|
|||||||
|
You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community today, you will have fewer ads, access to post topics, communicate privately with other members, respond to polls, upload content and access many other special features. If you have any problems with the registration process or your account login, please contact us. Hint: Don't have time to visit us daily? Subscribe to our main RSS feed to receive our frontpage posts at your convenience. |
| iLiad Developer's Corner For iLiad development discussion and planning |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
|
|
#1 |
|
Guru
![]() ![]()
Posts: 607
Karma: 197
Join Date: Oct 2005
Device: NCR3125, Nokia 770,...
|
Huge exploit found in 2.7
Ok, I have downloaded the 2.7. Awesome pdf thing, it remembers the zoom between pages, and this is already better than standard xpdf, nice icons, blah blah blah. Ah and yes, I got to execute a ls > /opt/content/books/a.txt command. But on the other hand the remote Xserver approach seems promising. So what do I do? Wait for a crack via Xserver to be done? Do I explain how I did the ls so you people can try to run shell scripts via similar methods, risking to be patched in the security fix? Personally I think that any Xserver exploit will be patched in the future, because it is a real internet security issue.
|
|
|
|
|
|
#2 | |
|
Evangelist
![]() ![]() ![]()
Posts: 457
Karma: 293
Join Date: May 2006
|
Quote:
|
|
|
|
|
|
|
#3 | |
|
Guru
![]() ![]()
Posts: 607
Karma: 197
Join Date: Oct 2005
Device: NCR3125, Nokia 770,...
|
Quote:
|
|
|
|
|
|
|
#4 | |
|
Fully Converged
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
Posts: 12,179
Karma: 68037
Join Date: Oct 2002
Location: Switzerland
Device: Sony Portable Reader
|
Quote:
|
|
|
|
|
|
|
#5 | |
|
Evangelist
![]() ![]() ![]()
Posts: 457
Karma: 293
Join Date: May 2006
|
Quote:
But seriously... I'm glad this was brought out in the open... I think it shows willingness to work with Irex in making their product better. Lets see how soon they fix this...!
|
|
|
|
|
|
|
#6 | |
|
Guru
![]() ![]()
Posts: 607
Karma: 197
Join Date: Oct 2005
Device: NCR3125, Nokia 770,...
|
Quote:
The PDF hole in 2.4 was a different issue; just because the confirmation window was not drawn in the the screen (it was, but the screen was not updated, remember) there was possible to do a pdf asking the user "click in this cross, then click this one and see what happens", the seconf cross subtly drawn over the OK button. It needs not to be so ovvious, it could be for instance a sudoku square asking two sequencial clicks, or some "start demo" thing. In spain we call this kind of deception a "Cuartango" trick, because this researcher in the CSIC did some work on deception windows over MSWindows. Last edited by arivero; 10-20-2006 at 08:26 AM. |
|
|
|
|
|
|
#7 | |
|
Connoisseur
![]() ![]()
Posts: 78
Karma: 103
Join Date: Aug 2006
Location: Ipswich, UK
Device: Irex Iliad
|
Quote:
|
|
|
|
|
|
|
#8 | |
|
Guru
![]() ![]()
Posts: 607
Karma: 197
Join Date: Oct 2005
Device: NCR3125, Nokia 770,...
|
Ok I will release it, on second inspection it is so simple that there is no issue.
I backquoted the password in the WEP configuration. this is, I created a new wireless wep connection (wizard, anyname, Proceed, Wireless, anyssid, proceed, WEP, proceed) and in the wep security key field I used: Quote:
And yep, it escaped. I think iRex does not really need to patch this one. It is not a security hole, as the ssh was. Nor a Cuartango trick, as the pdf could be. Here the Owner of the machine must know exactly what he is doing, no argue about being tricked to do it (except if you have got a devilish system admistrator telling you that THAT is the password for your local wlan!). Besides, you need to retort the trick in order to use it to "open the internet", because most probably this escape is executed at the level of the networking scripts, and man you do not want to call the networking script from the networking script. Last edited by arivero; 10-19-2006 at 03:40 PM. |
|
|
|
|
|
|
#9 | |
|
Connoisseur
![]() ![]()
Posts: 78
Karma: 103
Join Date: Aug 2006
Location: Ipswich, UK
Device: Irex Iliad
|
Quote:
|
|
|
|
|
|
|
#10 | |
|
Guru
![]() ![]()
Posts: 607
Karma: 197
Join Date: Oct 2005
Device: NCR3125, Nokia 770,...
|
Quote:
|
|
|
|
|
|
|
#11 | |
|
Evangelist
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Posts: 406
Karma: 754
Join Date: Jun 2006
Location: Madrid, Spain
Device: iliad, onhandpc, newton, zaurus
|
Quote:
What's next in my todo list queue: investigate the pageBar protocol and doing a simple viewer using SDL... Now that we can test it :-)~~~! Yipieee!!! Thanks arivero :-). |
|
|
|
|
|
|
#12 |
|
Connoisseur
![]()
Posts: 65
Karma: 10
Join Date: May 2006
|
Has anyone tried a java --version command yet?
|
|
|
|
|
|
#13 | |
|
Connoisseur
![]() ![]()
Posts: 78
Karma: 103
Join Date: Aug 2006
Location: Ipswich, UK
Device: Irex Iliad
|
Quote:
|
|
|
|
|
|
|
#14 | |
|
Evangelist
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Posts: 406
Karma: 754
Join Date: Jun 2006
Location: Madrid, Spain
Device: iliad, onhandpc, newton, zaurus
|
Quote:
|
|
|
|
|
|
|
#15 | |
|
Guru
![]() ![]()
Posts: 607
Karma: 197
Join Date: Oct 2005
Device: NCR3125, Nokia 770,...
|
Quote:
Last edited by arivero; 10-20-2006 at 10:25 AM. |
|
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| I found way to vastly improve displaying of text! | Malder1 | iRex iLiad | 43 | 01-05-2007 06:32 PM |
| Sony Reader in the press (huge round-up) | Bob Russell | Sony Portable Reader PRS-500/505 | 14 | 10-14-2006 08:46 AM |
| Adobe Acrobat subject to remote exploit | Alexander Turcic | News and Commentary | 3 | 09-16-2006 06:29 AM |
| Serious exploit in Greasemonkey 0.4 | Alexander Turcic | Lounge | 2 | 07-19-2005 05:59 AM |
| Mobile use in rural areas found to be riskier | Alexander Turcic | Lounge | 0 | 05-18-2005 05:55 AM |