RSSAmplifier

OJ's Perspective · Jan 17, 2015

A Note on Disclosure

0
Sign in to vote or save

This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.

In October last year, while conducting an internal assessment for a client in Sydney, I found a vulnerability in a vendor product. The flaw allows for remote code execution on the device, as the root user , without requiring authentication. Needless to say, “instant remote root” vulnerabilities are bad. On the scale of bug severity, they’re up pretty high. For a device such as…

Read on /posts/a-note-on-disclosure/

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.