Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

zero-day vulnerabilities

After back to back revelation of highly critical vulnerabilities in Microsoft products, its time now that Google has targeted Apple to take down the security aspect people look for in Apple products. Google's Project Zero Initiative have exposed 3 Zero-Day vulnerabilities in Apple's OS X operating system, in mere 2 days of time.

The alleged reports contain detailed information including the proof-of-concept, whose code is written by Ian Beer, a member of Google's Project Zero Team.

According to the reports, these vulnerabilities were already reported to Apple as on October 20, October 21, and October 23. As the 90 day deadline expired this week, the reports have been disclosed publicly by Project Zero team.

First Zero-Day Vulnerability

OS X networkd effective_audit_token XPC type confusion sandbox escape.

The vulnerability was successfully said to be tested on OS X Mavericks 10.9.5, but it might have been fixed in OS X Yosemite 10.10.

"networkd is the system daemon which implements the com.apple.networkd XPC service. It's unsandboxed but runs as its own user. com.apple.networkd is reachable from many sandboxes including the Safari WebProcess and ntpd (plus all those which allow system-network), reads the advisory published by Google for the issue. networkd parses quite complicated XPC messages and there are many cases where xpc_dictionary_get_value and xpc_array_get_value are used without subsequent checking of the type of the returned value.

Second Zero-Day Vulnerability

OS X IOKit kernel code execution due to NULL pointer dereference in IntelAccelerator

The Second vulnerability is an IOKit kernel code execution vulnerability caused by "Null Pointer derference in IntelAccelerator. Initially Beer believed this bug to be fixed in OS X Yosemite, but later he clarified this bug to be present in OS X version 10.10.

Third Zero-Day Vulnerability

OS X IOKit kernel memory corruption due to bad bzero in IOBluetoothDevice

This flaw contains the involvement of IOSBluetoothDevice class and hence can only be exploited with Bluetooth device being connected to the target computer. The exploit has been tested with an Apple Bluetooth keyboard, Beer said.

For the time being, Google believes 90 days is more than enough time for a vendor to fix a security hole, so the company is sticking to its policy.

Over the past two months, Google's Project Zero team is on a spree of exposing vulnerabilities in products of its major Rivals, Microsoft and Apple. From past month till now, 3 highly critical vulnerabilities have been exposed by Google's Project Zero Initiative.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.