Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Master issue for THARD-2 #28

Open
Rafiot opened this issue Jun 10, 2015 · 4 comments
Open

Master issue for THARD-2 #28

Rafiot opened this issue Jun 10, 2015 · 4 comments
Labels

Comments

@Rafiot
Copy link
Member

Rafiot commented Jun 10, 2015

Review of the attack surface on the rPI (e.g. power analysis)

@Rafiot Rafiot added the THARD-2 label Jun 10, 2015
@Rafiot
Copy link
Member Author

Rafiot commented Jan 29, 2016

@moshekaplan
Copy link

  • Exploiting libmagic
    • Writing a malicious binary to the second USB
    • Returning a fake MIMEtype

@Rafiot
Copy link
Member Author

Rafiot commented Feb 11, 2017

I didn't see any recent vulnerability in libmagic allowing command execution. Do you have references?

Fake MIMEtype is assumed, we use it for information and cross check with the extension of the file (see polyglot files).

@moshekaplan
Copy link

Unfortunately, this is the only reference I could find : https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-1606 , but it only has DoS and no code execution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants