Re: [FD] A way to trigger CVE-2014-1322 (userspace read kernel pointer)?

2014-05-21 Thread Keira Cran
Just to clarify if getting 0x0 means it's patched, how can I verify that it's leaking legit kernel pointer when it's non-zero? best, keira On Tue, May 20, 2014, at 03:31 PM, Christian Mayer wrote: > Yes and no. > > On the first machine (OS X 10.9.2 (13C1021)) I got no pointer. Compiled > with Ap

Re: [FD] new pen-test tool!

2014-07-07 Thread Keira Cran
Nice idea. Has there been any test to see if the scores are actually meaningful? Perhaps, running this question test on an org and then doing a normal pentest to see if there is some correlation between (at least) the severity of the results? On Thu, Jul 3, 2014, at 04:44 AM, Pete Herzog wrote: >

[FD] Jamming WiFi tracking beacons

2014-07-16 Thread Keira Cran
Hey, It's great that companies like Apple recognising the threat of tracking people via their devices wifi cards' MAC addresses, by randomising them. Naturally, I wondered i it was possible to jam the measurement beacon by spoofing tons of wifi clients. At one point in London, there was an adver