Re: [FD] Microsoft Forefront Unified Access Gateway 2010 External DNS Interaction

2018-07-06 Thread Thierry Zoller
Can this be used to perform DNS exfiltration ? (Assuming the UGW is whitelisted to perform DNS (which it likely must be) > # Exploit Title: Microsoft Forefront Unified Access Gateway 2010 External > DNS Interaction > # Vendor Homepage: https://www.microsoft.com/ > # Version: 2010 > # CVE : CVE-2

[FD] [TZO-01-2020] AVIRA Generic Malformed Container bypass (ISO)

2020-01-03 Thread Thierry Zoller
From the low-hanging-fruit-department AVIRA Generic Malformed Container bypass (ISO) Release mode: Silent

[FD] [TZO-02-2020] Kaspersyk Generic Malformed Archive Bypass (ZIP GFlag)

2020-01-03 Thread Thierry Zoller
From the low-hanging-fruit-department Kaspersky Generic Malformed Archive Bypass (ZIP GFlag) Release mode: Coordinated Dis

[FD] [TZO-03-2020] ESET Generic Malformed Archive Bypass (ZIP Compression Information)

2020-01-03 Thread Thierry Zoller
From the low-hanging-fruit-department ESET Generic Malformed Archive Bypass (ZIP Compression Information) Release mode: Coordin

[FD] [TZO-04-2020] Bitdefender Generic Malformed Archive Bypass (BZ2)

2020-01-07 Thread Thierry Zoller
From the low-hanging-fruit-department Bitdefender Generic Malformed Archive Bypass (BZ2) Release mode : Forced Disclosure Re

[FD] [TZO-05-2020] Kaspersky Generic Malformed Archive Bypass (ZIP Compressed Size)

2020-01-10 Thread Thierry Zoller
From the low-hanging-fruit-department Kaspersky Generic Malformed Archive Bypass (ZIP Compressed Size) Release mode: Coordina

[FD] [TZO-07-2020] Bitdefender Generic Malformed Archive Bypass (RAR HOST_OS)

2020-01-10 Thread Thierry Zoller
From the low-hanging-fruit-department Bitdefender Generic Malformed Archive Bypass (RAR HOST_OS) Release mode: Forced Discl

[FD] [TZO-08-2020] Bitdefender Generic Malformed Archive Bypass (ZIP GPFLAG)

2020-01-13 Thread Thierry Zoller
From the low-hanging-fruit-department Bitdefender Generic Malformed Archive Bypass (ZIP GPFLAG) Release mode: Forced Disclosur

[FD] [TZO-06-2020] - Kaspersky Generic Archive Bypass (ZIP FLNMLEN)

2020-01-13 Thread Thierry Zoller
From the low-hanging-fruit-department Kaspersky Generic Malformed Archive Bypass (ZIP Filename Length) Release mode: Coordinate

[FD] [TOOL] Permanent SD Card Locker (Read Only)

2020-01-13 Thread Thierry Zoller
Thought this might be interesting to the audience of FD. https://blog.zoller.lu/2020/01/sd-card-permanent-read-only-locker.html ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: ht

[FD] [TZO-09-2020] - Bitdefender Malformed Archive bypass (RAR Uncompressed Size)

2020-01-17 Thread Thierry Zoller
From the low-hanging-fruit-department Bitdefender Generic Malformed Archive Bypass (RAR Uncompressed Size) Release mode: Forced

[FD] [TZO-10-2020] - Bitdefender Malformed Archive bypass (RAR Compression Information)

2020-01-17 Thread Thierry Zoller
From the low-hanging-fruit-department Bitdefender Malformed Archive Bypass (RAR Compression Information) Release mode: Forced Dis

[FD] [TZO-11-2020] - ESET Generic Malformed Archive Bypass (BZ2 Checksum)

2020-02-14 Thread Thierry Zoller
From the low-hanging-fruit-department ESET Generic Malformed Archive Bypass (BZ2 Checksum) Release mode: Coordinated D

[FD] [TZO-13-2020] - AVIRA Generic AV Bypass (ZIP GPFLAG)

2020-02-14 Thread Thierry Zoller
From the low-hanging-fruit-department AVIRA Generic Malformed Container bypass (ZIP GPFLAG) Release mode: No Patch - Coord

[FD] [TZO-15-2020] - F-SECURE Generic Malformed Container bypass (RAR)

2020-02-14 Thread Thierry Zoller
From the low-hanging-fruit-department F-SECURE Generic Malformed Container bypass (RAR) Ref : [TZO-15-2020] -

[FD] [TZO-17-2020] - Kaspersky Generic Archive Bypass (ZIP FLNMLEN)

2020-02-18 Thread Thierry Zoller
From the low-hanging-fruit-department Kaspersky Generic Malformed Archive Bypass (ZIP Filename Length) Release mode: Coordinate

[FD] [TZO-18-2020] - Bitdefender Malformed Archive bypass (GZIP)

2020-02-18 Thread Thierry Zoller
From the low-hanging-fruit-department Bitdefender Generic Malformed Archive Bypass (GZIP) Release mode: Silent Patch Ref

Re: [FD] [TZO-03-2020] ESET Generic Malformed Archive Bypass (ZIP Compression Information)

2020-02-18 Thread Thierry Zoller
This was assigned CVE-2020-9264 ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [TZO-19-2020] - AVIRA Generic AV Bypass (ISO Container) - CVE-2020-9320

2020-02-28 Thread Thierry Zoller
From the low-hanging-fruit-department AVIRA Generic Malformed Container bypass (ISO Container) Release mode: Coordinated disc

[FD] [TZO-16-2020] - F-SECURE Generic Malformed Container bypass (GZIP)

2020-02-28 Thread Thierry Zoller
From the low-hanging-fruit-department F-SECURE Generic Malformed Container bypass (GZIP) Ref : [TZO-16-2020] - F-S

[FD] [TZO-22-2020] Qihoo360 | GDATA | Rising | Command Generic Malformed Archive Bypass

2020-02-28 Thread Thierry Zoller
From the lets-try-it-this-way Department Qihoo360 | GDATA | Rising | Webroot | Dr Web Generic Archive Bypass Release mode: Vendors do

[FD] [TZO-23-2020] - AVAST Generic Archive Bypass (ZIP)

2020-02-28 Thread Thierry Zoller
From the low-hanging-fruit-department Avast Generic Malformed Archive Bypass (ZIP GFlag) Release mode: Coordinated Di

[FD] QuickHeal Generic Malformed Archive Bypass (ZIP GPFLAG)

2020-03-03 Thread Thierry Zoller
From the low-hanging-fruit-department QuickHeal Generic Malformed Archive Bypass (ZIP GPFLAG) Release mode: Silent Patch Ref

[FD] [TZO-20-2020] - Quickheal Malformed Archive bypass (ZIP GPFLAG) - CVE-2020-9362

2020-03-06 Thread Thierry Zoller
From the low-hanging-fruit-department QuickHeal Generic Malformed Archive Bypass (ZIP GPFLAG) Release mode: Silent Patch Ref

[FD] [CDPWE-0001] - RocketReach

2020-05-29 Thread Thierry Zoller
Adapting the Mechanics of Vulnerability Disclosure to an area where Privacy Rights need to be scrutinized and where transparency becomes paramount. How to effectively evade the GDPR and the reach of the DPA (CDPWE-0001

Re: [FD] [CDPWE-0001] - RocketReach

2021-03-11 Thread Thierry Zoller
=== Adapting the Mechanics of Vulnerability Disclosure to an area where Privacy Rights need to be scrutinized and where transparency becomes paramount. === On the 29.