<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; exploit</title>
	<atom:link href="http://hackaday.com/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Sun, 12 Feb 2012 06:24:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; exploit</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>The future of cyberattacks</title>
		<link>http://hackaday.com/2011/02/04/the-future-of-cyberattacks/</link>
		<comments>http://hackaday.com/2011/02/04/the-future-of-cyberattacks/#comments</comments>
		<pubDate>Fri, 04 Feb 2011 18:35:33 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=34198</guid>
		<description><![CDATA[[Dino A. Dai Zovi] gave a talk in the earlier part of 2010 where he shares his thoughts on the future of malicious exploits. You can watch it on Ustream and he&#8217;s also posted a set of slides (PDF) that goes along with it. We find the 48 minute video to be quite interested. Instead of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=34198&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-34200" title="future-of-cyberattacks" src="http://hackadaycom.files.wordpress.com/2011/02/future-of-cyberattacks.jpg" alt="" width="470" height="329" /></p>
<p>[Dino A. Dai Zovi] <a href="http://trailofbits.com/2010/11/10/memory-corruption-exploitation-and-you/">gave a talk in the earlier part of 2010</a> where he shares his thoughts on the future of malicious exploits. You can <a href="http://www.ustream.tv/recorded/5167328">watch it on Ustream</a> and he&#8217;s also posted <a href="http://trailofbits.files.wordpress.com/2010/11/owasp_201011.pdf">a set of slides</a> (PDF) that goes along with it. We find the 48 minute video to be quite interested. Instead of going into mundane detail, he covers the broader picture; what has been done in the past, what will happen in the future, and how are we currently ill-equipped to respond to future threats? That last question is covered throughout the video, but seems to come back to the concept that we are stuck in a rut of terminology and past practice that is impeding our ability to innovate security strategies at the same rate that the bad guys are coming up with the next nasty thing to come down the pipeline.</p>
<br />Filed under: <a href='http://hackaday.com/category/security-hacks/'>security hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/34198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/34198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/34198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/34198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/34198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/34198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/34198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/34198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/34198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/34198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/34198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/34198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/34198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/34198/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=34198&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2011/02/04/the-future-of-cyberattacks/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2011/02/future-of-cyberattacks.jpg" medium="image">
			<media:title type="html">future-of-cyberattacks</media:title>
		</media:content>
	</item>
		<item>
		<title>The new Apple TV</title>
		<link>http://hackaday.com/2010/09/30/the-new-apple-tv/</link>
		<comments>http://hackaday.com/2010/09/30/the-new-apple-tv/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 17:00:22 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[HackIt]]></category>
		<category><![CDATA[home entertainment hacks]]></category>
		<category><![CDATA[a4]]></category>
		<category><![CDATA[apple tv]]></category>
		<category><![CDATA[arm]]></category>
		<category><![CDATA[Cortex-A8]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[SHAtter]]></category>
		<category><![CDATA[xbmc]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=28746</guid>
		<description><![CDATA[You&#8217;ve probably already heard about the Apple TV 2. It retails for $99 and packs a punch with HD video, optical audio, and WiFi in that tiny package. But as always, we like it for its hackability. Even though it&#8217;s just starting to ship, the hacks are already rolling in. The firmware is available from [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=28746&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-28748" title="apple-tv-2" src="http://hackadaycom.files.wordpress.com/2010/09/apple-tv-2.jpg" alt="" width="470" height="353" /></p>
<p>You&#8217;ve probably already heard about the Apple TV 2. It retails for $99 and packs a punch with HD video, optical audio, and WiFi in that tiny package. But as always, we like it for its hackability. Even though it&#8217;s just starting to ship, the hacks are already rolling in. The firmware is available from Apple&#8217;s servers and <a href="http://www.mobilesdna.com/news/shatter-exploit-decrypts-apple-tv2-1-firmware-ios-4-1-successfully/1637/">has already been unlocked</a> with the yet-to-be-release SHAtter exploit. [Das_coach] even sent us a link to a video of <a href="http://www.youtube.com/watch?v=RTJ5yG2LyX8">the new Frontrow ported for the iPod touch</a> (embedded after the break).</p>
<p>But the holy grail has to be XBMC. We&#8217;ve seen it <a href="http://hackaday.com/2009/08/28/apple-tv-with-boxee-and-more-update/">on the first generation Apple TV</a> and it was good. The second generation switches to <a href="http://en.wikipedia.org/wiki/Apple_A4">the A4 processor</a> which is an ARM Cortex-A8. Not quite as easy to port for as the Intel chip on the first generation was. But there is hope, one of the 2010 Google Summer of Code projects worked to port <a href="http://hackaday.com/2010/05/27/gsoc-takes-on-xbmc-on-the-beagleboard/">XBMC to another ARM device</a>, it&#8217;s just a matter of inspiring some developers to take on the quest to make it happen. We can&#8217;t wait for the day that we can just velcro one of these to the back of our TV and be done with it, that first generation Xbox isn&#8217;t going to last forever.</p>
<p><span id="more-28746"></span><span style="text-align:center; display: block;"><a href="http://hackaday.com/2010/09/30/the-new-apple-tv/"><img src="http://img.youtube.com/vi/RTJ5yG2LyX8/2.jpg" alt="" /></a></span></p>
<p>[<a href="http://www.hd-report.com/2010/09/01/new-apple-tv-features/apple-tv-2-hand/">Photo credit</a>]</p>
<br />Filed under: <a href='http://hackaday.com/category/hackit/'>HackIt</a>, <a href='http://hackaday.com/category/home-entertainment-hacks/'>home entertainment hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/28746/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/28746/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/28746/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/28746/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/28746/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/28746/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/28746/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/28746/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/28746/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/28746/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/28746/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/28746/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/28746/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/28746/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=28746&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/09/30/the-new-apple-tv/feed/</wfw:commentRss>
		<slash:comments>38</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/09/apple-tv-2.jpg" medium="image">
			<media:title type="html">apple-tv-2</media:title>
		</media:content>
	</item>
		<item>
		<title>DRM causes vulnerabilities</title>
		<link>http://hackaday.com/2010/09/26/drm-causes-vulnerabilities/</link>
		<comments>http://hackaday.com/2010/09/26/drm-causes-vulnerabilities/#comments</comments>
		<pubDate>Sun, 26 Sep 2010 20:00:08 +0000</pubDate>
		<dc:creator>Caleb Kraft</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[digital rights management]]></category>
		<category><![CDATA[dll]]></category>
		<category><![CDATA[drm]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=28601</guid>
		<description><![CDATA[We often hear people touting the evilness of DRM, but usually they are talking about the idea of ownership. In this case, DRM is actually causing harm. It turns out that Microsoft&#8217;s msnetobj.dll, which is supposed to enforce DRM on your computer, stopping you from doing certain things like saving files you don&#8217;t &#8220;own&#8221; is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=28601&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-large wp-image-28605" title="DRM_hero" src="http://hackadaycom.files.wordpress.com/2010/09/drm_hero1.jpg?w=450&#038;h=106" alt="This image is from Microsoft's DRM page." width="450" height="106" /></p>
<p>We often hear people touting the evilness of DRM, but usually they are talking about the idea of ownership. In this case, DRM is actually causing harm. It turns out that Microsoft&#8217;s msnetobj.dll, which is supposed to enforce DRM on your computer, stopping you from doing certain things like saving files you don&#8217;t &#8220;own&#8221;<a href="http://www.exploit-db.com/exploits/15061/"> is open to 3 attacks</a>.  Vulnerable to <a href="http://en.wikipedia.org/wiki/Buffer_overflow">buffer overflow</a>, integer overflow, and denial of service, this sucker is riddled with issues.</p>
<p>The vulnerabilities in this file aren&#8217;t groundbreaking. Buffer overflow is a common method to get to many systems. The problem here, according to some commenters at BoingBoing, is the fact that this DLL is called every time you open a media file.</p>
<p>[via <a href="http://www.boingboing.net/2010/09/24/microsofts-drm-makes.html">BoingBoing</a>]</p>
<br />Filed under: <a href='http://hackaday.com/category/news/'>news</a>, <a href='http://hackaday.com/category/security-hacks/'>security hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/28601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/28601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/28601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/28601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/28601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/28601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/28601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/28601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/28601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/28601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/28601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/28601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/28601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/28601/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=28601&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/09/26/drm-causes-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>26</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Caleb Kraft</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/09/drm_hero1.jpg?w=450" medium="image">
			<media:title type="html">DRM_hero</media:title>
		</media:content>
	</item>
		<item>
		<title>PSGroove on a PIC microcontroller</title>
		<link>http://hackaday.com/2010/09/15/psgroove-on-a-pic-microcontroller/</link>
		<comments>http://hackaday.com/2010/09/15/psgroove-on-a-pic-microcontroller/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 15:24:46 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[playstation hacks]]></category>
		<category><![CDATA[18F2550]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[pic]]></category>
		<category><![CDATA[playstation 3]]></category>
		<category><![CDATA[ps3]]></category>
		<category><![CDATA[psgroove]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=28225</guid>
		<description><![CDATA[There&#8217;s now a method of using PIC microcontrollers to exploit the PlayStation 3. This is centered around a PIC 18F2550 which has been popular in past hacks because of its built-in USB serial port. This again makes use of the PSGroove open source exploit code and, like the TI calculator version, seeks to expand the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=28225&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-28226" title="psgroove-pic-uc" src="http://hackadaycom.files.wordpress.com/2010/09/psgroove-pic-uc-e1284562590552.png" alt="" width="470" height="209" /></p>
<p>There&#8217;s now <a href="http://psx-scene.com/forums/showthread.php?t=65391">a method of using PIC microcontrollers to exploit the PlayStation 3</a>. This is centered around a PIC 18F2550 which has been <a href="http://hackaday.com/2010/08/05/rgb-vu-meter/">popular in past hacks</a> because of its built-in USB serial port. This again makes use of <a href="http://hackaday.com/2010/09/01/open-source-version-of-the-play-station-3-jailbreak/">the PSGroove open source exploit code</a> and, like <a href="http://hackaday.com/2010/09/10/playstation-3-exploit-using-a-ti84-calculator/">the TI calculator version</a>, seeks to expand the selection of hardware the code runs on.</p>
<p>In addition to the chip and a PIC programmer you&#8217;ll need the CCS compiler as others cannot successfully compile this code. A licensed copy is necessary because the demo version of the CCS compiler doesn&#8217;t support this particular chip. Add to that the fact that because of the timing it may take several tries to achieve the exploit and you may find yourself disappointed by this development. But there&#8217;s always room for improvement and this is a proven first step on the new architecture.</p>
<p>[Thanks das_coach via <a href="http://www.ps3hax.net/downloads.php?do=file&amp;id=399">PS3Hax</a> via <a href="http://www.elotrolado.net/viewtopic.php?f=179&amp;t=1479909&amp;p=1721567279#p1721567279">Elotrolado</a>]</p>
<br />Filed under: <a href='http://hackaday.com/category/playstation-hacks/'>playstation hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/28225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/28225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/28225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/28225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/28225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/28225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/28225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/28225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/28225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/28225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/28225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/28225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/28225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/28225/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=28225&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/09/15/psgroove-on-a-pic-microcontroller/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/09/psgroove-pic-uc-e1284562590552.png" medium="image">
			<media:title type="html">psgroove-pic-uc</media:title>
		</media:content>
	</item>
		<item>
		<title>PS3 exploit released</title>
		<link>http://hackaday.com/2010/01/27/ps3-exploit-released/</link>
		<comments>http://hackaday.com/2010/01/27/ps3-exploit-released/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 14:37:55 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[playstation hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[memory]]></category>
		<category><![CDATA[playstation 3]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=21123</guid>
		<description><![CDATA[You can now download the exploit package for the PlayStation 3. [Geohot] just posted the code you need to pull off the exploit we told you about on Sunday, making it available on a &#8220;silver platter&#8221; with just a bit of explanation on how it works. He&#8217;s located a critical portion of the memory to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=21123&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-21124" title="ps3_exploited" src="http://hackadaycom.files.wordpress.com/2010/01/ps3_exploited.jpg" alt="" width="470" height="301" /></p>
<p>You can now <a href="http://geohotps3.blogspot.com/2010/01/heres-your-silver-platter.html">download the exploit package for the PlayStation 3</a>. [Geohot] just posted the code you need to pull off <a href="http://hackaday.com/2010/01/24/ps3-hacked/">the exploit we told you about</a> on Sunday, making it available on a &#8220;silver platter&#8221; with <a href="http://pastie.org/795944">just a bit of explanation</a> on how it works. He&#8217;s located a critical portion of the memory to attack. By allocating it, pointing a whole bunch of code at those addresses, then deallocating it he causes many calls to invalid addresses. At the same time as those invalid calls he &#8220;glitches&#8221; the memory bus using a button on his FPGA board to hold it low for 40ns. This trips up the hypervisor security and somehow allows read/write access to that section of memory. Gentleman and Ladies, start your hacking. We wish you the best of luck!</p>
<p>[Thanks Phileas]</p>
<br />Posted in playstation hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/21123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/21123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/21123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/21123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/21123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/21123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/21123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/21123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/21123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/21123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/21123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/21123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/21123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/21123/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=21123&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/01/27/ps3-exploit-released/feed/</wfw:commentRss>
		<slash:comments>53</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/01/ps3_exploited.jpg" medium="image">
			<media:title type="html">ps3_exploited</media:title>
		</media:content>
	</item>
		<item>
		<title>Lightning Rod: keeps you safe from dirty Flashers</title>
		<link>http://hackaday.com/2010/01/01/lighting-rod-keeps-you-safe-from-dirty-flashers/</link>
		<comments>http://hackaday.com/2010/01/01/lighting-rod-keeps-you-safe-from-dirty-flashers/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 20:00:13 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[26c3]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[chaos communications congress]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[lightning rod]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=20152</guid>
		<description><![CDATA[A new open source package called Lightning Rod will help to close security exploits in Adobe&#8217;s dirty Flash code. A presentation made at the 26th Chaos Communication Congress showed that the package does its job by reviewing incoming code before the browser executes it. Heise Online is reporting that this method can block over 20 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=20152&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-20155" title="flash-code-protection" src="http://hackadaycom.files.wordpress.com/2010/01/flash-code-protection1.jpg" alt="" width="470" height="313" /></p>
<p>A new <a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;ie=UTF-8&amp;sl=de&amp;tl=en&amp;u=http://blitzableiter.recurity.com/&amp;prev=_t&amp;rurl=translate.google.com&amp;twu=1&amp;usg=ALkJrhh5zwOnDLBaBo0ceaZm16eP0mgabw">open source package called Lightning Rod</a> will help to close security exploits in Adobe&#8217;s dirty Flash code. A presentation made at the <a href="http://events.ccc.de/congress/2009/wiki/Welcome">26th Chaos Communication Congress</a> showed that the package does its job by reviewing incoming code before the browser executes it. <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.heise.de%2Fnewsticker%2Fmeldung%2F26C3-Schutz-gegen-Flash-Sicherheitsluecken-893588.html&amp;sl=de&amp;tl=en">Heise Online is reporting</a> that this method can block over 20 different known attacks and can even be used to filter out <a href="http://news.zdnet.com/2100-1009_22-138733.html">malicious JPG</a> attacks. As more vulnerabilities are discovered they can be added to Lightning Rod to close the breach. This amounts to a virus scanner for Flash code. It&#8217;s great to have this type of protection but why can&#8217;t Adobe handle its security problems?</p>
<p>[<a href="http://thebsreport.wordpress.com/2009/11/14/flasher-causes-bus-to-hit-police-station/">Photo Credit</a>]</p>
<p>[Thanks das_coach]</p>
<br />Posted in security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/20152/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=20152&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/01/01/lighting-rod-keeps-you-safe-from-dirty-flashers/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/01/flash-code-protection1.jpg" medium="image">
			<media:title type="html">flash-code-protection</media:title>
		</media:content>
	</item>
		<item>
		<title>freeBOOT gives the Xbox 360 JTAG hack new life</title>
		<link>http://hackaday.com/2009/10/20/freeboot-gives-the-xbox-360-jtag-hack-new-life/</link>
		<comments>http://hackaday.com/2009/10/20/freeboot-gives-the-xbox-360-jtag-hack-new-life/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 20:00:42 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[xbox hacks]]></category>
		<category><![CDATA[cygnos360]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[freeBoot]]></category>
		<category><![CDATA[jtag]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mod chip]]></category>
		<category><![CDATA[xbox 360]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=17550</guid>
		<description><![CDATA[There has been another development in the never-ending battle that is Microsoft trying to keep its gaming system closed to unauthorized use. Xbox-scene reports that a new hack called freeBOOT v0.01 allows the Xbox 360 to upgrade to the newer kernels, but allows the option of rebooting to an older kernel in order use the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=17550&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-17551" title="xbox360-freeBOOT-exploit" src="http://hackadaycom.files.wordpress.com/2009/10/xbox360-freeboot-exploit.jpg" alt="xbox360-freeBOOT-exploit" width="470" height="335" /></p>
<p>There has been another development in the never-ending battle that is Microsoft trying to keep its gaming system closed to unauthorized use. <a href="http://www.xbox-scene.com/xbox1data/sep/EkVVAEkpZELlGflwlM.php">Xbox-scene reports that a new hack</a> called freeBOOT v0.01 allows the Xbox 360 to upgrade to the newer kernels, but allows the option of rebooting to an older kernel in order use the JTAG exploit and gain access to the hardware.</p>
<p>In case you missed it, the <a href="http://www.free60.org/JTAG_Hack">JTAG hack</a> is a way to run <a href="http://hackaday.com/2009/08/17/snes-on-an-xbox360/">homebrew code on an Xbox 360</a>. Exploiting this hack makes it possible to boot a Linux kernel in about five seconds. We&#8217;ve long been fans of the <a href="http://hackaday.com/2008/09/20/xbmc-cross-platform-beta-released/">homebrew work done with XBMC</a> on the original Xbox and hope that advances like this will lead to that end. We want this because the older hardware cannot handle high definition content at full resolution but the Xbox 360 certainly can.</p>
<p>This exploit is still far from perfect. It currently requires that the <a href="http://www.cygnos360.com/">Cygnos360 mod chip</a> be installed on the system. A resistor also needs to be removed from the board to prevent accidental kernel updating. That being said, this is still progress. If you&#8217;re interested in step-by-step details, <a href="http://dwl.xbox-scene.com/nfo/freebootv0.01.txt">take a look at the text file instructions provided</a>.</p>
<p>[Thanks wdfowty]</p>
<br />Posted in security hacks, xbox hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/17550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/17550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/17550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/17550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/17550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/17550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/17550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/17550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/17550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/17550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/17550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/17550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/17550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/17550/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=17550&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/10/20/freeboot-gives-the-xbox-360-jtag-hack-new-life/feed/</wfw:commentRss>
		<slash:comments>37</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/10/xbox360-freeboot-exploit.jpg" medium="image">
			<media:title type="html">xbox360-freeBOOT-exploit</media:title>
		</media:content>
	</item>
		<item>
		<title>Android app &#8220;tests&#8221; Windows vulnerability</title>
		<link>http://hackaday.com/2009/09/14/android-app-tests-windows-vulnerability/</link>
		<comments>http://hackaday.com/2009/09/14/android-app-tests-windows-vulnerability/#comments</comments>
		<pubDate>Mon, 14 Sep 2009 20:30:26 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[android hacks]]></category>
		<category><![CDATA[pcs hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[server 2008]]></category>
		<category><![CDATA[smb]]></category>
		<category><![CDATA[smb2]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=15396</guid>
		<description><![CDATA[An Android App for &#8220;testing&#8221; the Windows SMB2 vulnerability we covered last week has been released. For testing? Yeah right! The availability of this kind of software makes it ridiculously easy for anybody to go out and cause some havoc. Go right now and double check that your machines that run Windows Vista or Windows [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=15396&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-15403" title="android_windows_vulnerability_checker" src="http://hackadaycom.files.wordpress.com/2009/09/android_windows_vulnerability_checker1.jpg" alt="android_windows_vulnerability_checker" width="320" height="392" /></p>
<p>An <a href="http://sinisterware.blogspot.com/2009/09/smb-check.html">Android App for &#8220;testing&#8221;</a> the Windows <a href="http://hackaday.com/2009/09/09/windows-7-and-vista-crash-via-smb-exploit/">SMB2 vulnerability we covered last week</a> has been released. For testing? Yeah right! The availability of this kind of software makes it ridiculously easy for anybody to go out and cause some havoc. Go right now and double check that your machines that run Windows Vista or Windows Server 2008 <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">are protected</a> (see the &#8220;workarounds&#8221; section.)</p>
<p>[Thanks Tom101]</p>
<br />Posted in android hacks, pcs hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/15396/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/15396/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/15396/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/15396/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/15396/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/15396/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/15396/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/15396/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/15396/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/15396/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/15396/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/15396/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/15396/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/15396/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=15396&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/09/14/android-app-tests-windows-vulnerability/feed/</wfw:commentRss>
		<slash:comments>48</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/09/android_windows_vulnerability_checker1.jpg" medium="image">
			<media:title type="html">android_windows_vulnerability_checker</media:title>
		</media:content>
	</item>
		<item>
		<title>Homebrew Wii via the bannerbomb exploit</title>
		<link>http://hackaday.com/2009/08/21/homebrew-wii-via-the-bannerbomb-exploit/</link>
		<comments>http://hackaday.com/2009/08/21/homebrew-wii-via-the-bannerbomb-exploit/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 21:18:35 +0000</pubDate>
		<dc:creator>Matt Schultz</dc:creator>
				<category><![CDATA[wii hacks]]></category>
		<category><![CDATA[bannerbomb]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[homebrew]]></category>
		<category><![CDATA[lifehacker]]></category>
		<category><![CDATA[twilight princess]]></category>
		<category><![CDATA[wii]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=13582</guid>
		<description><![CDATA[The Twilight Princess hack doesn&#8217;t work on newer versions of the Nintendo Wii, but thanks to a new exploit for the Wii, homebrew is still possible. Using an SD card and a few files, you can have the homebrew channel up and running in no time. The folks at Lifehacker show us how it&#8217;s done. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=13582&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-13583" title="bannerbomb_exploit" src="http://hackadaycom.files.wordpress.com/2009/08/bannerbomb_exploit.jpg" alt="bannerbomb_exploit" width="470" height="290" /></p>
<p>The Twilight Princess hack doesn&#8217;t work on newer versions of the Nintendo Wii, but thanks to <a href="http://bannerbomb.qoid.us/">a new exploit</a> for the Wii, homebrew is still possible. Using an SD card and a few files, you can have the homebrew channel up and running in no time. The folks at Lifehacker show us <a href="http://lifehacker.com/5342733/hack-your-wii-for-homebrew-without-twilight-princess">how it&#8217;s done</a>. It&#8217;s good to see that the Wii modding community is still in full force. Hopefully, this won&#8217;t turn into a back and forth battle between modders and Nintendo, like it has with <a href="http://hackaday.com/2009/05/07/psp-3000-firmware-503-hacked/">Sony</a> <a href="http://hackaday.com/2008/11/19/psp-3000-hacked/">and</a> <a href="http://hackaday.com/2008/10/18/psp-firmware-500-hacked/">the</a> <a href="http://hackaday.com/2007/01/30/psp-downgrader-for-v303-released/">PSP</a>.</p>
<br />Posted in wii hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/13582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/13582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/13582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/13582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/13582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/13582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/13582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/13582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/13582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/13582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/13582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/13582/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/13582/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/13582/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=13582&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/08/21/homebrew-wii-via-the-bannerbomb-exploit/feed/</wfw:commentRss>
		<slash:comments>26</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">mattcraigschultz</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/08/bannerbomb_exploit.jpg" medium="image">
			<media:title type="html">bannerbomb_exploit</media:title>
		</media:content>
	</item>
		<item>
		<title>BackTrack 4 Beta released</title>
		<link>http://hackaday.com/2009/02/10/backtrack-4-beta-released/</link>
		<comments>http://hackaday.com/2009/02/10/backtrack-4-beta-released/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 04:00:54 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[tool hacks]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[distro]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[fpga]]></category>
		<category><![CDATA[iso]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[remote-exploit]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=8448</guid>
		<description><![CDATA[The Remote Exploit Development Team has just announced BackTrack 4 Beta. BackTrack is a Linux based LiveCD intended for security testing and we&#8217;ve been watching the project since the very early days. They say this new beta is both stable and usable. They&#8217;ve moved towards behaving like an actual distribution: it&#8217;s based on Debian core, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=8448&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-8449" title="backtrack" src="http://hackadaycom.files.wordpress.com/2009/02/backtrack.jpg" alt="backtrack" width="450" height="176" /></p>
<p>The <a title="Remote-Exploit.org - Supplying offensive security products to the world" href="http://remote-exploit.org/">Remote Exploit Development Team</a> has just <a title="BackTrack 4 Beta Public Released" href="http://backtrack4.blogspot.com/2009/02/backtrack-4-beta-public-released.html">announced BackTrack 4 Beta</a>. BackTrack is a Linux based LiveCD intended for security testing and we&#8217;ve been watching the project since the very early days. They say this new beta is both stable and usable. They&#8217;ve moved towards behaving like an actual distribution: it&#8217;s based on Debian core, they use Ubuntu software, and they&#8217;re running their own BackTrack repositories for future updates. There are a lot of new features, but the one we&#8217;re most interested in is the built in <a title="Pico Computing, Inc" href="http://picocomputing.com/">Pico</a> card support. You can use the <a href="http://en.wikipedia.org/wiki/FPGA">FPGA</a>s to generate rainbow tables and do lookups for things like WPA, <a title="Intercepting GSM Traffic  - Hack a Day" href="http://hackaday.com/2008/02/15/shmoocon-2008-intercepting-gsm-traffic/">GSM</a>, and Bluetooth cracking. <a title="Remote-Exploit.org - Supplying offensive security products to the world" href="http://www.remote-exploit.org/backtrack_download.html">BackTrack ISO and VMWare images are available here</a>.</p>
<br />Posted in downloads hacks, security hacks, tool hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/8448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/8448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/8448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/8448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/8448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/8448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/8448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/8448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/8448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/8448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/8448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/8448/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/8448/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/8448/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=8448&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/02/10/backtrack-4-beta-released/feed/</wfw:commentRss>
		<slash:comments>99</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/02/backtrack.jpg" medium="image">
			<media:title type="html">backtrack</media:title>
		</media:content>
	</item>
		<item>
		<title>iPod Touch 2G jailbreak demoed</title>
		<link>http://hackaday.com/2009/01/17/ipod-touch-2g-jailbreak-demoed/</link>
		<comments>http://hackaday.com/2009/01/17/ipod-touch-2g-jailbreak-demoed/#comments</comments>
		<pubDate>Sun, 18 Jan 2009 01:35:08 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[digital audio hacks]]></category>
		<category><![CDATA[ipod hacks]]></category>
		<category><![CDATA[macs hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[appstore]]></category>
		<category><![CDATA[cydia]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[iboot]]></category>
		<category><![CDATA[iphone dev team]]></category>
		<category><![CDATA[ipod]]></category>
		<category><![CDATA[ipod touch]]></category>
		<category><![CDATA[ipod touch 2g]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[kernel]]></category>
		<category><![CDATA[musclenerd]]></category>
		<category><![CDATA[nes]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[redsn0w]]></category>
		<category><![CDATA[yellowsn0w]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7951</guid>
		<description><![CDATA[Now that the iphone-dev team has unlocked the iPhone 3G they&#8217;re moving onto jailbreaking the iPod Touch 2G. While they have a fully working jailbreak, it&#8217;s not yet in a user friendly format. [MuscleNerd] did a live video demo this afternoon to show what progress they had made. It starts with him showing the iPod [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7951&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><img class="size-full wp-image-7952 aligncenter" title="redsn0w" src="http://hackadaycom.files.wordpress.com/2009/01/redsn0w.jpg" alt="redsn0w" width="405" height="319" /></p>
<p>Now that the iphone-dev team has <a title="iPhone 3G unlock released  - Hack a Day" href="http://hackaday.com/2009/01/01/iphone-3g-unlock-released/">unlocked the iPhone 3G</a> they&#8217;re moving onto jailbreaking the <a title="IPod Touch 2G - Mahalo" href="http://www.mahalo.com/IPod_Touch_2G">iPod Touch 2G</a>. While they have a fully working jailbreak, it&#8217;s not yet in a user friendly format. [MuscleNerd] did a <a title="A Walkthrough" href="http://www.appleiphoneapps.com/2008/07/how-to-use-cydia-a-walkthrough/">live video demo this afternoon</a> to show what progress they had made. It starts with him showing the <a title="iPod - Mahalo" href="http://www.mahalo.com/IPod">iPod</a> on but not booting. He&#8217;s already patched the kernel, but it&#8217;s failing the signature check in iboot. He then uses the team&#8217;s recoverytool to exploit a hole in iboot and patch out the signature check. The ipod then boots normally and he shows non-App Store software like Mobile Terminal, <a title="A Walkthrough" href="http://www.appleiphoneapps.com/2008/07/how-to-use-cydia-a-walkthrough/">Cydia</a>, and an NES Emulator (which makes use of the iPod&#8217;s internal speaker).</p>
<p>The <a title="Dev-Team Blog - Thermonuclear pop!" href="http://blog.iphone-dev.org/post/70407787/thermonuclear-pop">redsn0w jailbreak</a> works, but it has to be applied via tether every time the iPod boots. The team won&#8217;t release anything until they&#8217;ve found a way around this problem. For more insight into the boot process, check out our coverage of their <a title="Hacking the iPhone  - Hack a Day" href="http://hackaday.com/2008/12/28/25c3-hacking-the-iphone/">Hacking the iPhone</a> talk at 25C3.</p>
<br />Posted in digital audio hacks, ipod hacks, macs hacks, news  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7951/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7951&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/01/17/ipod-touch-2g-jailbreak-demoed/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/01/redsn0w.jpg" medium="image">
			<media:title type="html">redsn0w</media:title>
		</media:content>
	</item>
		<item>
		<title>Homebrew on the PSP3000</title>
		<link>http://hackaday.com/2009/01/05/homebrew-on-the-psp3000/</link>
		<comments>http://hackaday.com/2009/01/05/homebrew-on-the-psp3000/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 20:24:04 +0000</pubDate>
		<dc:creator>Caleb Kraft</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[playstation hacks]]></category>
		<category><![CDATA[psp hacks]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[playstation]]></category>
		<category><![CDATA[psp]]></category>
		<category><![CDATA[psp3000]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7536</guid>
		<description><![CDATA[[matiaz] has released an exploit which allows homebrew on the PSP3000. It takes advantage of a vulnerability when loading save games on a game called GripShift. You can see the PSP running unsigned code in the video. [thanks wraggy] Posted in news, playstation hacks, psp hacks<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7536&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<span style="text-align:center; display: block;"><a href="http://hackaday.com/2009/01/05/homebrew-on-the-psp3000/"><img src="http://img.youtube.com/vi/0KdIrzsi4IA/2.jpg" alt="" /></a></span>
<p>[matiaz] has released an exploit which allows <a href="http://psp-news.dcemu.co.uk/gripshift-savegame-exploit-hello-world-sparta-sdk-exploit-works-on-psp-3000-178349.html">homebrew on the PSP3000</a>. It takes advantage of a vulnerability when loading save games on a game called GripShift. You can see the PSP running unsigned code in the video.</p>
<p>[thanks wraggy]</p>
<br />Posted in news, playstation hacks, psp hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7536/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7536/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7536/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7536&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/01/05/homebrew-on-the-psp3000/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Caleb Kraft</media:title>
		</media:content>
	</item>
		<item>
		<title>DNS exploit in the wild</title>
		<link>http://hackaday.com/2008/07/23/dns-exploit-in-the-wild/</link>
		<comments>http://hackaday.com/2008/07/23/dns-exploit-in-the-wild/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 02:00:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[dankaminsky]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[druid]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hdmoore]]></category>
		<category><![CDATA[matasano]]></category>
		<category><![CDATA[metasploit]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/07/23/dns-exploit-in-the-wild/</guid>
		<description><![CDATA[We&#8217;ve been tracking Metasploit commits since Matasano&#8217;s premature publication of [Dan Kaminsky]&#8216;s DNS cache poisoning flaw on Monday knowing full well that a functional exploit would be coming soon. Only two hours ago [HD Moore] and [I)ruid] added a module to the Metasploit Project that will let anyone test the vulnerability (with comment: &#8220;ZOMG. What [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2329&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="110" border="0" src="http://hackadaycom.files.wordpress.com/2008/06/had_switch.jpg?w=450&#038;h=110" alt="" /><br />We&#8217;ve been tracking <a href="http://metasploit.com/">Metasploit</a> commits since Matasano&#8217;s <a href="http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html">premature publication</a> of [Dan Kaminsky]&#8216;s DNS cache poisoning flaw on Monday knowing full well that a functional exploit would be coming soon. Only two hours ago [HD Moore] and [I)ruid] added a module to the Metasploit Project that will let anyone test the vulnerability (with comment: &#8220;<a href="http://metasploit.com/dev/trac/browser/framework3/trunk/modules/auxiliary/spoof/dns/baliwicked_host.rb?rev=5579">ZOMG. What is this? &gt;:-)</a>&#8220;). [HD] <a href="http://blog.wired.com/27bstroke6/2008/07/dns-exploit-in.html">told Threat Level</a> that it doesn&#8217;t work yet for domains that are already cached by the DNS server, but it will automatically wait for the cached entry to expire and then complete the attack. You can read more about the bailiwicked_host.rb module <a href="http://www.caughq.org/exploits/CAU-EX-2008-0002.txt">in CAU&#8217;s advisory</a>. For a more detailed description of how the attack works, see this <a href="http://beezari.livejournal.com/141796.html">mirror of Matason&#8217;s post</a>. You can check if the DNS server you are using is vulnerable by <a href="http://www.doxpara.com/">using the tool on [Dan]&#8216;s site</a>.</p>
<p>[photo: <a href="http://flickr.com/photos/dork/413073001/">mattdork</a>]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2329/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2329/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2329/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2329&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/07/23/dns-exploit-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had_switch.jpg" medium="image" />
	</item>
		<item>
		<title>Neutering the Apple Remote Desktop exploit</title>
		<link>http://hackaday.com/2008/06/19/neutering-the-apple-remote-desktop-exploit/</link>
		<comments>http://hackaday.com/2008/06/19/neutering-the-apple-remote-desktop-exploit/#comments</comments>
		<pubDate>Thu, 19 Jun 2008 23:45:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[macs hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[appleremotedesktop]]></category>
		<category><![CDATA[applescript]]></category>
		<category><![CDATA[ard]]></category>
		<category><![CDATA[ardagent]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[OsX]]></category>
		<category><![CDATA[slashdot]]></category>
		<category><![CDATA[tuaw]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/19/neutering-the-apple-remote-desktop-exploit/</guid>
		<description><![CDATA[Yesterday, Slashdot reported a privilege escalation vulnerability in OSX. Using AppleScript you can tell the ARDAgent to execute arbitrary shell script. Since, ARDAgent is running as root, all child processes inherit root privleges. Intego points out that if the user has activated Apple Remote Desktop sharing the ARDAgent can&#8217;t be exploited in this fashion. So, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2050&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="110" border="0" alt=""  src="http://hackadaycom.files.wordpress.com/2008/06/had_ard.jpg?w=450&#038;h=110" /><br />Yesterday, Slashdot reported a <a href="http://it.slashdot.org/it/08/06/18/1919224.shtml">privilege escalation vulnerability in OSX</a>. Using AppleScript you can tell the ARDAgent to execute arbitrary shell script. Since, ARDAgent is running as root, all child processes inherit root privleges. Intego <a href="http://www.intego.com/news/ism0802.asp">points out</a> that if the user has activated Apple Remote Desktop sharing the ARDAgent can&#8217;t be exploited in this fashion. So, the short term solution is to turn on ARD, which you can do without giving any accounts access privileges. <a href="http://www.tuaw.com/ardfix/">TUAW has an illustrated guide</a> to doing this in 10.4 and 10.5.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2050/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2050/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2050/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2050/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2050/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2050/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2050/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2050/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2050/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2050/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2050/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2050/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2050/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2050/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2050/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2050/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2050&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/19/neutering-the-apple-remote-desktop-exploit/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had_ard.jpg" medium="image" />
	</item>
	</channel>
</rss>
