Showing posts with label SC Magazine. Show all posts
Showing posts with label SC Magazine. Show all posts

Thursday, January 17, 2013

Security & Hacking: " Patient data revealed in medical device hack"

http://www.scmagazine.com.au/News/329222,patient-data-revealed-in-medical-device-hack.aspx


Face palm, after reading this section, though not only vulnerability:
Once an extensive 200Gb forensic imaging process of the Windows-based platform had completed and the system was booted into a virtual machine, it took the researchers "two minutes" to find the first vulnerability.
"We noticed there was a port open, and we started basic fuzzing and found a heap overflow and wrote up a quick exploit for it," Rios said.
"The exploit runs as a privileged service, so we owned the entire box - we owned everything that it could do."
The researchers suspect the authentication logins for the system,  one with a username Philips and password Service01, are hardcoded and unchangeable by users, but when they warned Philips the company refuted the claim.

Security evidently wasn't part of the design criteria.

Article notes US DHS (Dept. Homeland Security) and FDA (Food & Drug Administration) were pressuring Philips to fix the problem.

Thursday, November 8, 2012

Security & Hacking: PayPal Authorization bypass issue

Read the Live Hacking article first, it is much better written, so it is lot easier to understand, http://www.livehacking.com/2012/11/02/paypal-bug-bounty-program-not-working-as-well-as-it-should/

But I saw this issue on SC Magazine first http://www.scmagazine.com.au/News/321584,paypal-security-holes-expose-customer-card-data-personal-details.aspx

Neil Smith is the White Hat Hacker that found the vulnerability, his original blog post on the issue is http://l8security.com/post/33876600904/paypal-bug-bounty-a-lesson-in-not-being-a-fuckup

Have to say, he has a catchy title, though his blog post won't be easy to understand unless you have certain minimal coding/computer skills.

The Live Hacking article is the best one for general audience IMHO.

I have blogged about PayPal issues before http://cliffsesportcorner.blogspot.com/2011/12/psa-paypal-make-it-right.html

In that post I mentioned a hack that impacted friends of mine:
"A friend of mine passed away earlier this year, leaving a wife and two kids, and Paypal donations for them were stolen & Paypal wouldn't step up then either.  So this is the second time this year that I know of, where Paypal doesn't really seem to want to step up and make it right."