article thumbnail

Recently fixed WinRAR bug actively exploited in the wild

Security Affairs

The flaw is an “Absolute Path Traversal” issue in the library that could be exploited to execute arbitrary code by using a specially-crafted file archive. The issue affects a third-party library, called UNACEV2.DLL DLL that is used by WINRAR, it resides in the way an old third-party library, called UNACEV2.DLL,

article thumbnail

Severe bug in LibreOffice and OpenOffice suites allows remote code execution

Security Affairs

By exploiting the vulnerability it is possible to trigger the automatic execution of a specific python library included in the suite using a hidden onmouseover event. The expert pointed out that the python file, named “pydoc.py,” is already included in the LibreOffice software. .

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

[SI-LAB] FlawedAmmyy Leveraging Undetected XLM Macros as an Infection Vehicle

Security Affairs

File name: patent-2019-02-20T093A283A05-1.xls However, as already mentioned at the beginning of the technical analysis, SI-LAB team obtained two types of files, namely xls and doc archives. File name : 68131_46_20190219.doc Analyzing the MSI file – The installer/dropper of infamous FlawedAmmyy.

article thumbnail

Guarding Against Solorigate TTPs

eSecurity Planet

” In December, eSecurity Planet detailed FireEye’s initial findings , implications for the industry, and how to mitigate similar attacks. Presenting itself as a JPG file named “gracious_truth.jpg,” Teardrop is a memory-only dropper built to enter a network seamlessly and replace the embedded payload.

article thumbnail

Visual Cues and Clues: Born-Digital Photographs and their Metadata

Unwritten Record

First and foremost, let’s discuss how to find embedded metadata in a file. The metadata itself will not be seen in the image, however, it can be found in the file’s information, or properties. Accessing each file’s information is different on a PC or Mac, which we will outline below. Accessing File Metadata on a PC.

article thumbnail

APT34: Glimpse project

Security Affairs

The package comes with a README file having as a name “Read me.txt” (note the space). The name per se is quite unusual and the content is a simple guide on how to set a nodejs server and a Windows server who would run the “stand alone”.NET The panel reads those files and implements stats and actions.

article thumbnail

Quick and Easy Flash Prototypes

ChiefTech

To tackle the classic “how to prototype rich interactions” problem, I developed a process for translating static screen designs (from wireframes to visual comps) into interactive experiences using Flash. You’ll be saving each screen as a file named after this identifier (e.g., “W05.png”).