[Full-disclosure] multiple critical vulnerabilities in sophos products

2012-11-05 Thread Tavis Ormandy
List, I've completed the second paper in my series analyzing Sophos Antivirus internals, titled Practical Attacks against Sophos Antivirus. As the name suggests, this paper describes realistic attacks against networks using Sophos products. The paper includes a working pre-authentication remote

Re: [Full-disclosure] multiple critical vulnerabilities in sophos products

2012-11-05 Thread Michele Orru
Reading the paper now. The previous one about internals was awesome. enumerating badness keyword :D ROFL Cheers antisnatchor On Mon, Nov 5, 2012 at 3:14 PM, Tavis Ormandy tav...@cmpxchg8b.com wrote: List, I've completed the second paper in my series analyzing Sophos Antivirus internals,

Re: [Full-disclosure] multiple critical vulnerabilities in sophos products

2012-11-05 Thread Michele Orru
Also, They told me they will work on this, and will improve their internal security practices. is just ridiculous. I have the same feeling you had while reaching out with them, when the results from some of my product pentests cannot be disclosed even after patching. I wish we could always go