Monthly Archives August 2010

broken by design or stupidity ?

US-CERT just released TA10-238A. Excerpts : Due to the way Microsoft Windows loads dynamically linked libraries (DLLs), an application may load an attacker-supplied DLL instead of the legitimate one, resulting in the execution of arbitrary code. OK, I suppose an attacker must have administrator rights to plant a hostile DLL ? Or maybe not ? [...]

Hacking the Google Mini

At a customer site, they decomissioned a Google Mini Appliance. The message was clear : throw it away. I decided to check what I could do with it instead. I didn’t even try to use the onboard Google indexing features or data. I was given the box in condition of erasing the internal disk, so [...]

Switch to our mobile site