EXODUS BLOG


Exodus Intel VRT

To ../ or not to ../, that is the question

SEPTEMBER 13, 2018
Contributors: Grant Willcox and Gaurav Baruah Intro During our day-to-day research of N-day vulnerabilities at Exodus, we often come across public advisories containing incorrect root cause analysis of the core vulnerability. This blogpost details...
Read More

True Key: the not so uncommon story of a failed patch

SEPTEMBER 10, 2018
In this blog post, we examine the vendor-supplied patch addressing CVE-2018-6661.  The vulnerability was initially reported to Intel Security (McAfee) in June 2017 and disclosed publicly in April 2018.  Additionally, we contacted McAfee regarding the...
Read More

Introduction to Embedded Exploitation

SEPTEMBER 5, 2018
We are pleased to announce the offering of our next training course. This is a 5 day course and will focus on vulnerability research on embedded systems. Instructors David Barksdale – David is Director...
Read More

Fuzzing Grammars in Python: gramfuzz

JANUARY 3, 2017
Grammar-based fuzzing is not new, nor is my grammar-based fuzzer; however, this is my fifth, best, and favorite rewrite of it. My grammar fuzzer started with the original version in ruby, and then over the years...
Read More

Firmware Updates Made Easy

SEPTEMBER 8, 2016
Contributors: David Barksdale of Exodus Intelligence, Independent Security Researcher Jeremy Brown These are two vulnerabilities that allow a remote unauthenticated attacker to update firmware. If the device is configured with MAC or IP filtering, the...
Read More

VxWorks: Execute My Packets

AUGUST 9, 2016
Contributors David Barksdale and Alex Wheeler 1. Background Earlier this year we reported 3 vulnerabilities in VxWorks to Wind River. Each of these vulnerabilities can be exploited by anonymous remote attackers on the same network without...
Read More

Changing to Coordinated Disclosure

FEBRUARY 18, 2016
UPDATE 5/17/2016: The link for the POC for CVE-2016-1287 is live at https://github.com/exodusintel/disclosures Last week Exodus finished disclosure on CVE-2016-1287 “Cisco ASA Software IKEv1 and IKEv2 Buffer Overflow Vulnerability” officially marking the first time that...
Read More