EXODUS BLOG


Exploit Techniques

Firmware Updates Made Easy

SEPTEMBER 8, 2016
Contributors: David Barksdale of Exodus Intelligence, Independent Security Researcher Jeremy Brown These are two vulnerabilities that allow a remote unauthenticated attacker to update firmware. If the device is configured with MAC or IP filtering, the...
Read More

VxWorks: Execute My Packets

AUGUST 9, 2016
Contributors David Barksdale and Alex Wheeler 1. Background Earlier this year we reported 3 vulnerabilities in VxWorks to Wind River. Each of these vulnerabilities can be exploited by anonymous remote attackers on the same network without...
Read More

Exodus Intelligence 2016 Training Course

MAY 18, 2016
Vulnerability Development Master Class Since our inception, Exodus Intelligence has provided training courses on a variety of advanced subjects which have consistently been filled with students from around the world. Over the last few years, we’ve...
Read More

Execute My Packet

FEBRUARY 10, 2016
Contributors David Barksdale, Jordan Gruskovnjak, and Alex Wheeler 1. Background Cisco has issued a fix to address CVE-2016-1287. The Cisco ASA Adaptive Security Appliance is an IP router that acts as an application-aware firewall,...
Read More

Stagefright: Mission Accomplished?

AUGUST 13, 2015
Update (2015-08-13 1:16pm CST): We’ve been in contact with Zimperium and are working with them to provide coverage for detection of this flaw through their Stagefright Detector app. They have been very responsive (more...
Read More

Tails from the Cri2p

AUGUST 25, 2014
In continuation of the previous blog Fairy Tails and Silver Bullets we present the technical details of the flaws found in I2P (Invisible Internet Project) that also affects the Tails operating system.
Read More

Silver Bullets and Fairy Tails

JULY 23, 2014
Introduction This week we made mention on Twitter of a zero-day vulnerability we’ve unearthed that affects the popular Tails operating system. As the Tails website states: Tails is a live operating system, that you...
Read More

A browser is only as strong as its weakest byte

NOVEMBER 26, 2013
Back in September, FireEye posted a blog entry discussing CVE-2013-3147, a vulnerability in Microsoft Internet Explorer. They pointed out that Microsoft patched the issue on July 9th in Bulletin MS13-055. While reading their post...
Read More