Papers

   

 
Sep 06, 2010

Adobe Acrobat Reader acroform_PlugInMain memory corruption

Following previous report on this api that injects null code, more analysis on another part of this api was done and we found another vulnerability.

details...

 
Aug 25, 2010

Adobe Acrobat Reader All version Memory Corruption

The vulnerability was discovered in all versions of the program is available in our regular program open Acrobat reader and then attach AcroRd32.exe in windbg debugger. then from the file menu open our poc files.This vulnerability when loading a program when the api name acroform.api program reaches an error that follows on to eat.

details...

 
Jun 20, 2010

Quick guide to SQL Injection attacks and defenses

A SQL injection attack consists of insertion or "injection" of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to effect the execution of predefined SQL commands...

details...

          1  2  >  >>

 

All rights reserved to ITSecTeam Security Research.