Advertisement
Promo

Security threats Toolkit

Vulnerability found in Yoggie Pico

Tom Espiner ZDNet.co.uk

Published: 04 Jul 2007 17:08 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability has been found in Linux-based USB security device Yoggie Pico.

Yoggie Pico sits on a device, such as a laptop, and monitors web traffic to detect and block malware.

The zero-day vulnerability was disclosed on Monday by vulnerability researcher Cody Brocious.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Brocious said in his post that remote code execution was possible by subverting the "ping" function in the Yoggie web interface. "They expose a 'ping' function in their web interface for diagnostic purposes, which passes the IP/hostname given directly to ping in the form of 'ping -c 10 '. They do basic checking for ampersands, semicolons and pipes, but do not check for backticks, which allows you to execute commands as root on the device," wrote Brocious.

Avi Dardick, Yoggie's senior director of product management and support, said that the vulnerability had been fixed and that an update was released within 30 minutes of being disclosed.

Dardick played down the vulnerability, and denied that remote code execution was possible. "This was not remote execution, as the vulnerability requires access from the computer the device is supposed to connect to, to begin with, which requires an SSL handshake, and to begin processing you need to enter the username and password," he said. "With this in mind, yes, you could have hacked our Linux, but the exploit was by no means remote."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
40 out of 40 people found this useful



Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters