# KoreLogic Security > Professional cybersecurity consulting firm founded in 2004, specializing in penetration testing, vulnerability research, password security, and security assessments for Fortune 500 companies and government agencies. This file helps language models discover the most useful content on this site. ## Overview - [KoreLogic - Cybersecurity Services for Fortune 500 Companies and U.S. Government](https://korelogic.com/index.md): Founded 2004 | ISO 27001:2022 Certified | CREST Accredited. Professional cybersecurity services including penetration testing, cloud security, and AI/ML security testing. - [Our Approach - KoreLogic Security Methodology](https://korelogic.com/approach.md): Learn about KoreLogic's proven cybersecurity methodology. Quality-first approach, experienced team, and problem-solving mindset that Fortune 500 companies trust. - [About KoreLogic Security - CVE Authority | Government Partner | Founded 2004](https://korelogic.com/company.md): Learn about KoreLogic Security's leadership in cybersecurity. CVE Numbering Authority, government research partner, and trusted by Fortune 500 companies worldwide. - [Certifications & Accreditations - KoreLogic](https://korelogic.com/certifications.md): KoreLogic Security certifications and accreditations including ISO 27001:2022 certification and CREST accreditation. Download official certificates and verification documents. - [Client Stories - KoreLogic Security](https://korelogic.com/testimonials.md): Client stories from Fortune 500 CISOs, security directors, and technology leaders who trust KoreLogic with critical security challenges. - [Contact KoreLogic Security - Professional Cybersecurity Consultation](https://korelogic.com/contact.md): Contact KoreLogic Security for expert cybersecurity services. Email-first communication approach. Serving organizations across the United States. ## Services - [Cybersecurity Services - KoreLogic](https://korelogic.com/services.md): Professional cybersecurity services including penetration testing, defensive security, research, and password audit services for Fortune 500 companies and government agencies. - [Penetration Testing Services - KoreLogic](https://korelogic.com/services/penetration-testing.md): Full-scope offensive security testing for web, mobile, cloud, infrastructure, AI systems, social engineering, red teams, and scoped product hardware or IoT assessments. - [AI Security Testing - KoreLogic](https://korelogic.com/services/penetration-testing/ai-security.md): Security testing for AI/ML systems, LLMs, and generative AI applications, including prompt injection, model abuse, data exposure, and adversarial attack paths. - [Cloud Security Testing - KoreLogic](https://korelogic.com/services/penetration-testing/cloud-security.md): Cloud security assessments for AWS, Azure, and GCP covering infrastructure, identity, configuration, and security controls. - [Critical Infrastructure Cybersecurity - KoreLogic](https://korelogic.com/services/penetration-testing/critical-infrastructure.md): Critical infrastructure cybersecurity for water and electric utilities, including IT/OT penetration testing, ICS/SCADA review, and AWWA, NIST CSF, and NERC CIP gap analysis. - [External Penetration Testing - KoreLogic](https://korelogic.com/services/penetration-testing/external-testing.md): External penetration testing for perimeter defenses, internet-facing infrastructure, exposed services, and externally accessible systems. - [Internal Penetration Testing - KoreLogic](https://korelogic.com/services/penetration-testing/internal-testing.md): Professional internal penetration testing and network security assessments. In-depth testing of internal networks, systems, and security controls by certified security experts. - [Mobile Penetration Testing - KoreLogic](https://korelogic.com/services/penetration-testing/mobile-testing.md): Mobile application and device security testing for iOS, Android, MDM systems, and carrier-connected environments. - [Red Team Testing - KoreLogic](https://korelogic.com/services/penetration-testing/red-team.md): Threat-informed red team testing against critical assets, with realistic reconnaissance, custom tooling, collaborative analysis, detection guidance, and root cause remediation. - [Social Engineering Testing - KoreLogic](https://korelogic.com/services/penetration-testing/social-engineering.md): Targeted social engineering assessments to test human security vulnerabilities through phishing campaigns and social manipulation techniques. - [Web Application Security Testing - KoreLogic](https://korelogic.com/services/penetration-testing/web-application.md): Web application penetration testing and OWASP assessments for web apps, APIs, authentication flows, and custom applications. - [Password Audits & Recovery Services - KoreLogic](https://korelogic.com/services/password-audits-and-recovery.md): Proven Active Directory password security audits and recovery services for Fortune 500 enterprises and government agencies. - [Defensive Services - KoreLogic](https://korelogic.com/services/defensive.md): Proactive security architecture reviews and risk assessments to strengthen your security posture and protect critical assets. - [Research & Development Services - KoreLogic](https://korelogic.com/services/research.md): Cybersecurity research including password security, vulnerability discovery, open source tool development, and government-funded projects with demonstrated security outcomes. - [Federal Teaming & GSA Subcontracting - KoreLogic](https://korelogic.com/services/federal-teaming.md): Federal teaming and GSA subcontracting support for prime contractors that need specialized cybersecurity expertise for government engagements. ## Contest - [Crack Me If You Can - KoreLogic Password Cracking Contest](https://korelogic.com/contest.md): KoreLogic's Crack Me If You Can password cracking contest hub with current contest status, past winners, rules, scores, downloads, and challenge notes. - [Crack Me If You Can Contest Archive - KoreLogic](https://korelogic.com/contest/archive.md): Past KoreLogic Crack Me If You Can contest years with winners, rules, team standings, downloads, charts, and password-cracking challenge notes. ## Advisories - [Security Advisories - KoreLogic](https://korelogic.com/advisories.md): KoreLogic security advisories, CVE disclosures, affected vendors and products, and vulnerability research. - [KL-001-2026-001: yintibao Fun Print Mobile Unauthorized Access via Context Hijacking](https://korelogic.com/advisories/KL-001-2026-001.md): KL-001-2026-001 - yintibao Fun Print Mobile Unauthorized Access via Context Hijacking - CVE-2025-15464 - yintibao Fun Print Mobile - [KL-001-2025-012: Xorux XorMon-NG Read Only User Export Device Configuration Exposing Sensitive Information](https://korelogic.com/advisories/KL-001-2025-012.md): KL-001-2025-012 - Xorux XorMon-NG Read Only User Export Device Configuration Exposing Sensitive Information - CVE-2025-54766 - Xorux XorMon-NG - [KL-001-2025-013: Xorux XorMon-NG Web Application Privilege Escalation to Administrator](https://korelogic.com/advisories/KL-001-2025-013.md): KL-001-2025-013 - Xorux XorMon-NG Web Application Privilege Escalation to Administrator - CVE-2025-54765 - Xorux XorMon-NG - [KL-001-2025-014: Xorux LPAR2RRD Read Only User Denial of Service](https://korelogic.com/advisories/KL-001-2025-014.md): KL-001-2025-014 - Xorux LPAR2RRD Read Only User Denial of Service - CVE-2025-54767 - Xorux LPAR2RRD - [KL-001-2025-015: Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive Information](https://korelogic.com/advisories/KL-001-2025-015.md): KL-001-2025-015 - Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive Information - CVE-2025-54768 - Xorux LPAR2RRD - [KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal](https://korelogic.com/advisories/KL-001-2025-016.md): KL-001-2025-016 - Xorux LPAR2RRD File Upload Directory Traversal - CVE-2025-54769 - Xorux LPAR2RRD - [KL-001-2025-006: Schneider Electric EcoStruxure IT Data Center Expert XML External Entities Injection](https://korelogic.com/advisories/KL-001-2025-006.md): KL-001-2025-006 - Schneider Electric EcoStruxure IT Data Center Expert XML External Entities Injection - CVE-2025-6438 - Schneider Electric EcoStruxure IT Data Center Expert - [KL-001-2025-007: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Remote Code Execution](https://korelogic.com/advisories/KL-001-2025-007.md): KL-001-2025-007 - Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Remote Code Execution - CVE-2025-50121 - Schneider Electric EcoStruxure IT Data Center Expert - [KL-001-2025-008: Schneider Electric EcoStruxure IT Data Center Expert Root Password Discovery](https://korelogic.com/advisories/KL-001-2025-008.md): KL-001-2025-008 - Schneider Electric EcoStruxure IT Data Center Expert Root Password Discovery - CVE-2025-50122 - Schneider Electric EcoStruxure IT Data Center Expert - [KL-001-2025-009: Schneider Electric EcoStruxure IT Data Center Expert Remote Command Execution](https://korelogic.com/advisories/KL-001-2025-009.md): KL-001-2025-009 - Schneider Electric EcoStruxure IT Data Center Expert Remote Command Execution - CVE-2025-50123 - Schneider Electric EcoStruxure IT Data Center Expert - [KL-001-2025-010: Schneider Electric EcoStruxure IT Data Center Expert Privilege Escalation](https://korelogic.com/advisories/KL-001-2025-010.md): KL-001-2025-010 - Schneider Electric EcoStruxure IT Data Center Expert Privilege Escalation - CVE-2025-50124 - Schneider Electric EcoStruxure IT Data Center Expert - [KL-001-2025-011: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Server-Side Request Forgery](https://korelogic.com/advisories/KL-001-2025-011.md): KL-001-2025-011 - Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Server-Side Request Forgery - CVE-2025-50125 - Schneider Electric EcoStruxure IT Data Center Expert - [KL-001-2025-003: Mobile Dynamix PrinterShare Mobile Print Gmail Oauth Token Disclosure](https://korelogic.com/advisories/KL-001-2025-003.md): KL-001-2025-003 - Mobile Dynamix PrinterShare Mobile Print Gmail Oauth Token Disclosure - CVE-2025-5098 - Mobile Dynamix PrinterShare Mobile Print - [KL-001-2025-004: Mobile Dynamix PrinterShare Mobile Print Out-of-bounds Write](https://korelogic.com/advisories/KL-001-2025-004.md): KL-001-2025-004 - Mobile Dynamix PrinterShare Mobile Print Out-of-bounds Write - CVE-2025-5099 - Mobile Dynamix PrinterShare Mobile Print - [KL-001-2025-005: Mobile Dynamix PrinterShare Mobile Print Double-Free Memory Write](https://korelogic.com/advisories/KL-001-2025-005.md): KL-001-2025-005 - Mobile Dynamix PrinterShare Mobile Print Double-Free Memory Write - CVE-2025-5100 - Mobile Dynamix PrinterShare Mobile Print - [KL-001-2025-001: Checkmk NagVis Reflected Cross-site Scripting](https://korelogic.com/advisories/KL-001-2025-001.md): KL-001-2025-001 - Checkmk NagVis Reflected Cross-site Scripting - CVE-2024-13722 - Checkmk Checkmk/NagVis - [KL-001-2025-002: Checkmk NagVis Remote Code Execution](https://korelogic.com/advisories/KL-001-2025-002.md): KL-001-2025-002 - Checkmk NagVis Remote Code Execution - CVE-2024-13723 - Checkmk Checkmk/NagVis - [KL-001-2024-011: VICIdial Unauthenticated SQL Injection](https://korelogic.com/advisories/KL-001-2024-011.md): KL-001-2024-011 - VICIdial Unauthenticated SQL Injection - CVE-2024-8503 - VICIdial VICIdial - [KL-001-2024-012: VICIdial Authenticated Remote Code Execution](https://korelogic.com/advisories/KL-001-2024-012.md): KL-001-2024-012 - VICIdial Authenticated Remote Code Execution - CVE-2024-8504 - VICIdial VICIdial - [KL-001-2024-005: Open WebUI Stored Cross-Site Scripting](https://korelogic.com/advisories/KL-001-2024-005.md): KL-001-2024-005 - Open WebUI Stored Cross-Site Scripting - CVE-2024-6706 - Open WebUI Open WebUI - [KL-001-2024-006: Open WebUI Arbitrary File Upload + Path Traversal](https://korelogic.com/advisories/KL-001-2024-006.md): KL-001-2024-006 - Open WebUI Arbitrary File Upload + Path Traversal - CVE-2024-6707 - Open WebUI Open WebUI - [KL-001-2024-007: Journyx Unauthenticated Password Reset Bruteforce](https://korelogic.com/advisories/KL-001-2024-007.md): KL-001-2024-007 - Journyx Unauthenticated Password Reset Bruteforce - CVE-2024-6890 - Journyx Journyx (jtime) - [KL-001-2024-008: Journyx Authenticated Remote Code Execution](https://korelogic.com/advisories/KL-001-2024-008.md): KL-001-2024-008 - Journyx Authenticated Remote Code Execution - CVE-2024-6891 - Journyx Journyx (jtime) - [KL-001-2024-009: Journyx Reflected Cross Site Scripting](https://korelogic.com/advisories/KL-001-2024-009.md): KL-001-2024-009 - Journyx Reflected Cross Site Scripting - CVE-2024-6892 - Journyx Journyx (jtime) - [KL-001-2024-010: Journyx Unauthenticated XML External Entities Injection](https://korelogic.com/advisories/KL-001-2024-010.md): KL-001-2024-010 - Journyx Unauthenticated XML External Entities Injection - CVE-2024-6893 - Journyx Journyx (jtime) - [KL-001-2024-001: Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability](https://korelogic.com/advisories/KL-001-2024-001.md): KL-001-2024-001 - Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability - CVE-2024-2053 - Artica Artica Proxy - [KL-001-2024-002: Artica Proxy Unauthenticated PHP Deserialization Vulnerability](https://korelogic.com/advisories/KL-001-2024-002.md): KL-001-2024-002 - Artica Proxy Unauthenticated PHP Deserialization Vulnerability - CVE-2024-2054 - Artica Artica Proxy - [KL-001-2024-003: Artica Proxy Unauthenticated File Manager Vulnerability](https://korelogic.com/advisories/KL-001-2024-003.md): KL-001-2024-003 - Artica Proxy Unauthenticated File Manager Vulnerability - CVE-2024-2055 - Artica Artica Proxy - [KL-001-2024-004: Artica Proxy Loopback Services Remotely Accessible Unauthenticated](https://korelogic.com/advisories/KL-001-2024-004.md): KL-001-2024-004 - Artica Proxy Loopback Services Remotely Accessible Unauthenticated - CVE-2024-2056 - Artica Artica Proxy - [KL-001-2023-001: Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Read via sudo dig](https://korelogic.com/advisories/KL-001-2023-001.md): KL-001-2023-001 - Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Read via sudo dig - CVE-2023-20217 - Cisco ThousandEyes Enterprise Agent Virtual Appliance - [KL-001-2023-002: Cisco ThousandEyes Enterprise Agent Virtual Appliance Privilege Escalation via tcpdump](https://korelogic.com/advisories/KL-001-2023-002.md): KL-001-2023-002 - Cisco ThousandEyes Enterprise Agent Virtual Appliance Privilege Escalation via tcpdump - CVE-2023-20224 - Cisco ThousandEyes Enterprise Agent Virtual Appliance - [KL-001-2023-003: Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Modification via sudoedit](https://korelogic.com/advisories/KL-001-2023-003.md): KL-001-2023-003 - Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Modification via sudoedit - CVE-2023-22809 - Cisco ThousandEyes Enterprise Agent Virtual Appliance - [KL-001-2022-001: Moxa TN-5900 Firmware Upgrade Checksum Validation Vulnerability](https://korelogic.com/advisories/KL-001-2022-001.md): KL-001-2022-001 - Moxa TN-5900 Firmware Upgrade Checksum Validation Vulnerability - CVE-2021-46559 - Moxa TN-5900 - [KL-001-2022-002: Moxa TN-5900 Post Authentication Command Injection Vulnerability](https://korelogic.com/advisories/KL-001-2022-002.md): KL-001-2022-002 - Moxa TN-5900 Post Authentication Command Injection Vulnerability - CVE-2021-46560 - Moxa TN-5900 - [KL-001-2021-008: CyberArk Credential File Insufficient Effective Key Space](https://korelogic.com/advisories/KL-001-2021-008.md): KL-001-2021-008 - CyberArk Credential File Insufficient Effective Key Space - CVE-2021-31796 - CyberArk Application Access Manager/Credential Provider - [KL-001-2021-009: CyberArk Credential Provider Race Condition And Authorization Bypass](https://korelogic.com/advisories/KL-001-2021-009.md): KL-001-2021-009 - CyberArk Credential Provider Race Condition And Authorization Bypass - CVE-2021-31797 - CyberArk Application Access Manager/Credential Provider - [KL-001-2021-010: CyberArk Credential Provider Local Cache Can Be Decrypted](https://korelogic.com/advisories/KL-001-2021-010.md): KL-001-2021-010 - CyberArk Credential Provider Local Cache Can Be Decrypted - CVE-2021-31798 - CyberArk Application Access Manager/Credential Provider - [KL-001-2021-001: CommScope Ruckus IoT Controller Unauthenticated API Endpoints](https://korelogic.com/advisories/KL-001-2021-001.md): KL-001-2021-001 - CommScope Ruckus IoT Controller Unauthenticated API Endpoints - CVE-2021-33221 - CommScope Ruckus IoT Controller - [KL-001-2021-002: CommScope Ruckus IoT Controller Hard-coded API Keys Exposed](https://korelogic.com/advisories/KL-001-2021-002.md): KL-001-2021-002 - CommScope Ruckus IoT Controller Hard-coded API Keys Exposed - CVE-2021-33220 - CommScope Ruckus IoT Controller - [KL-001-2021-003: CommScope Ruckus IoT Controller Hard-coded System Passwords](https://korelogic.com/advisories/KL-001-2021-003.md): KL-001-2021-003 - CommScope Ruckus IoT Controller Hard-coded System Passwords - CVE-2021-33218 - CommScope Ruckus IoT Controller - [KL-001-2021-004: CommScope Ruckus IoT Controller Hard-coded Web Application Administrator Password](https://korelogic.com/advisories/KL-001-2021-004.md): KL-001-2021-004 - CommScope Ruckus IoT Controller Hard-coded Web Application Administrator Password - CVE-2021-33219 - CommScope Ruckus IoT Controller - [KL-001-2021-005: CommScope Ruckus IoT Controller Web Application Directory Traversal](https://korelogic.com/advisories/KL-001-2021-005.md): KL-001-2021-005 - CommScope Ruckus IoT Controller Web Application Directory Traversal - CVE-2021-33215 - CommScope Ruckus IoT Controller - [KL-001-2021-006: CommScope Ruckus IoT Controller Web Application Arbitrary Read/Write](https://korelogic.com/advisories/KL-001-2021-006.md): KL-001-2021-006 - CommScope Ruckus IoT Controller Web Application Arbitrary Read/Write - CVE-2021-33217 - CommScope Ruckus IoT Controller - [KL-001-2021-007: CommScope Ruckus IoT Controller Undocumented Account](https://korelogic.com/advisories/KL-001-2021-007.md): KL-001-2021-007 - CommScope Ruckus IoT Controller Undocumented Account - CVE-2021-33216 - CommScope Ruckus IoT Controller - [KL-001-2020-004: Barco wePresent Hardcoded API Credentials](https://korelogic.com/advisories/KL-001-2020-004.md): KL-001-2020-004 - Barco wePresent Hardcoded API Credentials - CVE-2020-28329 - Barco wePresent WiPG-1600W - [KL-001-2020-005: Barco wePresent Admin Credentials Exposed In Plain-text](https://korelogic.com/advisories/KL-001-2020-005.md): KL-001-2020-005 - Barco wePresent Admin Credentials Exposed In Plain-text - CVE-2020-28330 - Barco wePresent WiPG-1600W - [KL-001-2020-006: Barco wePresent Authentication Bypass](https://korelogic.com/advisories/KL-001-2020-006.md): KL-001-2020-006 - Barco wePresent Authentication Bypass - CVE-2020-28333 - Barco wePresent WiPG-1600W - [KL-001-2020-007: Barco wePresent Undocumented SSH Interface Accessible Via Web UI](https://korelogic.com/advisories/KL-001-2020-007.md): KL-001-2020-007 - Barco wePresent Undocumented SSH Interface Accessible Via Web UI - CVE-2020-28331 - Barco wePresent WiPG-1600W - [KL-001-2020-008: Barco wePresent Global Hardcoded Root SSH Password](https://korelogic.com/advisories/KL-001-2020-008.md): KL-001-2020-008 - Barco wePresent Global Hardcoded Root SSH Password - CVE-2020-28334 - Barco wePresent WiPG-1600W - [KL-001-2020-009: Barco wePresent Insecure Firmware Image](https://korelogic.com/advisories/KL-001-2020-009.md): KL-001-2020-009 - Barco wePresent Insecure Firmware Image - CVE-2020-28332 - Barco wePresent WiPG-1600W - [KL-001-2020-003: Cellebrite EPR Decryption Relies on Hardcoded AES Key Material](https://korelogic.com/advisories/KL-001-2020-003.md): KL-001-2020-003 - Cellebrite EPR Decryption Relies on Hardcoded AES Key Material - CVE-2020-14474 - Cellebrite UFED - [KL-001-2020-002: Cellebrite Restricted Desktop Escape and Escalation of User Privilege](https://korelogic.com/advisories/KL-001-2020-002.md): KL-001-2020-002 - Cellebrite Restricted Desktop Escape and Escalation of User Privilege - CVE-2020-12798 - Cellebrite UFED - [KL-001-2020-001: Cellebrite Hardcoded ADB Authentication Keys](https://korelogic.com/advisories/KL-001-2020-001.md): KL-001-2020-001 - Cellebrite Hardcoded ADB Authentication Keys - CVE-2020-11723 - Cellebrite UFED - [KL-001-2018-009: Dell OpenManage Network Manager Multiple Vulnerabilities](https://korelogic.com/advisories/KL-001-2018-009.md): KL-001-2018-009 - Dell OpenManage Network Manager Multiple Vulnerabilities - CVE-2018-15767, CVE-2018-15768 - Dell OpenManage Network Manager - [KL-001-2018-008: HPE VAN SDN Unauthenticated Remote Root Vulnerability](https://korelogic.com/advisories/KL-001-2018-008.md): KL-001-2018-008 - HPE VAN SDN Unauthenticated Remote Root Vulnerability - HP Enterprise VAN SDN Controller - [KL-001-2018-007: Sophos UTM 9 loginuser Privilege Escalation via confd Service](https://korelogic.com/advisories/KL-001-2018-007.md): KL-001-2018-007 - Sophos UTM 9 loginuser Privilege Escalation via confd Service - Sophos UTM 9 - [KL-001-2018-002: NetEx HyperIP Authentication Bypass](https://korelogic.com/advisories/KL-001-2018-002.md): KL-001-2018-002 - NetEx HyperIP Authentication Bypass - NetEx HyperIP - [KL-001-2018-003: NetEx HyperIP Post-Auth Command Execution](https://korelogic.com/advisories/KL-001-2018-003.md): KL-001-2018-003 - NetEx HyperIP Post-Auth Command Execution - NetEx HyperIP - [KL-001-2018-004: NetEx HyperIP Privilege Escalation Vulnerability](https://korelogic.com/advisories/KL-001-2018-004.md): KL-001-2018-004 - NetEx HyperIP Privilege Escalation Vulnerability - NetEx HyperIP - [KL-001-2018-005: NetEx HyperIP Local File Inclusion Vulnerability](https://korelogic.com/advisories/KL-001-2018-005.md): KL-001-2018-005 - NetEx HyperIP Local File Inclusion Vulnerability - NetEx HyperIP - [KL-001-2018-006: Trend Micro IMSVA Management Portal Authentication Bypass](https://korelogic.com/advisories/KL-001-2018-006.md): KL-001-2018-006 - Trend Micro IMSVA Management Portal Authentication Bypass - Trend Micro InterScan Mail Security Virtual Apppliance - [KL-001-2018-001: Sophos Web Gateway Persistent Cross Site Scripting Vulnerability](https://korelogic.com/advisories/KL-001-2018-001.md): KL-001-2018-001 - Sophos Web Gateway Persistent Cross Site Scripting Vulnerability - Sophos Web Gateway - [KL-001-2017-022: Splunk Local Privilege Escalation](https://korelogic.com/advisories/KL-001-2017-022.md): KL-001-2017-022 - Splunk Local Privilege Escalation - Splunk Splunk Enterprise - [KL-001-2017-017: Infoblox NetMRI Administration Shell Escape and Privilege Escalation](https://korelogic.com/advisories/KL-001-2017-017.md): KL-001-2017-017 - Infoblox NetMRI Administration Shell Escape and Privilege Escalation - Infoblox NetMRI - [KL-001-2017-018: Infoblox NetMRI Administration Shell Factory Reset Persistence](https://korelogic.com/advisories/KL-001-2017-018.md): KL-001-2017-018 - Infoblox NetMRI Administration Shell Factory Reset Persistence - Infoblox NetMRI - [KL-001-2017-019: Sonicwall WXA5000 Console Jail Escape and Privilege Escalation](https://korelogic.com/advisories/KL-001-2017-019.md): KL-001-2017-019 - Sonicwall WXA5000 Console Jail Escape and Privilege Escalation - Sonicwall WXA5000 WAN Optimization Appliance - [KL-001-2017-020: Sophos UTM 9 loginuser Privilege Escalation via Insecure Directory Permissions](https://korelogic.com/advisories/KL-001-2017-020.md): KL-001-2017-020 - Sophos UTM 9 loginuser Privilege Escalation via Insecure Directory Permissions - Sophos UTM 9 - [KL-001-2017-021: Sophos UTM 9 Management Application Local File Inclusion](https://korelogic.com/advisories/KL-001-2017-021.md): KL-001-2017-021 - Sophos UTM 9 Management Application Local File Inclusion - Sophos UTM 9 - [KL-001-2017-016: Solarwinds LEM Insecure Update Process](https://korelogic.com/advisories/KL-001-2017-016.md): KL-001-2017-016 - Solarwinds LEM Insecure Update Process - Solarwinds Multiple - [KL-001-2017-010: Barracuda WAF Early Boot Root Shell](https://korelogic.com/advisories/KL-001-2017-010.md): KL-001-2017-010 - Barracuda WAF Early Boot Root Shell - Barracuda Web Application Firewall V360 - [KL-001-2017-011: Barracuda WAF Internal Development Credential Disclosure](https://korelogic.com/advisories/KL-001-2017-011.md): KL-001-2017-011 - Barracuda WAF Internal Development Credential Disclosure - Barracuda Web Application Firewall V360 - [KL-001-2017-012: Barracuda WAF Grub Password Complexity](https://korelogic.com/advisories/KL-001-2017-012.md): KL-001-2017-012 - Barracuda WAF Grub Password Complexity - Barracuda Web Application Firewall V360 - [KL-001-2017-013: Barracuda WAF Management Application Username and Session ID Leak](https://korelogic.com/advisories/KL-001-2017-013.md): KL-001-2017-013 - Barracuda WAF Management Application Username and Session ID Leak - Barracuda Web Application Firewall V360 - [KL-001-2017-014: Barracuda WAF Support Tunnel Hijack](https://korelogic.com/advisories/KL-001-2017-014.md): KL-001-2017-014 - Barracuda WAF Support Tunnel Hijack - Barracuda Web Application Firewall V360 - [KL-001-2017-015: Solarwinds LEM Hardcoded Credentials](https://korelogic.com/advisories/KL-001-2017-015.md): KL-001-2017-015 - Solarwinds LEM Hardcoded Credentials - Solarwinds Log and Event Manager Virtual Appliance - [KL-001-2017-005: Solarwinds LEM Privilege Escalation via Controlled Sudo Path](https://korelogic.com/advisories/KL-001-2017-005.md): KL-001-2017-005 - Solarwinds LEM Privilege Escalation via Controlled Sudo Path - Solarwinds Log and Event Manager Virtual Appliance - [KL-001-2017-006: Solarwinds LEM Privilege Escalation via Sudo Script Abuse](https://korelogic.com/advisories/KL-001-2017-006.md): KL-001-2017-006 - Solarwinds LEM Privilege Escalation via Sudo Script Abuse - Solarwinds Log and Event Manager Virtual Appliance - [KL-001-2017-007: Solarwinds LEM Management Shell Escape via Command Injection](https://korelogic.com/advisories/KL-001-2017-007.md): KL-001-2017-007 - Solarwinds LEM Management Shell Escape via Command Injection - Solarwinds Log and Event Manager Virtual Appliance - [KL-001-2017-008: Solarwinds LEM Management Shell Arbitrary File Read](https://korelogic.com/advisories/KL-001-2017-008.md): KL-001-2017-008 - Solarwinds LEM Management Shell Arbitrary File Read - Solarwinds Log and Event Manager Virtual Appliance - [KL-001-2017-009: Solarwinds LEM Database Listener with Hardcoded Credentials](https://korelogic.com/advisories/KL-001-2017-009.md): KL-001-2017-009 - Solarwinds LEM Database Listener with Hardcoded Credentials - Solarwinds Log and Event Manager Virtual Appliance - [KL-001-2017-004: WatchGuard XTMv User Management Cross-Site Request Forgery](https://korelogic.com/advisories/KL-001-2017-004.md): KL-001-2017-004 - WatchGuard XTMv User Management Cross-Site Request Forgery - WatchGuard XTMv - [KL-001-2017-001: Trendmicro InterScan Arbitrary File Write](https://korelogic.com/advisories/KL-001-2017-001.md): KL-001-2017-001 - Trendmicro InterScan Arbitrary File Write - Trendmicro InterScan Web Security Virtual Appliance - [KL-001-2017-002: Trendmicro InterScan Privilege Escalation Vulnerability](https://korelogic.com/advisories/KL-001-2017-002.md): KL-001-2017-002 - Trendmicro InterScan Privilege Escalation Vulnerability - CVE-2016-9315 - Trendmicro InterScan Web Security Virtual Appliance - [KL-001-2017-003: Trendmicro InterScan Remote Root Access Vulnerability](https://korelogic.com/advisories/KL-001-2017-003.md): KL-001-2017-003 - Trendmicro InterScan Remote Root Access Vulnerability - Trendmicro InterScan Web Security Virtual Appliance - [KL-001-2016-008: Sophos Web Appliance Privilege Escalation](https://korelogic.com/advisories/KL-001-2016-008.md): KL-001-2016-008 - Sophos Web Appliance Privilege Escalation - Sophos Web Apppliance - [KL-001-2016-009: Sophos Web Appliance Remote Code Execution](https://korelogic.com/advisories/KL-001-2016-009.md): KL-001-2016-009 - Sophos Web Appliance Remote Code Execution - Sophos Web Apppliance - [KL-001-2016-004: Cisco Firepower Threat Management Console Authenticated Denial of Service](https://korelogic.com/advisories/KL-001-2016-004.md): KL-001-2016-004 - Cisco Firepower Threat Management Console Authenticated Denial of Service - Cisco Firepower Threat Management Console - [KL-001-2016-005: Cisco Firepower Threat Management Console Hard-coded MySQL Credentials](https://korelogic.com/advisories/KL-001-2016-005.md): KL-001-2016-005 - Cisco Firepower Threat Management Console Hard-coded MySQL Credentials - CVE-2016-6434 - Cisco Firepower Threat Management Console - [KL-001-2016-006: Cisco Firepower Threat Management Console Local File Inclusion](https://korelogic.com/advisories/KL-001-2016-006.md): KL-001-2016-006 - Cisco Firepower Threat Management Console Local File Inclusion - CVE-2016-6435 - Cisco Firepower Threat Management Console - [KL-001-2016-007: Cisco Firepower Threat Management Console Remote Command Execution Leading to Root Access](https://korelogic.com/advisories/KL-001-2016-007.md): KL-001-2016-007 - Cisco Firepower Threat Management Console Remote Command Execution Leading to Root Access - CVE-2016-6433 - Cisco Firepower Threat Management Console - [KL-001-2016-003: SQLite Tempdir Selection Vulnerability](https://korelogic.com/advisories/KL-001-2016-003.md): KL-001-2016-003 - SQLite Tempdir Selection Vulnerability - SQLite/Hwaci SQLite - [KL-001-2016-002: Ubiquiti Administration Portal CSRF to Remote Command Execution](https://korelogic.com/advisories/KL-001-2016-002.md): KL-001-2016-002 - Ubiquiti Administration Portal CSRF to Remote Command Execution - Ubiquiti AirGateway, AirFiber, mFi - [KL-001-2016-001: Arris DG1670A Cable Modem Remote Command Execution](https://korelogic.com/advisories/KL-001-2016-001.md): KL-001-2016-001 - Arris DG1670A Cable Modem Remote Command Execution - Arris Cable Modem - [KL-001-2015-001: Microsoft Windows Server 2003 SP2 Arbitrary Write Privilege Escalation](https://korelogic.com/advisories/KL-001-2015-001.md): KL-001-2015-001 - Microsoft Windows Server 2003 SP2 Arbitrary Write Privilege Escalation - CVE-2014-4076 - Microsoft TCP/IP Protocol Driver - [KL-001-2015-007: Seagate GoFlex Satellite Remote Telnet Default Password](https://korelogic.com/advisories/KL-001-2015-007.md): KL-001-2015-007 - Seagate GoFlex Satellite Remote Telnet Default Password - CVE-2015-2874 - Seagate GoFlex Satellite - [KL-001-2015-008: Dell Pre-Boot Authentication Driver Uncontrolled Write to Arbitrary Address](https://korelogic.com/advisories/KL-001-2015-008.md): KL-001-2015-008 - Dell Pre-Boot Authentication Driver Uncontrolled Write to Arbitrary Address - CVE-2015-6856 - Dell Pre-Boot Authentication Driver - [KL-001-2015-006: Linksys EA6100 Wireless Router Authentication Bypass](https://korelogic.com/advisories/KL-001-2015-006.md): KL-001-2015-006 - Linksys EA6100 Wireless Router Authentication Bypass - Linksys EA6100 - EA6300 Wireless Router - [KL-001-2015-005: VBox Satellite Express Arbitrary Write Privilege Escalation](https://korelogic.com/advisories/KL-001-2015-005.md): KL-001-2015-005 - VBox Satellite Express Arbitrary Write Privilege Escalation - CVE-2015-6923 - VBox Communications Satellite Express Protocol - [KL-001-2015-003: SiS Windows VGA Display Manager Multiple Privilege Escalation](https://korelogic.com/advisories/KL-001-2015-003.md): KL-001-2015-003 - SiS Windows VGA Display Manager Multiple Privilege Escalation - CVE-2015-5465 - Silicon Integrated Systems Corporation Windows VGA Display Manager - [KL-001-2015-004: XGI Windows VGA Display Manager Arbitrary Write Privilege Escalation](https://korelogic.com/advisories/KL-001-2015-004.md): KL-001-2015-004 - XGI Windows VGA Display Manager Arbitrary Write Privilege Escalation - CVE-2015-5466 - Silicon Integrated Systems Corporation XGI VGA Display Manager - [KL-001-2015-002: Piriform CCleaner Wiped Filename Recovery](https://korelogic.com/advisories/KL-001-2015-002.md): KL-001-2015-002 - Piriform CCleaner Wiped Filename Recovery - CVE-2015-3999 - Piriform CCleaner - [KL-001-2014-004: VMWare vmx86.sys Arbitrary Kernel Read](https://korelogic.com/advisories/KL-001-2014-004.md): KL-001-2014-004 - VMWare vmx86.sys Arbitrary Kernel Read - VMWare Workstation - [KL-001-2014-002: Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation](https://korelogic.com/advisories/KL-001-2014-002.md): KL-001-2014-002 - Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation - CVE-2014-4971 - Microsoft Bluetooth Personal Area Networking - [KL-001-2014-003: Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation](https://korelogic.com/advisories/KL-001-2014-003.md): KL-001-2014-003 - Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation - CVE-2014-4971 - Microsoft MQ Access Control - [KL-001-2014-001: Oracle VirtualBox Guest Additions Arbitrary Write Privilege Escalation](https://korelogic.com/advisories/KL-001-2014-001.md): KL-001-2014-001 - Oracle VirtualBox Guest Additions Arbitrary Write Privilege Escalation - CVE-2014-2477 - Oracle VirtualBox Guest Additions ## Blog - [Blog - KoreLogic Security Research](https://korelogic.com/blog.md): KoreLogic security research posts, password-security writing, vulnerability analysis, and tool announcements. - [Heads Up. CyberConVA 2026 Lands February 12, 2026 in Richmond, Virginia](https://korelogic.com/blog/2026/02/02/cyberconva-2026.md): CyberConVA 2026 brings together cybersecurity leaders and professionals on February 12th, 2026 at the Museum of Science in Richmond, Virginia. - [CyberConVA 2025!](https://korelogic.com/blog/2025/01/20/cybercon2025.md): CyberConVA 2025 brings cybersecurity leaders and practitioners to Richmond for sessions on AI red teaming, security program strategy, executive perspectives, and regional networking. - [2024: What KoreLogic Has Been Up To](https://korelogic.com/blog/2025/01/13/2024-what-korelogic-has-been-up-to.md): A year-in-review covering KoreLogic work across CMIYC, CyberConVA, penetration testing, AI security research, vulnerability disclosure, ISO 27001 certification, and team growth. - [WMkick - MITM MS-RPC, WMI, WinRM to Capture NetNTLMv2 Hashes](https://korelogic.com/blog/2021/08/22/wmkick-mitm-netntlmv2-hashes.md): WMkick captures NetNTLMv2 hashes from WMI, MS-RPC, and WinRM traffic, extending MITM coverage for protocols not fully handled by tools like Responder. - [WePresent... vulnerabilities!](https://korelogic.com/blog/2021/01/05/wepresent-vulnerabilities.md): Exploit-chain research showing how unauthenticated vulnerabilities in Barco WePresent WiPG-1600 firmware led to root shell access. - [Cellebrite Good Times, Come On: Reverse-Engineering Phone Forensics Tools](https://korelogic.com/blog/2020/06/29/cellebrite-reverse-engineering-forensics.md): How can vulnerabilities in technologies used by our judicial system affect the outcome of cases brought to the courts? - [FTimes, KLEL, and File Hooks](https://korelogic.com/blog/2019/11/08/ftimes-klel-and-file-hooks.md): A practical FTimes guide to using KLEL and file hooks to run external programs or scripts on matching files during dig, map, or mad stages. - [Building FTimes With Lua](https://korelogic.com/blog/2019/09/05/building-ftimes-with-lua.md): A hands-on guide to building FTimes with XMagic and an embedded Lua interpreter so file hooks can perform more complex searches. - [FTimes 3.13.0 Released](https://korelogic.com/blog/2019/09/04/ftimes-3130-released.md): FTimes 3.13.0 adds Linux BTRFS support, new encoder and decoder routines, and KLEL-based include and exclude filters. - [Unpatched Fringe Infrastructure Bits](https://korelogic.com/blog/2019/08/19/unpatched-fringe-infrastructure-bits.md): An internal penetration testing discussion of overlooked fringe infrastructure devices that can remain unpatched and introduce security risk. - [Password Audits - Focus on the Admins](https://korelogic.com/blog/2019/05/09/password-audits-8211-focus-on-the-admins.md): A practical argument for periodic password audits, with emphasis on administrator accounts and the risk reduction they can provide. - [Building FTimes With Python3](https://korelogic.com/blog/2019/04/25/building-ftimes-with-python3.md): A hands-on guide to building FTimes with XMagic and an embedded Python interpreter so file hooks can perform more complex searches. - [Building FTimes With Perl](https://korelogic.com/blog/2019/04/11/building-ftimes-with-perl.md): A hands-on guide to building FTimes with XMagic and an embedded Perl interpreter so file hooks can perform more complex searches. - [FTimes 3.12.0 Released](https://korelogic.com/blog/2019/03/15/ftimes-3120-released.md): FTimes 3.12.0 collects several years of fixes and enhancements, including depth-limited mapping and digging plus additional encoding and decoding support. - [New LibPathWell Release, and an Updated Talk](https://korelogic.com/blog/2017/05/12/new-libpathwell-release-and-an-updated-talk.md): PathWell 0.7.0 release notes plus an updated talk highlighting new features in the password topology enforcement project. - [Virtual Appliance Spelunking](https://korelogic.com/blog/2016/10/10/virtual-appliance-spelunking.md): A virtual appliance reversing case study based on Cisco Firepower Management Center research that resulted in multiple CVEs. - [Nothing To See Here, Move Along](https://korelogic.com/blog/2016/08/08/nothing-to-see-here-move-along.md): Vendors often have interesting ways to facilitate support for their appliances. Today, I'll discuss a few ways we have seen it implemented: one that is vulnerable to exploitation and others that aren't so bad. - [Cracking Grid - Essential Attributes](https://korelogic.com/blog/2016/05/25/cracking-grid-8211-essential-attributes.md): A look at KoreLogic password cracking operations and the infrastructure attributes that matter for sustained cracking workloads. - [LinkedIn Revisited - Full 2012 Hash Dump Analysis](https://korelogic.com/blog/2016/05/19/linkedin-2012-hash-analysis.md): KoreLogic revisits the full 2012 LinkedIn password hash dump, analyzing the separate email and password lists without linking identities to passwords. - [Update on Crack Me If You Can - DEFCON 2016](https://korelogic.com/blog/2016/03/28/update-on-crack-me-if-you-can-8211-defcon-2016.md): KoreLogic answers common questions about the DEF CON 2016 Crack Me If You Can password cracking contest. - [Hacking an Arris Cablemodem](https://korelogic.com/blog/2016/02/12/hacking-an-arris-cablemodem.md): Part four of KoreLogic firmware research, covering a remote root vulnerability discovered in a popular Arris cable modem. - [The importance of access to firmware files](https://korelogic.com/blog/2015/12/18/the-importance-of-access-to-firmware-files.md): Part three of the firmware series explains why access to usable device firmware matters for IoT security research and vulnerability analysis. - [Unplugging An IoT Device From The Cloud](https://korelogic.com/blog/2015/12/11/unplugging-an-iot-device-from-the-cloud.md): Part two of the firmware series examines Blossom, a cloud-connected smart watering device, and the security implications of IoT cloud dependence. - [Q: Can I have your password? A: Yes you can.](https://korelogic.com/blog/2015/12/04/q-can-i-have-your-password-a-yes-you-can.md): Part one of a firmware and embedded device research series, introducing the security themes and device-analysis approach for the posts that follow. - [LibPathWell 0.6.3 Released](https://korelogic.com/blog/2015/10/01/libpathwell-063-released.md): LibPathWell 0.6.3 release announcement for the PathWell password topology library and PAM module for dynamic password-strength enforcement. - [MASTIFF Output Plug-ins](https://korelogic.com/blog/2015/09/25/mastiff-output-plug-ins.md): An update on MASTIFF output plug-ins and how they advance the project goal of automated static analysis for submitted files. - [How I Solved (Most Of) the Yara CTF Puzzles: Puzzle #9 - #11](https://korelogic.com/blog/2015/08/21/yara-ctf-puzzles-9-11.md): Walkthrough of the final three Black Hat YARA CTF puzzles, covering puzzle logic and YARA rule analysis. - [How I Solved (Most Of) the Yara CTF Puzzles: Puzzle #5 - #8](https://korelogic.com/blog/2015/08/19/yara-ctf-puzzles-5-8.md): Walkthrough of solving puzzles five through eight from the Black Hat YARA CTF challenge, continuing the earlier puzzle analysis. - [How I Solved (Most Of) the Yara CTF Puzzles: Puzzle #1 - #4](https://korelogic.com/blog/2015/08/17/yara-ctf-puzzles-1-4.md): Walkthrough of solving the first four logic and YARA-based puzzles from the Black Hat YARA CTF challenge. - [LibPathWell 0.6.1 Released](https://korelogic.com/blog/2015/07/31/libpathwell-061-released.md): First public release of LibPathWell and its PAM module for dynamic password-strength enforcement using password topology histograms. - [Hacking Team Documents Claim BIOS-based Persistence](https://korelogic.com/blog/2015/07/09/hacking-team-bios-persistence.md): Analysis of leaked Hacking Team material indicating BIOS-based persistence capabilities in the company Remote Control System spyware platform. - [Giles at Black Hat and in the ISSA Journal](https://korelogic.com/blog/2015/06/23/giles-at-black-hat-and-in-the-issa-journal.md): The Giles production rule system compiler (which we described ) has gotten some good press lately! - [MASTIFF Online Updated to Add pyOLEScanner](https://korelogic.com/blog/2015/06/19/mastiff-online-updated-to-add-pyolescanner.md): MASTIFF Online added pyOLEScanner support for Office document analysis, refreshed search controls, and reprocessed existing samples to expose the new plugin results. - [The WebJob Framework: An Endpoint Security Solution](https://korelogic.com/blog/2015/06/10/the-webjob-framework-an-endpoint-security-solution.md): Overview of the WebJob framework, a centralized endpoint security system for executing programs across managed systems in production environments. - [One Month of MASTIFF Online!](https://korelogic.com/blog/2015/05/27/one-month-of-mastiff-online.md): One month after opening MASTIFF Online, KoreLogic released MASTIFF 0.7.1 with bug fixes and new analysis plug-ins. - [What Did CCleaner Wipe?](https://korelogic.com/blog/2015/05/18/what-did-ccleaner-wipe.md): Forensic analysis of CCleaner secure deletion behavior and the artifacts it can leave behind when filenames, file contents, and free space are wiped. - [MASTIFF Online Free 1.0.0 Released](https://korelogic.com/blog/2015/04/27/mastiff-online-free-100-released.md): MASTIFF Online 1.0.0 introduced a free web interface for uploading files and receiving static analysis results from the MASTIFF framework. - [SSD Storage - Ignorance of Technology is No Excuse](https://korelogic.com/blog/2015/03/24/ssd-storage-ignorance-of-technology-is-no-excuse.md): A forensic storage discussion on why SSD behavior changes assumptions about long-term preservation of digital evidence. - [Windows 2003 Privilege Escalation via tcpip.sys](https://korelogic.com/blog/2015/01/28/windows-2003-privilege-escalation-via-tcpipsys.md): Discussion of a Windows Server 2003 SP2 TCP/IP driver vulnerability that could allow local privilege escalation from unprivileged access. - [Giles 3.0.0 Released](https://korelogic.com/blog/2015/01/22/giles-300-released.md): Announcement of the Giles 3.0.0 production rule system compiler release and availability for users of the KoreLogic toolset. - [Brain Bleeding JavaScript Obfuscation](https://korelogic.com/blog/2015/01/12/brain-bleeding-javascript-obfuscation.md): A malware-analysis walkthrough showing how heavily obfuscated JavaScript can hide web-based attacks and how analysts can reason through deobfuscation. - [Using Windows Resource Language Codes for Attribution](https://korelogic.com/blog/2014/12/23/windows-resource-language-attribution.md): A malware-attribution discussion of Windows resource language codes and how they were interpreted in reporting around the Sony compromise. - [VMware: "It''s not a vulnerability, mmkkkayyy"](https://korelogic.com/blog/2014/11/18/vmware-its-not-a-vulnerability-mmkkkayyy.md): Research on VMware Workstation behavior that allowed members of the __vmware__ group to extract arbitrary sections of kernel memory. - [im in ur scm, bein a ninja](https://korelogic.com/blog/2014/11/05/im-in-ur-scm-bein-a-ninja.md): A follow-up on source code repository tampering risks and why compromised developer or administrator access can undermine trusted code. - [Password Security Research Featured in the Huffington Post](https://korelogic.com/blog/2014/10/17/password-research-huffington-post.md): Coverage of Huffington Post reporting on KoreLogic password topology research and the risk of users overusing common password patterns. - [Vuln Analysis: Classic write-what-where in XP's BthPan](https://korelogic.com/blog/2014/10/07/vuln-analysis-xp-bthpan.md): Vulnerability analysis of a write-what-where flaw in the BthPan.sys Bluetooth driver on 32-bit Windows XP SP3. - [CISO's Corner: Password Cracking Best Practices and Myths](https://korelogic.com/blog/2014/10/02/ciso-password-cracking-best-practices.md): A CISO-focused discussion of password cracking risks, breach lessons, authentication assumptions, and practical controls for reducing password exposure. - [FTimes 3.11.0 Released](https://korelogic.com/blog/2014/07/30/ftimes-3110-released.md): FTimes 3.11.0 adds embedded Python file hook support, introduces the ftimes-bimvl tool, and includes cleanup and bug fixes. - [KLogTail 1.2.0 Released](https://korelogic.com/blog/2014/07/22/klogtail-120-released.md): KLogTail 1.2.0 adds bug fixes, clearer warning and error messages for log analysis workflows, a basic man page, and project restructuring. - [Repository Tampering: What You Don't Know Can Hurt You](https://korelogic.com/blog/2014/06/26/repository-tampering-security.md): A security scenario showing how compromised developer or sysadmin accounts can be used to tamper with revision control systems and trusted code. - [Callback Functions in Malware](https://korelogic.com/blog/2014/05/27/callback-functions-in-malware.md): KoreLogic analyzes malware downloaders that use API callback functions to redirect execution flow and complicate reverse engineering. - [MASTIFF Updates and Git SSL Issue](https://korelogic.com/blog/2014/04/17/mastiff-updates-and-git-ssl-issue.md): A MASTIFF development update covering recent repository changes, SSL access notes, and a major change to the analysis plug-in architecture. - [Mini-Crack Me If You Can for ISSW 2014](https://korelogic.com/blog/2014/04/07/mini-crack-me-if-you-can-for-issw-2014.md): KoreLogic ran a mini Crack Me If You Can password cracking contest for ISSW 2014 attendees, with a gift card prize for participants. - [PathWell Topologies](https://korelogic.com/blog/2014/04/04/pathwell-topologies.md): PathWell identifies and blocks common passwords by modeling password topologies and learned user behavior from the DARPA Cyber Fast Track project. - [MASTIFF in KoreLogic Git Repository](https://korelogic.com/blog/2014/03/25/mastiff-in-korelogic-git-repository.md): KoreLogic moved MASTIFF development into a public Git repository so users can access and clone newer development versions. - [ShmooCon Epilogue Prologue: PathWell](https://korelogic.com/blog/2014/01/09/shmoocon-epilogue-prologue-pathwell.md): Preview of a ShmooCon Epilogue talk on PathWell, KoreLogic password topology research, and dynamic password-strength enforcement. - [Converting IDA PAT to Yara Signatures](https://korelogic.com/blog/2013/11/15/converting-ida-pat-to-yara-signatures.md): A technique for converting IDA pattern files into YARA signatures to help identify library code in stripped, statically linked Linux malware. - [MASTIFF on Mac OS X](https://korelogic.com/blog/2013/10/30/mastiff-on-mac-os-x.md): A walkthrough of running MASTIFF on Mac OS X and the portability considerations behind its Python-based design. - [CMIYC 2013 Encrypted Challenge Files, Password Creation, and Hints](https://korelogic.com/blog/2013/09/04/cmiyc-2013-encrypted-challenge.md): We've just published details about the Crack Me If You Can 2013 encrypted file challenges : the passphrase for each encrypted file, and the hints that are included in each one. - [Mini-Password Cracking Challenge for LOLBitCoin Party](https://korelogic.com/blog/2013/08/12/mini-password-challenge-lolbitcoin.md): A mini DEF CON password cracking challenge built around a small NTLM hash list and the story behind its significance. - [CMIYC 2013 Post-game](https://korelogic.com/blog/2013/08/08/cmiyc-2013-post-game.md): A post-game introduction to KoreLogic coverage of the 2013 Crack Me If You Can password cracking contest and follow-up analysis. - [Submerging a GPU Cluster in Mineral Oil](https://korelogic.com/blog/2013/06/05/submerging-a-gpu-cluster-in-mineral-oil.md): KoreLogic consultants describe submerging a GPU cracking system in mineral oil and running it continuously for password research workloads. - [Crack Me If You Can 2013 Is On!](https://korelogic.com/blog/2013/05/09/crack-me-if-you-can-2013-is-on.md): Announcement that KoreLogic would bring the Crack Me If You Can password cracking contest back for DEF CON 21. - [MASTIFF 0.6.0 Released](https://korelogic.com/blog/2013/04/19/mastiff-060-released.md): MASTIFF 0.6.0 release announcement for KoreLogic static analysis users, with updated project files and release materials. - [FTimes 3.10.0 Released](https://korelogic.com/blog/2013/04/01/ftimes-3100-released.md): FTimes 3.10.0 adds updated file hook support, introduces KLEL-based XMagic, fixes bugs, and raises the minimum required libklel version. - [KLEL 1.1.0 Released](https://korelogic.com/blog/2013/02/15/klel-110-released.md): KLEL 1.1.0 release announcement for KoreLogic Expression Language users, with updates to the language and supporting documentation.