<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5240287929972979182</id><updated>2011-04-21T13:36:50.355-07:00</updated><title type='text'>Code Audit Labs</title><subtitle type='html'>blog for http://www.VulnHunt.com ,professional Code Audit Laboratory.
include source code audit and binary code audit.
if you need Code audit service, feel free to contact us, vulnhunt at gmail.com</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://codeaudit.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240287929972979182/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://codeaudit.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Code Audit Lab</name><uri>http://www.blogger.com/profile/05115135831495791532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5240287929972979182.post-5101667071024748273</id><published>2007-07-30T20:20:00.000-07:00</published><updated>2007-07-30T20:29:41.081-07:00</updated><title type='text'>CAL-20070730-1 BlueSkyCat ActiveX Remote Heap Overflow vulnerability</title><content type='html'>CAL-20070730-1 BlueSkyCat ActiveX Remote Heap Overflow vulnerability&lt;br /&gt;&lt;br /&gt;BACKGROUND:&lt;br /&gt;===========&lt;br /&gt;&lt;br /&gt;   BlueSkychat is a professional voice and video chat software widely used&lt;br /&gt;by large chat websites in china.&lt;br /&gt;&lt;br /&gt;DESCRIPTION:&lt;br /&gt;============&lt;br /&gt;&lt;br /&gt;   Code Audit Labs Code Audit for BlueSkyCat ActiveX Control and discovered&lt;br /&gt;a vulnerability .&lt;br /&gt;&lt;br /&gt;   Remote exploitation of a buffer overflow in an ActiveX control&lt;br /&gt;distributed&lt;br /&gt;with Bluesky.cn could allow for the execution of arbitrary code.&lt;br /&gt;&lt;br /&gt;   When Blueskychat are installed, they register the following ActiveX&lt;br /&gt;control on the system:&lt;br /&gt;&lt;br /&gt;   ProgId: V2.V2Ctrl.1&lt;br /&gt;   ClassId: 2EA6D939-4445-43F1-A12B-8CB3DDA8B855&lt;br /&gt;   File: v2.ocx&lt;br /&gt;&lt;br /&gt;   This control contains a buffer overflow in its ConnecttoServer() method.&lt;br /&gt;&lt;br /&gt;   This is a clent side vulnerability. So the clients of following chat&lt;br /&gt;servers which install the affected BlueSkyCat software are affected.&lt;br /&gt;bliao http://www.bliao.com&lt;br /&gt;qqliao http://www.qqliao.com&lt;br /&gt;7liao http://www.7liao.com&lt;br /&gt;haoliao http://www.haoliao.net&lt;br /&gt;51liao http://chat.51liao.net&lt;br /&gt;heshang http://www.heshang.net&lt;br /&gt;xicn http://vchat.xicn.net&lt;br /&gt;CN104 http://www.cn104.com&lt;br /&gt;liao-tian http://www.liao-tian.com&lt;br /&gt;aliao http://www.aliao.net&lt;br /&gt;kuailiao http://www.kuailiao.com&lt;br /&gt;mtliao http://www.mtliao.com&lt;br /&gt;pj0427 http://www.pj0427.com&lt;br /&gt;uighur http://chat.uighur.cn&lt;br /&gt;wmliao http://www.wmliao.com &lt;br /&gt;&lt;br /&gt;see full report:&lt;br /&gt;&lt;a href="http://www.vulnhunt.com/advisories/CAL-20070730-1_BlueSkyCat_v2.ocx_ActiveX_remote_heap_overflow_vulnerability_en.txt"&gt;&lt;br /&gt;english&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.vulnhunt.com/advisories/CAL-20070730-1_BlueSkyCat_v2.ocx_ActiveX_remote_heap_overflow_vulnerability.txt"&gt;&lt;br /&gt;chinese&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240287929972979182-5101667071024748273?l=codeaudit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codeaudit.blogspot.com/feeds/5101667071024748273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5240287929972979182&amp;postID=5101667071024748273' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240287929972979182/posts/default/5101667071024748273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240287929972979182/posts/default/5101667071024748273'/><link rel='alternate' type='text/html' href='http://codeaudit.blogspot.com/2007/07/cal-20070730-1-blueskycat-activex.html' title='CAL-20070730-1 BlueSkyCat ActiveX Remote Heap Overflow vulnerability'/><author><name>Code Audit Lab</name><uri>http://www.blogger.com/profile/05115135831495791532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240287929972979182.post-1727821938852992590</id><published>2007-07-05T19:01:00.000-07:00</published><updated>2007-07-05T19:10:20.013-07:00</updated><title type='text'>[0day wild]symantec anti-virus Local Privilege Escalation Vulnerability</title><content type='html'>A team named whitecell  (http://www.whitecell.org/list.php?id=49 ) discover a new  symantec anti-virus Local Privilege Escalation Vulnerability.  The vendor is not noticed.&lt;br /&gt;&lt;br /&gt;Exploitation allows an attacker to execute arbitrary code within the context of the kernel.&lt;br /&gt;And exploit has high rate of succeed.&lt;br /&gt;&lt;br /&gt;Code Audit Labs has confirmed the existence of the vulnerability within last update Symantec AntiVirus 10.0.0.359.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240287929972979182-1727821938852992590?l=codeaudit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codeaudit.blogspot.com/feeds/1727821938852992590/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5240287929972979182&amp;postID=1727821938852992590' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240287929972979182/posts/default/1727821938852992590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240287929972979182/posts/default/1727821938852992590'/><link rel='alternate' type='text/html' href='http://codeaudit.blogspot.com/2007/07/0day-wildsymantec-anti-virus-local.html' title='[0day wild]symantec anti-virus Local Privilege Escalation Vulnerability'/><author><name>Code Audit Lab</name><uri>http://www.blogger.com/profile/05115135831495791532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240287929972979182.post-3596810668145489987</id><published>2007-06-01T07:26:00.000-07:00</published><updated>2007-06-01T07:29:06.300-07:00</updated><title type='text'>code audit labs</title><content type='html'>this is blog of code audit labs,  wait for us.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240287929972979182-3596810668145489987?l=codeaudit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codeaudit.blogspot.com/feeds/3596810668145489987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5240287929972979182&amp;postID=3596810668145489987' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240287929972979182/posts/default/3596810668145489987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240287929972979182/posts/default/3596810668145489987'/><link rel='alternate' type='text/html' href='http://codeaudit.blogspot.com/2007/06/code-audit-labs.html' title='code audit labs'/><author><name>Code Audit Lab</name><uri>http://www.blogger.com/profile/05115135831495791532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry></feed>
