Francisco Amato of Infobyte Security Research just announced ISR-evilgrade v1.0.0, a toolkit for exploiting products which perform online updates in an insecure fashion. This tool works in conjunction with man-in-the-middle techniques (DNS, ARP, DHCP, etc) to exploit a wide variety applications. The demonstration video uses the CAU/Metasploit DNS exploit in conjunction with the Sun Java update mechanism to execute code on a fully patched Windows machine. For more information, see the README and slide deck. The first release includes exploits for Sun Java, Winzip, Winamp, Mac OS X, OpenOffice, iTunes, Linkedin Toolbar, DAP, Notepad , and Speedbit
Explore more from Rapid7
Vulnerability & Exploit Database
Rapid7s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.
Search the database
Rapid7 Labs
The threat research behind the alerts: adversary tracking, curated intelligence, and flagship threat reports.
Explore the research
Rapid7 MDR
Gain 24x7 XDR monitoring, remediation, and DFIR from experts that extend your team to help secure your extended ecosystem.
Explore MDR
Exposure management
Get continuous assessment of your attack surface with the critical context to validate and extinguish vulnerabilities and policy gaps.
See how it works