This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Zero Days. Show all posts
Showing posts with label Zero Days. Show all posts

How (not) to handle software vulnerability submissions

If you're a software vendor developing programs more complex than "Hello World", eventually you will face an issue with a security vulnerability in your products.

For those who don't know I currently have an automated crawler searching Pastebin for new exploits and vulnerabilities.  This crawler reports its results live via the Twitter hashtag #exploitAlert. Every once in a while if something catches my attention, I'll submit it to the software vendor.

For most vendors the process is very straightforward...just send an email or fill out a form.  For an example of the right way to allow submissions of security vulnerabilities take a look at Microsoft's method.

Recently a supposed "0 day" vulnerability for Parallels Plesk was found by my crawler (a permanent copy of this paste is available here).  I've never worked with Parallels software before, so I went to their website to try and find out where to submit a vulnerability.  Finally I found it was an option on their support form.

My jaw dropped when I saw the warning at the bottom of the support form...


Well that certainly puts a stopper on things.  I'm not a paying customer...so obviously I won't be able to continue.  And what's even worse...if I was a paying customer...I would be CHARGED for submitting a security vulnerability!

Policies such as the one above will only cause frustrated users to post the vulnerability publicly instead of through responsible disclosure.

If anyone from Parallels reads this I would like to encourage you to push for reform of your vulnerability submission practices.

IE Zero Day and Increase in Global Malware Indicators

A look at the last 30 days of web searches for common malware infection indicators shows that the Internet Explorer Zero Day vulnerability has been in the wild since possibly September 12, 2012, or possibly as far back as September 8.

On September 11, the indicator search volume was at 67 on a sliding scale.  As of September 16, 2012 (the last day Google provides search data for at this time), the search volume had increased to 94.

The search volume had peaked on September 2, and was on a fairly steady decline since, with the exception of a brief spike in search activity on September 8.

IE Zero Day Exploit in the Wild

There is an IE exploit in the wild which affects IE 7, 8, and 9.

For more information, see the SANS ISC post.

New @CaffSec Twitter Feature: #exploitAlert

I've taken the Google Alert "zero day" exploit feed and created automated Twitter notifications.

You can get updated #exploitAlert notifications by following my Twitter account, @CaffSec.

The feed currently monitors PasteBin for new exploits.  Expect additional feeds soon!

Emergency Adobe Flash Patch Today

Good Morning!

Today we will be treated to an emergency patch for Adobe Flash.
Prenotification: Security Update for Flash Player

Keep an eye on Adobe's security bulletins page for the patch.

Apparently this patch will address zero-day vulnerabilities which are currently being exploited.

Happy Patching!