iPad We only shared complete issues with Apple support Some details were shared with our attendees of SyScan Singapore 2011 and HITB Amsterdam 2011 If you want more 0days and exploits, you should definitely register to our next trainings  BlackHat AD, HITB India, etc  </description><link>http://www.secuobs.com/revue/news/334516.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/334516.shtml</guid></item>
<item><title> SPIP recently fixed 2 vulnerabilities notified by Tehtri-Security  0day  </title><description>Secuobs.com : 2011-10-01 12:18:10 - TEHTRI Security RSS -  Our CTO, Laurent ESTIEUX, discovered two vulnerabilities in a well-known CMS product named SPIP   a local path disclosure  all SPIP version    an SQL injection  SPIP 192 branch  As Tehtri-Security is engaged in a responsible disclosure policy, technical information were notified to the SPIP-Team for fixes SPIP is now patched and latest version can be downloaded at http wwwspipnet en_article5265html </description><link>http://www.secuobs.com/revue/news/332123.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/332123.shtml</guid></item>
<item><title> New Event HITBGSEC 2012   New Training about Strategic Cyber Attacks </title><description>Secuobs.com : 2011-09-22 12:08:28 - TEHTRI Security RSS -  Join us at the India's Premier Global IT Security Conference next year This will definitely be the place to be with some of the most influential thinkers in the security industry and India's leading CxO's There, we will give a tremendous new training, called  Strategic cyber attacks, Advanced Persistent Threats and beyond  This will be the time to show and explain why every sensitive places get hacked in this cyber world, and how attackers work to steal data or destroy infrastructures More information in the future Stay tuned </description><link>http://www.secuobs.com/revue/news/330355.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/330355.shtml</guid></item>
<item><title> 0days found in software used by banks, telcos, military, airports </title><description>Secuobs.com : 2011-09-20 20:25:16 - TEHTRI Security RSS -  During a penetration test, TEHTRI-Security found local and remote security issues in a product that is currently used to ensure 24x7 availabity and load balancing for military applications, as well as high availability in airports for air traffic control, plus banking or medical services, etc As we created 0days that could be used to attack all those networks, we directly contacted the vendor to improve the security of their customers With our exploits, the final effect could be a remote admin access on the infrastructure </description><link>http://www.secuobs.com/revue/news/329996.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/329996.shtml</guid></item>
<item><title> Mobile Device Management Vulnerabilities  0days  </title><description>Secuobs.com : 2011-09-13 15:01:43 - TEHTRI Security RSS -  To handle the awesome use of smartphones, large-scale companies and organizations came to MDM, Mobile Device Management This allows to manage, to monitor and to secure a mobile fleet  more or less easily  Troubles might happen when remote attackers get an illegal access on the MDM, as this could lead to opportunities like locating employees, wiping phones tablets, stealing data, etc We recently discovered multiple vulnerabilities  0days  in some MDM clients and servers To give an example, we found security flaws on iPhone iPad clients, and on control panel of some MDM products  stealing remote credentials, XSRF, LDAP injection, remote wipe of the entire fleet, network protocol issues, etc  We strongly recommend to launch advanced technical penetration tests and to create an architecture that might apply containment and detection to follow potential future intruders </description><link>http://www.secuobs.com/revue/news/328536.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/328536.shtml</guid></item>
<item><title> Facebook Security Issues through HTML Iframes </title><description>Secuobs.com : 2011-09-12 16:02:24 - TEHTRI Security RSS -  Evil Facebook users could craft special web pages on facebookcom  in order to abuse some end-users, thanks to the use of Iframe loading external web resources This could potentially lead to privacy issues, phishing attempts, XSS CSRF and client-side attacks We shared humble demonstrations as a proof of concepts </description><link>http://www.secuobs.com/revue/news/328351.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/328351.shtml</guid></item>
<item><title> Facebook silently fixed our vulnerability shown at HITB Amsterdam 2011 </title><description>Secuobs.com : 2011-08-21 14:23:05 - TEHTRI Security RSS -  We recently discovered that Facebook patched its iPhone App without sharing any credit and without any advisory They just silently fixed a vulnerability found by TEHTRI-Security This one was only shared with the attendees during our talk at HITB Amsterdam 2011 And the proof of concept was only shared with Facebook and Apple support Apple recently told us that the vulnerability was fixed by Facebook around July This does explains why we had no news from Facebook Disclose or not disclose, that's not a question, anymore </description><link>http://www.secuobs.com/revue/news/324312.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/324312.shtml</guid></item>
<item><title> GooglePlus Reader Privacy Issue </title><description>Secuobs.com : 2011-08-13 21:25:38 - TEHTRI Security RSS -  Some Google Plus readers might reveal technical information and IP addresses while reading specially crafted G  profiles with malicious behaviors This could be used to commit targetted attacks against some G  end users or to track them More information on our blog </description><link>http://www.secuobs.com/revue/news/322951.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/322951.shtml</guid></item>
<item><title> TEHTRI-Security slides from HITB Amsterdam 2011 </title><description>Secuobs.com : 2011-05-19 16:59:06 - TEHTRI Security RSS -  Our slides from HITB Amsterdam 2011 are now available on HITB web site We gave examples of new concepts of attacks in the iPhone world For example we explained how fishing attacks could be done with telephone calls, and how to hijack a local application of the iPhone  with a demo where we have stolen the Facebook password, or Twitter or Paypal  We also played with new fuzzing possibilities that helped at crashing some applications  FaceBook, Twitter  Finally, we gave a proof of concept to do a remote detection of a jailbroken device We got many positive feedbacks and questions by emails, etc </description><link>http://www.secuobs.com/revue/news/305895.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/305895.shtml</guid></item>
<item><title> TEHTRI-Security slides from SyScan Singapore 2011 </title><description>Secuobs.com : 2011-04-29 16:22:26 - TEHTRI Security RSS -  Feel free to read our slides from SyScan Singapore 2011 It's all about hacking stuff like web clients, smartphones, etc We also explained our tricks to hack the famous iPhone file, called consolidateddb thanks to TRIGGERS, which is now used by other researchers </description><link>http://www.secuobs.com/revue/news/301613.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/301613.shtml</guid></item>
<item><title> Disable iPhone Tracking with SQL TRIGGERS in consolidateddb </title><description>Secuobs.com : 2011-04-25 22:38:15 - TEHTRI Security RSS -  Quick notes related to iPhone location tracking and how to hack the infamous consolidateddb file thanks to SQL TRIGGERS injected inside it More information available through our Blog Join us at SyScan Singapore this week, or at HITB Europe next month </description><link>http://www.secuobs.com/revue/news/300678.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/300678.shtml</guid></item>
<item><title> Check the security of your BlackBerry </title><description>Secuobs.com : 2011-03-19 12:05:14 - TEHTRI Security RSS -  Come and try our quick security checker for your BlackBerry device Just point your BlackBerry browser to http tehtriscom bbcheck and read the results More information available through our Blog </description><link>http://www.secuobs.com/revue/news/292788.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/292788.shtml</guid></item>
<item><title> About iPhone iOS 43 Personal Hotspot </title><description>Secuobs.com : 2011-03-07 12:55:08 - TEHTRI Security RSS -  Tiny security advisory plus technical thoughts related to a quick test made with the iPhone iOS 43 that should be available soon </description><link>http://www.secuobs.com/revue/news/289833.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/289833.shtml</guid></item>
<item><title> Slides from our latest talk  BlackHat DC 2011  available   Inglourious Hackerds, targeting web clients </title><description>Secuobs.com : 2011-01-23 13:51:34 - TEHTRI Security RSS - Read the very latest version of our slides from our talk at BlackHat DC 2011, dealing with attacks against web clients, especially RIM, Apple, HTC and Google stuff, but not only </description><link>http://www.secuobs.com/revue/news/280181.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/280181.shtml</guid></item>
<item><title> NetworkWorldcom  Mobile device makers react differently to attack info, researcher says </title><description>Secuobs.com : 2011-01-21 15:18:32 - TEHTRI Security RSS - NetworkWorld  new article dealing with TEHTRI-Security talk at BlackHat Washington DC,  Inglourious Hackerds, Targeting Web Clients  </description><link>http://www.secuobs.com/revue/news/279886.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/279886.shtml</guid></item>
<item><title> NetworkWorldcom  Is retaliation the answer to cyber attacks  </title><description>Secuobs.com : 2011-01-21 15:18:32 - TEHTRI Security RSS -  NetworkWorld  new article dealing with TEHTRI-Security talk at BlackHat Washington DC,  Inglourious Hackerds, Targeting Web Clients  </description><link>http://www.secuobs.com/revue/news/279885.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/279885.shtml</guid></item>
<item><title> Gartnercom  If A Toy Breaks in a Work Forest, Will The Toy Vendor Hear a Noise and Fix It  </title><description>Secuobs.com : 2011-01-21 15:18:32 - TEHTRI Security RSS - Gartner  thoughts related to TEHTRI-Security talk at BlackHat Washington DC,  Inglourious Hackerds, Targeting Web Clients  </description><link>http://www.secuobs.com/revue/news/279884.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/279884.shtml</guid></item>
<item><title> Client-Side Attack  Upgrade your BlackBerry devices </title><description>Secuobs.com : 2011-01-20 01:38:01 - TEHTRI Security RSS -  TEHTRI-Security found a vulnerability on BlackBerry devices This security issue was patched by RIM, with an official advisory displayed recently on their site Basically, when a BlackBerry device user browses to a malformed web page, the BlackBerry browser application consumes sufficient resources to make the BlackBerry device appear unresponsive Check CVE-2010-2599 </description><link>http://www.secuobs.com/revue/news/279478.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/279478.shtml</guid></item>
<item><title> BlackHat DC 2011  0days and exploiting web clients </title><description>Secuobs.com : 2011-01-19 17:34:54 - TEHTRI Security RSS -  TEHTRI-Security gave a talk yesterday during BlackHat Briefings in Washington DC We explained how we found some 0days against some devices  Apple, RIM, Android, HTC  with client-side attacks We got an awesome surprise for the attendees, with experts from RIM who came and explained how they mitigated the vulnerability we found, thanks to a worldwide patch, etc </description><link>http://www.secuobs.com/revue/news/279273.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/279273.shtml</guid></item>
<item><title> Safari Patch released by Apple with Credits to TEHTRI-Security</title><description>Secuobs.com : 2011-01-04 08:42:43 - TEHTRI Security RSS -  CVE-ID  CVE-1010-1752, Available for  Safari 503 and Safari 413, on platforms Windows 7, Vista, XP SP2 or later -- Description  A stack overflow exists in CFNetwork's URL handling code Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution This issue is addressed through improved memory handling </description><link>http://www.secuobs.com/revue/news/275634.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/275634.shtml</guid></item>
<item><title> New talk  BlackHat DC 2011 -  Inglourious Hackerds, Targeting Web Clients </title><description>Secuobs.com : 2010-12-02 19:00:27 - TEHTRI Security RSS -  TEHTRI-Security will give a talk at the next BlackHat in Washington DC Our briefing will be called  Inglourious Hackerds  Targeting Web Clients  There, we will disclose many interesting tricks, exploits, 0days, etc, related to attacks that can occur against web clients for many devices and web browsers </description><link>http://www.secuobs.com/revue/news/268902.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/268902.shtml</guid></item>
<item><title> HITB - Advanced European Training   Hunting Web Attackers </title><description>Secuobs.com : 2010-11-20 14:22:21 - TEHTRI Security RSS -  TEHTRI-Security will propose this offensive training to help administrators and IT Security staff who want to hunt down web attackers It will contain plenty of cutting-edge hands-on exercices and 0days During HITB Malaysia 2010, the room was almost full, with students from Fortune 500, government agencies, etc So, register quickly and join us in Amsterdam, Netherlands, during Hack In The Box HITBSecConf 2011 There, we will release some of our self-defense cyber weapons with 0days there </description><link>http://www.secuobs.com/revue/news/266335.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/266335.shtml</guid></item>
<item><title> MACOSX Patch released by Apple with Credits to TEHTRI-Security </title><description>Secuobs.com : 2010-11-11 14:09:48 - TEHTRI Security RSS -  CVE-ID  CVE-2010-1752, Available for  Mac OS X v1058, Mac OS X Server v1058, Mac OS X v106 through v1064, Mac OS X Server v106 through v1064 -- Description  A stack overflow exists in CFNetwork's URL handling code Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution This issue is addressed through improved bounds checking </description><link>http://www.secuobs.com/revue/news/264179.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/264179.shtml</guid></item>
<item><title> Security-Advisory  TEHTRI-SA-2010-032 - Security issue in BaiduSpider </title><description>Secuobs.com : 2010-11-02 12:24:54 - TEHTRI Security RSS -  TEHTRI-Security found security issues related to Baidu products This one deals with Baiduspider Baidu company contacted </description><link>http://www.secuobs.com/revue/news/261764.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/261764.shtml</guid></item>
<item><title> Security-Advisory  TEHTRI-SA-2010-031 - 0day on Safari for Windows </title><description>Secuobs.com : 2010-10-24 15:31:33 - TEHTRI Security RSS -  TEHTRI-Security found a stack overflow in Safari for Windows  latest version 502 - 7533185  from Apple Inc IT Security crew from Apple contacted with an example of exploit plus a description  Vulnerable DLL, etc  This is a client-side attack against this web browser, without the interaction of the end-user  once the evil web page is loaded  No detail shared out of the Apple team </description><link>http://www.secuobs.com/revue/news/259525.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/259525.shtml</guid></item>
<item><title> New talk  Black-Hat Abu Dhabi 2010 </title><description>Secuobs.com : 2010-10-23 22:09:44 - TEHTRI Security RSS -  TEHTRI-Security will be part of Black-Hat Abu Dhabi 2010 for a new talk called  Extrusion and Web Hacking  We will focus on real threats and security issues related to extrusion, by explaining how attackers try to get a stealth control or an evil interaction of a remote web resource  real life covert channel, stealth bounces, etc  </description><link>http://www.secuobs.com/revue/news/259464.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/259464.shtml</guid></item>
<item><title> Security-Advisory  TEHTRI-SA-2010-030 - 0day on Android - App Gmail </title><description>Secuobs.com : 2010-10-22 21:01:39 - TEHTRI Security RSS -  TEHTRI-Security Lab  Vulnerability found on Android product Application  Gmail - comgoogleandroidgm Google Security Team contacted </description><link>http://www.secuobs.com/revue/news/259294.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/259294.shtml</guid></item>
<item><title> Credits from Apple </title><description>Secuobs.com : 2010-10-20 19:35:05 - TEHTRI Security RSS -  TEHTRI-Security was recently added twice on an article that provides credit to people who have reported potential security issues in Applecom web servers </description><link>http://www.secuobs.com/revue/news/258642.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/258642.shtml</guid></item>
<item><title> New Talk   Analyzing Massive Web Attacks </title><description>Secuobs.com : 2010-09-17 01:52:01 - TEHTRI Security RSS -  The goal of this talk is to have a deep look at some recent web attacks that occured over the Internet, especially those that were used to target a huge number of people Thanks to special forensics operations, we will be able to bring code used by attackers to get an access, to keep control, and to commit cyber crimes Place   Kuala Lumpur, Malaysia, HITBSecConf 2010 </description><link>http://www.secuobs.com/revue/news/247771.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/247771.shtml</guid></item>
<item><title> New Training   Hunting Web Attackers </title><description>Secuobs.com : 2010-09-17 01:52:01 - TEHTRI Security RSS -  TEHTRI-Security will give a new offensive training to help administrators and IT Security staff to hunt down web attackers, with plenty of cutting-edge hands-on exercices So join us in Kuala Lumpur, Malaysia, during Hack In The Box HITBSecConf 2010 We will release some of our self-defense cyber weapons with 0days there </description><link>http://www.secuobs.com/revue/news/247770.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/247770.shtml</guid></item>
<item><title> Security-Advisory  TEHTRI-SA-2010-028 - 0day on BlackBerry </title><description>Secuobs.com : 2010-07-03 11:02:30 - TEHTRI Security RSS - During the first Hack In The Box conference in Europe, we have explained many security issues related to attacks against web clients in insecure environments This particular advisory was about the BlackBerry No technical detail was given to the public, so that the customers of this product might not be attacked because of our researches Everything is in the hands of BlackBerry who are already working to fix this vulnerability </description><link>http://www.secuobs.com/revue/news/237383.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/237383.shtml</guid></item>
<item><title> CVE-2010-1752  TEHTRI-Security inside the iPhone iOS4 </title><description>Secuobs.com : 2010-07-03 11:02:30 - TEHTRI Security RSS - TEHTRI-Security found a stack overflow in CFNetwork, through the code used to handle URL By visiting a maliciously crafted website, we found that it might lead to an unexpected application termination or arbitrary code execution This issue has been addressed by Apple through improved memory handling Apple has given credit to TEHTRI-Security on their site for reporting this issue, as we provided the 0day directly to them, so that the security of their customers could be improved This has been released to the public for the first time during Hack In The Box Europe </description><link>http://www.secuobs.com/revue/news/237382.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/237382.shtml</guid></item>
<item><title> TEHTRI-Security research analyzed by BBC </title><description>Secuobs.com : 2010-06-18 13:00:52 - TEHTRI Security RSS -  BBC News has just released an article about our recent works, in their Technology category </description><link>http://www.secuobs.com/revue/news/232833.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/232833.shtml</guid></item>
<item><title> TEHTRI-Security interviewed by The Register </title><description>Secuobs.com : 2010-06-18 06:46:34 - TEHTRI Security RSS -  Dan Goodin in San Francisco, working for The Register, asked us many questions about our talk of SyScan Singapore He wrote an article called  Researcher shows how to strike back at web assailants </description><link>http://www.secuobs.com/revue/news/232758.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/232758.shtml</guid></item>
<item><title> Security-Advisory  TEHTRI-SA-2010-023 - Vuln in NEON</title><description>Secuobs.com : 2010-06-17 19:42:23 - TEHTRI Security RSS -  We just released this new 0day against the exploit pack called NEON Remote and pre-authentication 0day Permanent XSS and XSRF against the administrators in the admin panel It can be used to steal cookies of authentication of the evil admins, to destroy their databases used for attack management, to identify the attackers, etc </description><link>http://www.secuobs.com/revue/news/232573.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/232573.shtml</guid></item>
<item><title> HITB Amsterdam  Speaker  Web in the Middle Attacking Clients </title><description>Secuobs.com : 2010-05-11 15:40:42 - TEHTRI Security RSS -  TEHTRI-Security will be at HITBSecConf Amsterdam 2010 for a new talk It will be time to play around threats targetting web clients, on well known services as well as for in-depth hacking operations For example, we will talk about attacks on remote compromised LAN, hotspots, etc </description><link>http://www.secuobs.com/revue/news/220987.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/220987.shtml</guid></item>
<item><title> SyScan 2010 Singapore  Speaker  Striking Back Web Attackers </title><description>Secuobs.com : 2010-05-02 19:56:48 - TEHTRI Security RSS -  TEHTRI-Security will be at SyScan 2010 Singapore for an innovative talk called  Striking back web attackers It will be time for white-hats to find new ways to protect themselves once they are under attack by evil intruders The best defense is a good offense Get more information on SyScanorg </description><link>http://www.secuobs.com/revue/news/218077.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/218077.shtml</guid></item>
<item><title> HITB Dubai 2010  Our slides are available</title><description>Secuobs.com : 2010-04-25 11:11:43 - TEHTRI Security RSS -  If you want to enjoy what we presented during HITBSecConf Dubai 2010, follow this link and read our slides Our goal was to give a 1 hour overview about how web attackers behave to remain stealth on a network they were able to break-in </description><link>http://www.secuobs.com/revue/news/215803.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/215803.shtml</guid></item>
<item><title> Security-Advisory  TEHTRI-SA-2010-009 - Squirrelmail 0-day</title><description>Secuobs.com : 2010-04-25 11:11:43 - TEHTRI Security RSS - Transform Squirrelmail as a Nmap-like scanner Remote exploit, post-authentication Most versions Issue in default plugin called mail_fetch Page 69 on our slides </description><link>http://www.secuobs.com/revue/news/215802.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/215802.shtml</guid></item>
<item><title> Security-Advisory  TEHTRI-SA-2010-010 - Horde 0-day</title><description>Secuobs.com : 2010-04-25 11:11:43 - TEHTRI Security RSS - Transform Horde as a Nmap-like scanner Remote exploit, pre-authentication Most versions Issue in plugin called IMP Page 74 on our slides </description><link>http://www.secuobs.com/revue/news/215801.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/215801.shtml</guid></item>
<item><title> HITB Magazine  Interview of TEHTRI-Security</title><description>Secuobs.com : 2010-04-25 11:11:43 - TEHTRI Security RSS -  Editor-in-Chief Zarul Shahrin Suhaimi made an interview of TEHTRI-Security Check this issue number 2 of HITB Magazine, and find out what we think about IT Security, on page 42 </description><link>http://www.secuobs.com/revue/news/215800.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/215800.shtml</guid></item>
<item><title>Security Advisory  TEHTRI-SA-2010-002 - Vuln in Acunetix product</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS - TEHTRI-Security Lab   Vulnerability found in Acunetix Scanner First report sent to Acunetix Status  Under discussion with Acunetix </description><link>http://www.secuobs.com/revue/news/197518.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197518.shtml</guid></item>
<item><title>CanSecWest 2010  Training given</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS - Canada Vancouver   A security training will be given at the Master Security Dojo, Cansecwest 2010, 22-26 March 2010, about   Advanced PHP Hacking </description><link>http://www.secuobs.com/revue/news/197517.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197517.shtml</guid></item>
<item><title>Twitter Account added</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS - You may follow us on Twitter too, where we just created our account </description><link>http://www.secuobs.com/revue/news/197516.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197516.shtml</guid></item>
<item><title>Advanced PHP Hacking</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS - Full program of the training given in Vancouver, is now available on Cansecwest Conference web site </description><link>http://www.secuobs.com/revue/news/197515.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197515.shtml</guid></item>
<item><title>Security-Advisory  TEHTRI-SA-2010-008 - Vuln in Apple product</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS - TEHTRI-Security Lab   Vulnerability found in iPhone product, latest firmware  Safari issue  Report sent to Apple </description><link>http://www.secuobs.com/revue/news/197514.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197514.shtml</guid></item>
<item><title>Web site updated</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS - We've just uploaded the new version of our web site Enjoy </description><link>http://www.secuobs.com/revue/news/197513.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197513.shtml</guid></item>
<item><title> More about our Dubai talk during HITBSecConf 2010</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS -  Web and Stealth Hacking  TEHTRI-Security talk will aim at covering web hacking and stealth issues, showing how security staff and attackers play some kind of hide and seek war-games on the Internet from time to time Before concluding, we will also introduce new offensive concepts that demonstrate how attackers like pentesters, blackhats, etc, can be helped to become stealthier on the wire, so that defenders understand some kind of limitations of the current situation and tools </description><link>http://www.secuobs.com/revue/news/197512.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197512.shtml</guid></item>
<item><title> Cansecwest Security Training  Program Updated online</title><description>Secuobs.com : 2010-03-03 10:57:31 - TEHTRI Security RSS - Our Security Master's Dojo course that will occur during next Cansecwest 2010  22-23 March 2010  has been updated and is available here This session aims at providing a hands-on focused PHP Hacking experience After this course, you will really know how attackers work and move through PHP hax0ring so that they can jump deeper down to your networks This training will end with a final amazing exercise through a step by step live hacking simulation It will help students at coming back to offensive and defensive hands-on actions seen during the whole day, thanks to a complete information warfare operation </description><link>http://www.secuobs.com/revue/news/197511.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/197511.shtml</guid></item>
</channel>
</rss>
 
