Advertisement
Promo

Security threats Toolkit

Vulnerability found in Yoggie Pico

Tom Espiner ZDNet.co.uk

Published: 04 Jul 2007 17:08 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability has been found in Linux-based USB security device Yoggie Pico.

Yoggie Pico sits on a device, such as a laptop, and monitors web traffic to detect and block malware.

The zero-day vulnerability was disclosed on Monday by vulnerability researcher Cody Brocious.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Brocious said in his post that remote code execution was possible by subverting the "ping" function in the Yoggie web interface. "They expose a 'ping' function in their web interface for diagnostic purposes, which passes the IP/hostname given directly to ping in the form of 'ping -c 10 '. They do basic checking for ampersands, semicolons and pipes, but do not check for backticks, which allows you to execute commands as root on the device," wrote Brocious.

Avi Dardick, Yoggie's senior director of product management and support, said that the vulnerability had been fixed and that an update was released within 30 minutes of being disclosed.

Dardick played down the vulnerability, and denied that remote code execution was possible. "This was not remote execution, as the vulnerability requires access from the computer the device is supposed to connect to, to begin with, which requires an SSL handshake, and to begin processing you need to enter the username and password," he said. "With this in mind, yes, you could have hacked our Linux, but the exploit was by no means remote."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
40 out of 40 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

2 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters