Results 1 to 3 of 3

Thread: Evilgrade problem (itunes update)

  1. #1
    Join Date
    2013-Nov
    Posts
    24

    Exclamation Evilgrade problem (itunes update)

    I am currently trying to get Evilgrade to intercept the itunes update process on Windows. I currently have 11.0.3.43. I keep getting errors once the apple update service finds and downloads the payload.






    1. Why is the EULA in Spanish?? And the title of the download is blank?? How do I get it in English and display an accurate title?
    2. Is there a fake a certificate that the apple updater will accept?
    Visit my blog! PenTesting for Amateurs, by Amateurs -- Request your own tutorial, or send one to me to post.
    "thevanoutside" a Wordpress Blog!

  2. #2
    Join Date
    2013-Dec
    Posts
    1
    Hi there! I just saw the message sorry for the delay. I'm one of the developers of Evilgrade, the itunes module execute a xss in the updater if you click in the item a browser have to be executed point to a update payload. I didn't know if this version is still vulnerable but the simple process have a protection and can't be bypassed without a valid autenticode.

  3. #3
    Join Date
    2013-Nov
    Posts
    24
    Quote Originally Posted by famato View Post
    Hi there! I just saw the message sorry for the delay. I'm one of the developers of Evilgrade, the itunes module execute a xss in the updater if you click in the item a browser have to be executed point to a update payload. I didn't know if this version is still vulnerable but the simple process have a protection and can't be bypassed without a valid autenticode.
    Thanks for the reply! Hard to come by during the holidays! I have this pointed to the correct agent, as it is the right size and it IS downloaded. I think the EULA was in spanish because of my region settings (when I was increasing the transmit power to my wireless card I changed the region settings) so no problem there. I guess I'll just pass on to the next module then. I am trying to find a service that most users have, and itunes is the most common.

    I tried winupdate but I don't think this service is vulnerable either then as it wont even download the agent. I have the same exact settings, even tried pointing to the same payload, same syntax, but it looks like windows 8 or 7 isn't vulnerable to the update service either. Looks like they finally got they finally figured out how to sign these updates.
    Visit my blog! PenTesting for Amateurs, by Amateurs -- Request your own tutorial, or send one to me to post.
    "thevanoutside" a Wordpress Blog!

Similar Threads

  1. Last update GUI problem
    By Chayim in forum General Archive
    Replies: 1
    Last Post: 2020-01-13, 19:00

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •