<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-932717656972193247</id><updated>2008-08-21T05:50:18.488-07:00</updated><title type='text'>Harmony Security : Blog</title><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.harmonysecurity.com/blog/atom.xml'/><author><name>Steve</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>17</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-5505554679725298460</id><published>2008-08-21T05:46:00.000-07:00</published><updated>2008-08-21T05:50:18.502-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Reverse Engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='OllyDbg'/><title type='text'>[New Tool] OllySocketTrace</title><summary type='text'>OllySocketTrace is a plugin for OllyDbg to trace the socket operations being performed by a process. It will record all buffers being sent and received. All parameters as well as return values are recorded and the trace is highlighted with a unique color for each socket being traced.

The socket operations currently supported are: WSASocket, WSAAccept, WSAConnect, WSARecv, WSARecvFrom, WSASend, </summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/08/new-tool-ollysockettrace.html' title='[New Tool] OllySocketTrace'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/5505554679725298460'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/5505554679725298460'/><author><name>Harmony Security</name><uri>http://www.blogger.com/profile/01721796390165002069</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-3416477586687474531</id><published>2008-08-20T09:36:00.000-07:00</published><updated>2008-08-20T09:53:56.198-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='services'/><title type='text'>New Services</title><summary type='text'>We are soon to be offering several new services, including:Malware Analysis
This service offers detailed malware reports and customised solutions for malware outbreaks.Vulnerability Discovery
This service offers to discover critical vulnerabilities in your software products.Exploit Development
This service offers the development of reliable proof of concept exploits for software </summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/08/new-services.html' title='New Services'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/3416477586687474531'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/3416477586687474531'/><author><name>Harmony Security</name><uri>http://www.blogger.com/profile/01721796390165002069</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-6539119454885828695</id><published>2008-06-05T07:28:00.000-07:00</published><updated>2008-06-25T07:09:20.234-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>VMware Tools HGFS Local Privilege Escalation Vulnerability</title><summary type='text'>iDefense have published an advisory for a local privilege escalation vulnerability (CVE-2007-5671) in the VMware Tools HGFS driver which was discovered by Stephen Fewer of Harmony Security.

You can read the full iDefense advisory here:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=712

And the VMware advisory here:
http://www.vmware.com/security/advisories/VMSA-2008-0009.</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/06/vmware-tools-hgfs-local-privilege.html' title='VMware Tools HGFS Local Privilege Escalation Vulnerability'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/6539119454885828695'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/6539119454885828695'/><author><name>Harmony Security</name><uri>http://www.blogger.com/profile/01721796390165002069</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-51170147509989981</id><published>2008-05-28T02:52:00.000-07:00</published><updated>2008-06-25T07:09:20.235-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>EMC AlphaStor Multiple Vulnerabilities</title><summary type='text'>iDefense have published advisories for multiple vulnerabilities in EMC AlphaStor which were discovered by Stephen Fewer of Harmony Security. You can read the full iDefense advisories here:

EMC AlphaStor Server Agent Multiple Stack Buffer Overflow Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=702

EMC AlphaStor Library Manager Arbitrary Command Execution </summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/05/emc-alphastor-multiple-vulnerabilities.html' title='EMC AlphaStor Multiple Vulnerabilities'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/51170147509989981'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/51170147509989981'/><author><name>Harmony Security</name><uri>http://www.blogger.com/profile/01721796390165002069</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-8538444105009757734</id><published>2008-04-11T02:29:00.000-07:00</published><updated>2008-06-25T07:09:20.235-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>EMC DiskXtender Multiple Vulnerabilities</title><summary type='text'>iDefense have published advisories for multiple vulnerabilities in EMC DiskXtender which were discovered by Stephen Fewer of Harmony Security. You can read the full iDefense advisories here:

EMC DiskXtender Authentication Bypass Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=683

EMC DiskXtender File System Manager Buffer Overflow Vulnerability
http://</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/04/emc-diskxtender-multiple.html' title='EMC DiskXtender Multiple Vulnerabilities'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/8538444105009757734'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/8538444105009757734'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-5135919079045739901</id><published>2008-02-21T05:57:00.000-08:00</published><updated>2008-06-25T07:09:20.236-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>EMC RepliStor Multiple Heap Overflow Vulnerabilities</title><summary type='text'>iDefense has published an advisory for multiple remote pre-authentication code execution vulnerabilities in the EMC RepliStor software suite which were discovered by Stephen Fewer of Harmony Security.

You can read the full iDefense advisory here:

 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=664
</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/02/emc-replistor-multiple-heap-overflow.html' title='EMC RepliStor Multiple Heap Overflow Vulnerabilities'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/5135919079045739901'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/5135919079045739901'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-5889353824297891228</id><published>2008-01-09T16:51:00.000-08:00</published><updated>2008-06-25T07:09:20.237-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>Novell NetWare Client nicm.sys Local Privilege Escalation Vulnerability</title><summary type='text'>iDefense has published an advisory for a vulnerability in the Novell NetWare Client which was discovered by Stephen Fewer of Harmony Security. It is a local privilege escalation vulnerability whereby an unprivileged user can execute malicious code in kernel mode by exploiting an insecure IOCTL in the NCIM device driver.

You can read the full iDefense advisory here:

http://labs.idefense.com/</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/01/novell-netware-client-nicmsys-local.html' title='Novell NetWare Client nicm.sys Local Privilege Escalation Vulnerability'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/5889353824297891228'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/5889353824297891228'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-4603960331728900546</id><published>2008-01-09T16:44:00.000-08:00</published><updated>2008-06-25T07:09:20.237-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>Motorola netOctopus Agent MSR Write Privilege Escalation Vulnerability</title><summary type='text'>iDefense has published an advisory for a vulnerability in the Motorola netOctopus Agent which was discovered by Stephen Fewer of Harmony Security. It is a local privilege escalation vulnerability whereby an unprivileged user can reliably execute malicious code in ring 0 by hijacking the SYSENTER_EIP_MSR via an improperly exposed interface in the NantSys device driver.

You can read the full </summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/01/motorola-netoctopus-agent-msr-write.html' title='Motorola netOctopus Agent MSR Write Privilege Escalation Vulnerability'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4603960331728900546'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4603960331728900546'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-7582043074456525990</id><published>2008-01-09T16:40:00.000-08:00</published><updated>2008-06-25T07:09:20.238-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>Novell ZENworks Endpoint Security Management Local Privilege Escalation Vulnerability</title><summary type='text'>iDefense has published an advisory for a vulnerability in the  Novell ZENworks Endpoint Security Management (ESM) Security Client which was discovered by Stephen Fewer of Harmony Security. It is a local privilege escalation vulnerability whereby an unprivileged user can trivially run executables with SYSTEM privileges.

You can read the full iDefense advisory here:

http://labs.idefense.com/</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2008/01/novell-zenworks-endpoint-security.html' title='Novell ZENworks Endpoint Security Management Local Privilege Escalation Vulnerability'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/7582043074456525990'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/7582043074456525990'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-4653228930642584283</id><published>2007-12-13T14:19:00.000-08:00</published><updated>2008-06-25T07:09:33.852-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>[New Tool] OllyHeapTrace</title><summary type='text'>OllyHeapTrace is a plugin for OllyDbg (version 1.10) to trace the heap operations being performed by a process. It will monitor heap allocations and frees for multiple heaps, as well as operations such as creating or destroying heaps and reallocations. All parameters as well as return values are recorded and the trace is highlighted with a unique colour for each heap being traced.

The primary </summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/12/new-tool-ollyheaptrace.html' title='[New Tool] OllyHeapTrace'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4653228930642584283'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4653228930642584283'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-8683011937397147052</id><published>2007-11-13T14:06:00.000-08:00</published><updated>2008-06-25T07:09:20.238-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>Novell NetWare Client Privilege Escalation Vulnerability</title><summary type='text'>iDefense has published an advisory for a vulnerability in the Novell NetWare Client which was discovered by Stephen Fewer of Harmony Security. It is a local privilege escalation vulnerability whereby an unprivileged user can exploit the vulnerable driver nwfilter.sys and gain kernel mode code execution. Novell is issuing a patch that will remove the vulnerable driver.

You can read the full </summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/11/novell-netware-client-privilege.html' title='Novell NetWare Client Privilege Escalation Vulnerability'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/8683011937397147052'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/8683011937397147052'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-7717609215521497644</id><published>2007-11-06T16:01:00.000-08:00</published><updated>2008-06-25T07:09:20.239-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>Microsoft DebugView Privilege Escalation Vulnerability</title><summary type='text'>iDefense has published an advisory for a privilege escalation vulnerability in the Microsoft DebugView tool which was discovered by Stephen Fewer of Harmony Security. You can read the full iDefense advisory here:

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=621
</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/11/microsoft-debugview-privilege.html' title='Microsoft DebugView Privilege Escalation Vulnerability'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/7717609215521497644'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/7717609215521497644'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-4044687900526428383</id><published>2007-10-22T15:29:00.000-07:00</published><updated>2008-06-25T07:09:33.852-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>[New Tool] OllyCallTrace</title><summary type='text'>OllyCallTrace is a plugin for OllyDbg (version 1.10) to trace the call chain of a thread allowing you to monitor it for irregularities to aid in the debugging of stack based buffer overflows as well as to quickly plot the execution flow of a program you are reversing.

You can download OllyCallTrace from here:

http://www.harmonysecurity.com/OllyCallTrace.html
</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/10/new-tool-ollycalltrace.html' title='[New Tool] OllyCallTrace'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4044687900526428383'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4044687900526428383'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-6212176774141349548</id><published>2007-10-10T17:09:00.000-07:00</published><updated>2008-06-25T07:09:20.240-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>Kaspersky Web Scanner ActiveX Format String Vulnerability</title><summary type='text'>iDefense has published an advisory for a high-risk vulnerability in the Kaspersky online virus scanner which was discovered by Stephen Fewer of Harmony Security. You can read the full iDefense advisory here:

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=606

And you can read the Kaspersky response here:

http://www.kaspersky.com/news?id=207575572</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/10/kaspersky-web-scanner-activex-format.html' title='Kaspersky Web Scanner ActiveX Format String Vulnerability'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/6212176774141349548'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/6212176774141349548'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-637284026419868114</id><published>2007-08-09T19:51:00.000-07:00</published><updated>2008-06-25T07:09:20.241-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>[HS-A007] Qbik WinGate Remote Denial of Service</title><summary type='text'>WinGate by Qbik IP Management Limited is a sophisticated gateway and server product used in over 600,000 networks across the globe. WinGate provides a number of network services including an SMTP server for email. It is this SMTP server component that is vulnerable to a remotely exploitable format string vulnerability that can lead to a remote DoS attack, resulting in the entire WinGate service </summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/08/hs-a007-qbik-wingate-remote-denial-of.html' title='[HS-A007] Qbik WinGate Remote Denial of Service'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/637284026419868114'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/637284026419868114'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-6821490416945435179</id><published>2007-06-28T15:24:00.000-07:00</published><updated>2008-06-25T07:09:20.241-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advisories'/><title type='text'>[HS-A006] Multiple XSS in Wordpress theme K2</title><summary type='text'>Two Cross Site Scripting (XSS) vulnerabilities have been identified in K2, a popular theme for Wordpress. These are reflected XSS vulnerabilities and can allow for an attacker to craft a malicious URL which when accessed by a victim will allow an attacker to run arbitrary code, typically JavaScript, in the victims browser.You can read the advisory here:
http://www.harmonysecurity.com/HS-A006.html</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/06/new-advisory-multiple-xss-in-wordpress.html' title='[HS-A006] Multiple XSS in Wordpress theme K2'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/6821490416945435179'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/6821490416945435179'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-932717656972193247.post-4913259246827396417</id><published>2007-03-12T23:11:00.000-07:00</published><updated>2008-06-25T07:09:58.442-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Website Redux</title><summary type='text'>We are pleased to announce the long overdue overhaul of the Harmony Security website. An obvious addition has been the blog where we will be periodically posting news, views and various technical content on topics that are being worked on. Subscribe now to stay informed.</summary><link rel='alternate' type='text/html' href='http://www.harmonysecurity.com/blog/2007/03/website-redux.html' title='Website Redux'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4913259246827396417'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/932717656972193247/posts/default/4913259246827396417'/><author><name>Steve</name><email>noreply@blogger.com</email></author></entry></feed>