Luigi Auriemma

aluigi@autistici.org


News
Advisories
Proof-of-concepts
Research
QuickBMS
Fake_players_bug
MyToolz
Password_recovery
Patches
MyMusic
TestingToolz
About...
RSS_feeds
Amiga_ADF
Forum
aluigi.org
mirror.aluigi.org
twitter


27 Jan 2012 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.6c
fixed a compability problem with the gcc optimizations regarding the patch for kzip

27 Jan 2012 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.6b

27 Jan 2012 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.6
added various other compression algorithms and optimized the usage of kzip

23 Jan 2012 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.5
added the EXECUTE method for both Comtype and Encryption, String scanf/strstr/strrstr, various new compression algorithms, usage of kzip.exe in reimport mode if the compressed size is bigger than the original one, fixes and optimizations

17 Jan 2012 Advisories: Two Denials of Service in Rockwell RNADiagReceiver 2.40.0.12 (SCADA)
just an old test I did in the far September 2011 and planned to do better when inspired, I have released it now only to free my bugs queue and return on this product later without rush

15 Jan 2012 Advisories: Directory traversal in NeoAxis Web Player 1.4

15 Jan 2012 MyToolz: Calcc 0.1.5
added support for strings and chars, FILETIME/time64 visualization

11 Jan 2012 Advisories: some bugs in SumatraPDF and ExpressView

09 Jan 2012 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.4a
added a slower but more secure way to manage the allocated memory, it's a crazy experiment I had in mind and may help during the debugging of some scripts

09 Jan 2012 MyToolz: Signsrch 0.1.7
added only the possibility of scanning folders, the rest is unchanged

09 Jan 2012 MyToolz: QuickRVA 0.2.3a
micro fix if e_lfanew is minor than the size of IMAGE_DOS_HEADER and updated distorm library

19 Dec 2011 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.4
solved some bugs but there is still lot to do, created also an encryption_scan.bat+bms solution for scanning the various encryption algorithms with a known key and optional ivec

18 Dec 2011 Research: FSB files extractor 0.2.13a
solved lame bug with duplicated extensions

11 Dec 2011 Password_recovery: Sony Station Launcher profile and packet password decoder 0.2

04 Dec 2011 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.3b
fixed a problem with Open FDDE/FDSE

03 Dec 2011 Advisories: Vulnerabilities in Serv-U 11.1.0.3

03 Dec 2011 Advisories: Endless loop in CyberLink PowerDVD 11.0.0.2114

02 Dec 2011 Fake_players_bug: SA:MP invisible Fake Players DoS 0.1.8
compatible with 0.3d

01 Dec 2011 Research: NCF/CCF packet format to tcpdump capture format 0.2
rewritten, now handles the compressed packets and the timestamps

29 Nov 2011 Advisories: Vulnerabilities in 3S CoDeSys 3.4 SP4 Patch 2 (SCADA)

28 Nov 2011 Advisories: Use-after-free in Microsys PROMOTIC 8.1.4 (SCADA)

28 Nov 2011 Password_recovery: PROMOTIC data decrypter 0.1
decrypts the informations (users credentials and Data) available in users.ini and the PRA projects

28 Nov 2011 Advisories: Vulnerabilities in Siemens Automation License Manager (SCADA)

28 Nov 2011 Advisories: Vulnerabilities in Siemens SIMATIC WinCC flexible 2008 SP2 (SCADA)

28 Nov 2011 Research: Telltale TTARCH files extractor/rebuilder 0.1.12c
added the key of Jurassik Park

14 Nov 2011 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.3a
added the possibility of automatically setting new filenames for those that already exist (choose 'r' when prompted)

14 Nov 2011 Research: Gslist 0.8.10b
some small fixes

14 Nov 2011 MyToolz: Mydown and mydownlib
a small fix for URLs placed in const buffers

07 Nov 2011 Advisories: GE Proficy iFix HMI/SCADA ihDataArchiver.exe Trusted Header Size Remote Code Execution Vulnerability

03 Nov 2011 Advisories: Vulnerabilities in HP Data Protector Media Operations 6.20

03 Nov 2011 Advisories: Use-after-free in Excel for Office 2003 11.8335.8333 SP3
it was only a quick automated experiment so it's nothing special or interesting at the moment, maybe requires additional research or just to be put in the trash. there are 2 advisories but the bug is probably the same, sorry but I don't care now

30 Oct 2011 MyToolz: Proxocket 0.1.7
better compatibility with Windows Vista/7/2008 (thanx devnull)

30 Oct 2011 MyToolz: Lame Patcher 0.4.4b
avoid admin privileges on Vista/Win7

30 Oct 2011 Research: Live for Speed setups dumper 0.1a
solved the problem with UAC asking for admin privileges on Vista/Win7

30 Oct 2011 Research: GS peerchat server emulator 0.1.3a
added only the check of gslist.cfg when launched and the -v verbose option

30 Oct 2011 TestingToolz: UDPSZ 0.3.3a

30 Oct 2011 Advisories: ActiveX bug in Microsys PROMOTIC 8.1.4

29 Oct 2011 Research: PunkBuster online GUID checker 0.1.13
added Battlefield 3 and Red Orchestra 2

13 Oct 2011 Advisories: Vulnerabilities in PROMOTIC 8.1.3

10 Oct 2011 Advisories: Vulnerabilities in atvise webMI2ADS 1.0

10 Oct 2011 Advisories: Use after free in IRAI AUTOMGEN 8.022

10 Oct 2011 Advisories: Denial of Service in OPC Systems.NET 4.00.0048

02 Oct 2011 Advisories: Vulnerabilities in Cytel Studio 9

01 Oct 2011 Advisories: Vulnerabilities in GenStat 14.1.0.5943

28 Sep 2011 Advisories: Arbitrary memory corruption in NCSS 07.1.21

27 Sep 2011 Advisories: Vulnerabilities in PcVue 10 (SCADA)

25 Sep 2011 QuickBMS: QuickBMS generic files extractor and reimporter 0.5.3
now it's no longer needed to specify the output folder when used from the command-line, added arguments to the CallFunction command, enhanced the unzip_dynamic compression, fixed a bug in the recompression of XMemCompress

25 Sep 2011 Advisories: Integer overflow in Sterling Trader 7.0.2

22 Sep 2011 Advisories: Vulnerabilities in Sunway ForceControl 6.1 sp3 (SCADA)

19 Sep 2011 Advisories: Vulnerabilities in EViews 7.2

19 Sep 2011 Advisories: Vulnerabilities in MetaServer RT 3.2.1.450

19 Sep 2011 TestingToolz: UDPSZ 0.3.3
fixes and enhancements

16 Sep 2011 Research: Race WTCC files encrypter/decrypter 0.3.1a
solved a problem in the handling of sub folders

16 Sep 2011 Research: ISI rFactor files decrypter/encrypter 0.2.1a
solved a problem in the handling of sub folders

13 Sep 2011 Advisories: released the full detailed advisory of my WINS vulnerability (MS11-035 / ZDI-11-167)

13 Sep 2011 Advisories: Code execution in MetaStock 11

13 Sep 2011 Advisories: Vulnerabilities in eSignal 10.6.2425

13 Sep 2011 Advisories: Multiple vulnerabilities in Cogent DataHub 7.1.1.63 (SCADA)

13 Sep 2011 Advisories: Stack overflow in DAQFactory 5.85 build 1853 (SCADA)

13 Sep 2011 Advisories: Multiple vulnerabilities in Progea Movicon / PowerHMI 11.2.1085 (SCADA)

13 Sep 2011 Advisories: Directory traversal in Carel PlantVisor 2.4.4 (SCADA)

13 Sep 2011 Advisories: Denial of Service in Rockwell RSLogix 19 (SCADA)

13 Sep 2011 Advisories: Multiple vulnerabilities in Measuresoft ScadaPro 4.0.0 (SCADA)

13 Sep 2011 Advisories: Denial of Service in Beckhoff TwinCAT 2.11.0.2004 (SCADA)

12 Sep 2011 News: now you can follow me also on twitter

05 Sep 2011 Patches: XPDF pdftotext/pdftops/pdfimages allow copying of text (Win32) 0.1.1
added support for version 3.03

02 Sep 2011 Advisories: vulnerabilities in MPlayer on Windows and BroadWin WebAccess Client

... old news