main | consulting | archives | about us | contact


L | A | T | E | S | T releases from Secure Reality A . r . c . h . i .v . e .s
A brand new release of injectso, version 0.2 A Study In Scarlet
Exploiting Common Vulnerablilities in PHP Applications


(SRADV00010)
Remote command execution vulnerabilities in SquirrelMail


(SRADV00009)
Remote command execution vulnerabilities in phpSecurePages

(SRADV00008)
Remote command execution vulnerabilities in phpMyAdmin and phpPgAdmin


injectso is a tool to inject shared libraries into running processes under Linux (IA32 and Sparc) and Solaris (Sparc). It also provides a set of routines that injected libraries can use to easily modify the behaviour of the host process by intercepting library function calls.

injectso was first presented by Shaun Clowes at the BlackHat Briefings in Amsterdam, Holland, 2001. Shaun will also be presenting a speech including injectso and other binary modification techniques at the BlackHat Briefings in Las Vegas on the 1st of August.