UIKit, Metric Logs, Kern_Invalid, Shell Code execution
I use i Phone version 7.1.2 and I am new to apple. I am curious to know if anyone in the community has noticed "bug_type";"193"os_version":"iPhone OS 7.1.2, It seems as though the system crash report states, Exception Type:EXC_BAD_ACCESS (SIGSEGV), Exception Subtyp: Kern_Invalid_Address at 0x0000000015d592c8 triggered by Thread 0 or bug_type";176, found under General, About, diagnostic and usage data.
Or if anyone in the community has also seen awdd-2014-09-11-001040-3.consolidated.metriclog. It seems as if a UIKit is involved similar to cunzhang from Adlab of Venustech, and Ian Beer of Google Project ZOO's findings.
It seems as though crashes are occurring on the phone using shell code execution and UIKit's I am unaware of a patch or software update. Although I have been privy to the wild card diginotar fake ssl certs, in the past.
Has anyone else seen or encountered Data subject FlashStatus-2014-09-10-234947.ips.synced bug type 176, Setup_2014-09-10-075848_iPhone.ips bug type 109, concerning airport settings, bud_2014-)9-11-171830_Metric-Log-Inc.ips Path System Library Private Frameworks, crashed triggered byThread 5 0libsqlite3.dylib+139484 0x000000001995a0dc 0x199518000.
I have shown this to Apple employees and they stated I may need to contact a programmer.
I have contacted Apple directly brought this to their attention, they are, as always very supportive. But, I believe I need a programmer as this is above my expertise. Any help from the community would be appreciated. Even a link to where I can find out more would be helpful.
Yes, thank you. This is the closest solution to my problem.
However, I will now introduce host_profile host agent.
But I can not understand where exactly did I lack rights to the agent?
======================
SAPSYSTEMNAME = SAP
SAPSYSTEM = 99
service/porttypes = SAPHostControl SAPOscol SAPCCMS
service/admin_users = daaadm sapadm
DIR_LIBRARY = /usr/sap/hostctrl/exe
DIR_EXECUTABLE = /usr/sap/hostctrl/exe
DIR_PROFILE = /usr/sap/hostctrl/exe
DIR_GLOBAL = /usr/sap/hostctrl/exe
DIR_INSTANCE = /usr/sap/hostctrl/exe
DIR_HOME = /usr/sap/hostctrl/work
service/logfile_000 = /tmp/s
service/logfile_001 = /usr/sap/DAA/SMDA97/SMDAgent/log/smdagent_trace*.trc
service/logfile_002 = /usr/sap/DAA/SMDA97/SMDAgent/log/smdagent_trace.*.trc
service/logfile_003 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/dispatcher/log/applications*.log
service/logfile_004 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/dispatcher/log/applications.*.log
service/logfile_005 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/dispatcher/log/defaultTrace*.trc
service/logfile_006 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/dispatcher/log/defaultTrace.*.trc
service/logfile_007 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/server0/log/applications*.log
service/logfile_008 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/server0/log/applications.*.log
service/logfile_009 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/server0/log/applications/com.sap.xi/xi*.log
service/logfile_010 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/server0/log/applications/com.sap.xi/xi.*.log
service/logfile_011 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/server0/log/defaultTrace*.trc
service/logfile_012 = /usr/sap/SLM/DVEBMGS00/j2ee/cluster/server0/log/defaultTrace.*.trc
======================
Similar Messages
-
Help 'Exiting' after Automator Shell Script Execution
Hello,
I've recently installed and got running GCalDaemon (http://gcaldaemon.sourceforge.net/) which allows me to Synch Rainlendar <-> Google Calendar through iCal (You can also synch iCal <-> Google Calendar). I needed to start up a shell script/applescript after each startup/login in order for GCalDaemon to start the synching process each time and continue to do so at the timed intervals. I would do so by the following terminal code:
cd /usr/local/sbin/GCALDaemon/bin
./standalone-start.sh
I then tried automating this process and came across shell script execution through Automator. I did so and created a .app with the above mentioned code. This works and it starts up the necessary .sh file I need and the snyching works under StartUp. My concern is however, how do I exit terminal once the code has executed the necessary file? All I have in my .app is the above mentioned code for now. I just need it to exit terminal because on startup or after starting the program, I get this issue (See Attachment)
This continues to run, so my guess is that I need to add code to exit terminal and allow the .app to close itself properly after doing so.
Please guide me in the right direction.
Picture Belows shows what happens when I run the Automator App. It continues to run until I quit out of the app manually (TheGCal programs works fine though). I feel I need to have app quit Terminal or fully end the process and quit out on it's own.
Thanks
<table style="width:auto;"><tr><td></td></tr><tr><td style="font-family:arial,sans-serif; font-size:11px; text-align:right">From GCalDaemon</td></tr></table>i redirected the command output to /dev/null which is unix equivalent of a black hole and I also redirected error output to standard output in case the script produces any errors.
also & at the end tells it to continue without waiting for the script to finish.
Message was edited by: V.K. -
False positive for GNU Bash Remote Code Execution Vulnerabil​ity
Dear Team,
in my customer, one of banking in brunei want to access several finance website such as www.iifm.net etc. Tipping point IPS blokec to access the website with report as a 16800: TCP: GNU Bash Remote Code Execution Vulnerability ( Low Severity). The site is normal and legal website. Our question is the several website is needed to access by our employee due to the dailiy working. Please advice
Best Regards
YudiHello Yuibagan,
This is the Consumer products forum.
You need to be in the HP Enterprise Business Community for IT related issues for servers, etc.
I think you will want to post this question in the Security section. Dont post the same question more than once as you did here.
HP Networking
You will also want to take a look at the Articles and updates explaining GNU Bash here:
GNU Bash vulnerability "Shellshock" (CVE-2014-6271... - HP Enterprise Business Community
HP Security Research: GNU Bash vulnerability "Shel... - HP Enterprise Business Community
HP AppDefender and HP WebInspect updates: GNU Bash... - HP Enterprise Business Community
HPSR Software Security Content 2014 Update 3 - HP Enterprise Business Community
Good luck -
Error with dbms_scheduler and shell script execution
Hi,guys.
I have an issue with a dbms_scheduler and a shell script execution. So, the shell script as it self works fine, when i'm executing ./test.sh all process is running, but when i'm executing the script from dbms_scheduler it just simply doesn't work. Actually it works, but some of executable information in sh doesn't work, seems it just jump over of the part of the script. Sendmail part is running, maybe there is problem with rman script as it self?
DB version: 10g
And my scripts:
Shell scripts (permisons 755):
#!/bin/ksh
export PATH=/home/oracle/product/asm_home/bin:/home/oracle/product/db_home/bin:/usr/bin:/etc:/usr/sbin:/usr/ucb:/home/oracle/bin:/usr/bin/X11:/sbin:.
export ORACLE_BASE=/home/oracle/product
export ORACLE_SID=zabbix
export ORACLE_HOME=/home/oracle/product/db_home
${ORACLE_HOME}/bin/rman<<EOF
connect target /
run {backup recovery area delete all input;}
EOF
{ echo "From:[email protected]"
echo "To: [email protected]"
echo "Subject: Recovery area"
echo 'Content-Type: text/html'
echo
echo '<html><body><table border="1" cellspacing="1">'
echo '<tr><td><b>Process</b></td><td><b>Statuss</b></td></tr>'
echo "<tr><td>RMAN</td><td><b>Works</b></td></tr>"
echo "</table></body></html>"
} | sendmail -tIn the first part i'm exporting all of the important stuff for oracle, then I call RMAN with specific atributes. And then there is just simply sendmail functionality inside script to represent if script works (for now).
And below pl/sql script:
begin
DBMS_SCHEDULER.CREATE_JOB
job_name => 'FLASH_RECOVERY',
job_type => 'EXECUTABLE',
job_action => '/home/oracle/backup/test.sh',
start_date => sysdate,
job_class => 'DEFAULT_JOB_CLASS',
enabled => TRUE,
auto_drop => FALSE,
comments => 'FLASH RECOVERY USAGE AREA backup and delete'
END;
/And this job execution:
begin
DBMS_SCHEDULER.run_job (job_name =>'FLASH_RECOVERY',use_current_session => TRUE);
end;What can be wrong? For me, I think it's something with permisions.
I hope you got my idea and could help me.
Tom
Edited by: safazaurs on 2013.18.2 22:16There is no error, i just receive all the time e-mail, seems it jumps over rman. I tried almost everything and still couldn't get result as i want. And, if i'm running script from command line - it works. Rman calls, and starts to recover archivelogs.
-
Code Execution in Cover Flow View and .mov Files
There is a code inside QuickTime movies that gets executed in Cover Flow view in Leopard!!!!!!!!.
I was helping a friend installing Leopard on his machine, and after restarting, I was showing him the new options in the Finder, when a found a bunch of videos (searched on his computer with Spotlight) and switched to 'Cover Flow View', and then Safari started opening web pages from the internet (Mostly adult sites).
After doing some tests I've noticed that the pages load the moment the Finder 'refines' the view of the videos. You know when the Finder first generates a blocky image of the video (some times called proxy image) and then generates a higher or cleaner resolution of that same video.
Not only that, if I resize the window or the preview pane, the code executed again and Safari opened the pages again!!!!
The Finder also executed the code in icon view with the 'Show Icon Preview' option selected in 'View Options' (Command-J).
Opening the videos in QuickTime Player did not trigger the code. But I've noticed that the videos start playing the moment they open. The Inspector (Command-I) didn't show anything unusual. But the Properties window (Command-J in QuickTime Pro) show a "Sprite Track" of Format 'Sprite' but again the different tabs (Annotations, Resources, Visual Settings or Other Settings) didn't show anything unusual.
*CORRECTION: The code also gets executed at the middle of the video when played in QuickTime. So this problem is related to QuickTime.!!!!!!*
The only solution to stop the code execution is to delete the 'Sprite Track'!!!!.
I also opened the movies in TextEdit and found the following text almost at the end of all the weird symbols:
(I'm sorry but the code disappears when I publish this post).
That's one of the pages that Safari was opening.
I don't know where my friend downloaded those videos, but the potential security risk is imminent.
I had the same results even after updating to QuickTime 7.3
I can upload the videos somewhere (at least the 'clean' ones) so you can make you own tests.
Any thoughts or comments?????
Is this a known issue in QuickTime?????
P.S. Once again please excuse my English (my main language is Spanish).If I'm understanding correctly the "Sprite" is a part of how QuickTime works. In older versions you USED to be able to attach JavaScript to a sprite and do all kinds of useful and fun things. However, some websites used JavaScript to alter themselves, so a well crafted QuickTime movie could be used to deploy code that would alter websites. As a result, a LOT of this functionality was curtailed in later versions and many cool QuickTime functions no longer work.
The few that DO still work are when they are basic hyperlinks that take you to another web page, (Like at the end of this movie, BUT you have to click the link to go
http://www.makentosh.com/tipsfromtheiceberg/Blog/Entries/2006/3/7Somebody_ToldMe....html
) and others no longer work within the browser (they only work when using the QuickTime player). Give this a try. Use Safari to "Open File..." and open the .mov file. After it's open, see if it generates any other windows from there. If it doesn't, then I'd THINK it's operating as intended BUT it wouldn't hurt to send your feedback here for Apple to look into and/or fix it if necessary.
http://www.apple.com/quicktime/feedback/
Message was edited by: Kyn Drake -
Logging same NC code for multiple components
Hi,
When logging NC codes in SAP ME 6.0 it is possible to log the same NC Code (defect) against many ref-des for
multiple components.
However when logging a secondary code (Action) for the previous primary NC Code all the choosen ref-des and components
don't get copied..
Is this how it is supposed to work or is there a setting somewhere so that all ref-des and components gets copied?
Best Regards,
Johan NordebrinkHi Johan,
The matter of your question is related to Ref Des List re-desinged for 6.0.
Overall situation looks like a design gap because:
- no explicit statement in the documentation describing the case of copying multiple Ref Des'es;
- the case of 1-to-1 relation between Component and Ref Des is mentioned in the context of auto-population of these feilds on tabbing out if one of the field is populated;
- the case of single Ref Des is widely referenced in the context of VTR that is a new feature in 6.0.
So, if you need this to be reviewed by Product Mgmt (maybe they agreed to identify this as a bug), as usually you should either ask your SAP ME Consulting representative or submit a support ticket (depending on whom you pefer to talk with ).
Regards,
Sergiy -
Web Part Error: Sandboxed code execution request failed - office 365
If i am trying to edit the webpart, i am getting this error "Web Part Error: Sandboxed code execution request failed"
But the same code worked properly before two months, i didnt done any deployment activities from last 6 months..i dont know how it is possible ?
and the same issue happening during the javascript post back also
1) I cant able to restart the sandbox service because i am using office 365
2) it worked properly before march month, after the patch upgrade which is released by microsoft, i am facing this kind of issue..
can any one help to resolve this issue ?Hi,
Please post your question on online community for sharepoint -
Halt code execution while awaiting a return value - like JOptionPane..
I've been struggling with a minor annoying problem...
I want to achive kindda the same thing as what happens when you call: String s = JOptionPane.showInputDialog(...);
The code execution locks until a value is returned, and this is exactly what I want to be able to do with my own custom dialog/frame/whatever.
Obviously, wait() and notify() on the calling thread won't work, so how can I achieve this optionpane gui-code-locking behaviour with my own custom gui components?
Thx in advance !From JInternalFrame source:
* Creates a new <code>EventDispatchThread</code> to dispatch events
* from. This method returns when <code>stopModal</code> is invoked.
synchronized void startModal() {
/* Since all input will be blocked until this dialog is dismissed,
* make sure its parent containers are visible first (this component
* is tested below). This is necessary for JApplets, because
* because an applet normally isn't made visible until after its
* start() method returns -- if this method is called from start(),
* the applet will appear to hang while an invisible modal frame
* waits for input.
if (isVisible() && !isShowing()) {
Container parent = this.getParent();
while (parent != null) {
if (parent.isVisible() == false) {
parent.setVisible(true);
parent = parent.getParent();
try {
if (SwingUtilities.isEventDispatchThread()) {
EventQueue theQueue = getToolkit().getSystemEventQueue();
while (isVisible()) {
// This is essentially the body of EventDispatchThread
AWTEvent event = theQueue.getNextEvent();
Object src = event.getSource();
// can't call theQueue.dispatchEvent, so I pasted its body here
if (event instanceof ActiveEvent) {
((ActiveEvent) event).dispatch();
} else if (src instanceof Component) {
((Component) src).dispatchEvent(event);
} else if (src instanceof MenuComponent) {
((MenuComponent) src).dispatchEvent(event);
} else {
System.err.println("unable to dispatch event: " + event);
} else
while (isVisible())
wait();
} catch(InterruptedException e){}
* Stops the event dispatching loop created by a previous call to
* <code>startModal</code>.
synchronized void stopModal() {
notifyAll();
}It basically works like this:
If this thread is not the EventDispatcher, then just use wait() and notify().
If it is the EventDispatcher...the process the events from here while we wait for the dialog to close. Seems kind of dirty, but it works. -
I am attempting to increase time the c code execution time as
I improve the performance of my algorithm. I tried using time.h and
when doing something simple like
time_t1;
time(t1);
The compiler responds with
called object ‘&time’ is not a function
What is the best method for timing the c execution time given
we are not using the Alchemy gcc?Yea...I am looking for something on the C side of things. I
tried using clock() also but I don't feel like the values are
correct. The timings stay the same every time I run the program
even with changes to the C code and some other odd results. Any
thoughts? I could just be doing something wrong...does anyone know
if this should work??? -
Varchar2 "Width" during code execution
Release 10g2 --
Is it possible to in some way determine the defined "width" of a char variable (esp. varchar2) during code execution?
For example, given:
=================================
strng VARCHAR2(<width>)
BEGIN
strng := function(sizeof(strng))
=================================
Is there any reasonably straightforward manner to create that "sizeof" function which can return the max width of strng to the function? I'd like to make sure, without writing exception logic, that I don't overflow the boundary of the strng variable. This is fairly easy to do in c but I don't see anything readily analogous in Oracle. Assume that strng is not tied to a table column, in particular, although that, too (i.e., created using %TYPE in the definition) would probably be useful to be determinable as well.
Any suggestions as to how one might accomplish this without some absurd "fill until the exception occurs" loop would be appreciated.Thanks, I searched for something like that but didn't find it.
There is a function called VSIZE in Oracle 9i, but it returns the memory length of the ACTUAL string, not the theoretical maximum. The only way I see for you is to select the string length from the data dictionary, look at ALL_TAB_COLUMNS. Or write a loop with an exception section, trying to add one character after another until the exception is raised. This is correct, VSIZE does not do what I'm after. The specific link above deals more with the special case of %TYPE. I'm more interested in the general case of a defined variable -- Where in the Data Dictionary would I look for information about a variable? (I don't necessarily need instructions, but a pointer to something to read that should cover what I'm after would be helpful-- even a book reference would be of use, since it's hard to tell what books cover what topics well -- I don't mind becoming more knowledgeable about the DD, that seems like widely useful info anyway).
Any suggestions, links, pointers, would be greatly appreciated, thanks. -
Revision: 14488
Revision: 14488
Author: [email protected]
Date: 2010-03-01 15:25:19 -0800 (Mon, 01 Mar 2010)
Log Message:
PARB changes: Mark some APIs as @private (logging and error codes). They're not critical to expose right now, we'll review them, lock them down, and expose them publicly in time for 1.0.
Modified Paths:
osmf/trunk/framework/OSMF/org/osmf/events/MediaErrorCodes.as
osmf/trunk/framework/OSMF/org/osmf/logging/ILogger.as
osmf/trunk/framework/OSMF/org/osmf/logging/ILoggerFactory.as
osmf/trunk/framework/OSMF/org/osmf/logging/Log.as
osmf/trunk/framework/OSMF/org/osmf/logging/TraceLogger.as
osmf/trunk/framework/OSMF/org/osmf/logging/TraceLoggerFactory.asRemember that Arch Arm is a different distribution, but we try to bend the rules and provide limited support for them. This may or may not be unique to Arch Arm, so you might try asking on their forums as well.
-
CF Metrics logging is useful for examining performance problems.
To enable you would edit JRun.XML and apply some changes; details:
http://kb2.adobe.com/cps/191/tn_19120.html
Since CF10 does not use JRun now changed to Tomcat, how would one enable something similar to CF Metrics logging?
I appreciate CF10 > Server Monitoring > Server Monitor is present tho for a system with Standard licence Server Monitor would not available.
Thanks in advance, Carl.The metrics logging in CF 9 and earlier was provided by JRun. However, tomcat does not provide this and the only option is to use its mbeans to get the required information. The cfstat utility that is shipped with CF 10 uses the mbeans API to get the same and you can use that.
We are also exploring if we can build something similar to metrics logging that was there in CF 9 and earlier.
Sent from my HTC -
Allowing the movie to run during complex code execution
Hello,
I have this complex XML processing code that builds up thousands of objects on stage. This might take some time. Perhaps not that big time to bring up that message about slow code execution, however signifficant enough to cause interface uncomfortabilities.
I understand very well that I can restructure my code in order to save all contextual variables, all counters in an object that is passed down to onEnterFrame events that process it a little bit and then pass it further, until the job is done.
However, before I go into dissecting my code, I wanted to make sure if there really is not a way how tom tell flash player do it's frame rendering routine while a complex code is executed in background (without splitting it up).
Thanks!No, unfortunately, Flash player is not able to run something on a seperate thread while code is currently executing (the player will just lock up if the code execution takes longer than a certain amount of time and you'll get the dreaded "A script is causing the player to run slowly" dialog). People have done work to do something similar to what you are trying to do, but ultimately, it comes down to running an ENTER_FRAME event or timer to break up the code execution.
-
Threat Feed (McAfee) say my ipad2 got threats, memory corruption vulnerability exist,
which could lead to remote code execution. How to solve this problem?You can't solve this problem yourself. You would need to wait for apple to release a "fix" or for McAfee to revise their judgement.
If you're worried about the threats, don't do things that would expose yourself to the vulnerability that they describe.
Since I can't see what you're looking at, I can't give you any other advice. -
Hi Experts,
My IPS has been reporting "PHP-Remote Code Execution" attack on one of our webserver for a while now. Each time the attackers IP address keeps changing. I created an object-group and access-list to deny the object-group on my firewall and i keep adding the attacker's IPs to the group, however i keep recieving new "PHP-Remote Code Execution" attacks. My IPS is in promiscous mode and i have auto signature update enabled.
IPS has reported "packet denied by global correlation in some case. Like i said, IPS is in promiscous mode. Signature: 2271/0 and CVE-2012-1823
Apart from making sure the webservers have the right security patches, What else should i be doing?. Do not want to miss anything out?cactus wrote:mhakali. I applaud your attention to security.
However, it is generally not well received to post the same thing in multiple categories..
Yes. Please do not cross-post: http://bbs.archlinux.org/viewtopic.php?p=205922
Use the above thread for discussion.
Locking.
Maybe you are looking for
-
I recently had to buy a new PC as the old one was getting very slow. When the technicians tried transferring over files to the new PC they discovered that several files were corrupted, including iTunes. I had made a backup of iTunes on an external ha
-
Problems when using shared instances of struts and apache-commons?
I found this worrisome statement on this page (http://struts.apache.org/1.3.8/userGuide/configuration.html) regarding sharing jar files across multiple applications: <i>When a class is loaded from a shared class loader, static variables used within t
-
Apple TV rental has corrupted sound
I just rented a movie on my apple tv. It downloaded and the image is perfect but the sound is corrupted and garbled. It can't be watched. Any idea what I can do?
-
How to download the Windows version of the CS6 trial?
Im trying before I buy but I mistakenly downloaded everything to my mac instaed of my pc. Can I get a redo?
-
Hi All , I have a Flex+Java Application , which is running fine , and i am sending the List of employess to Flex from my Java(Struts) like :(In flex i am using HTTPService)(Employee is a java bean) XStream xstream = new XStream(); EmpDAO dao=new E