-
Not a fashion famous brand. Hermes ransomware, the predecessor to Ryuk. NCSC Releases Advisory on Ryuk Ransomware.
Preface: The NCSC is investigating current Ryuk ransomware campaigns targeting organisations globally, including in the UK. In some cases, Emotet and Trickbot infections have also been identified on networks targeted by Ryuk. Technical details: Ryuk was first seen in August 2018. The Ryuk ransomware is often not observed until a period of time after the…
-
IoT world hiccups – CVE-2019-12951 Mongoose parse mqtt() Function Heap-Based Buffer Overflow Vulnerability – Now fixed – Jun 2019
Preface: Smart City look like a housekeeper. The sensor is his eye.But do you have question? He is a man or she is a woman. Background: Mongoose is a cross-platform embedded web server and networking library with functions including different protocol (TCP, HTTP, WebSocket, Server MQTT client and broker). What is MQTT? MQTT is a…
-
Cisco security advisory – DCNM – Jul 2019
Preface: The vendor announce that they found vulnerability on their product means they are responsible. Even though it is not a good news. But believe that it is under control. Product background: Data Center Network Manager (DCNM) is the network management platform for all NX-OS-enabled deployments . Vulnerability details: Authentication Bypass Vulnerability occurs due to…
-
A design flaw – The CVE dictionary entry submitted on 2018 (cve-2018-10239), vendor official announcement of the first publication on May 13, 2019.
Preface: You can still find the default username and password on your computer today! Coincidentally, they share common characteristics. They have super user capabilities. Synopsis: Infoblox delivers essential technology to enable customers to manage, control and optimize DNS, DHCP, IPAM . Vulnerability Details: A privilege escalation vulnerability in the “support access” feature on Infoblox NIOS…
-
Country to country APT attack mechanism not complex, believe that it exploit design flaw instead of backdoor – Jun 2019
Preface: It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness, … Synopsis: Mongoose is a cross-platform embedded web server and networking library with functions including different protocol (TCP, HTTP, WebSocket, Server MQTT client and broker). Since the footprint is small…
-
Microsoft Exchange server 2013 and new version of product are vulnerable to NTLM relay attacks (2019)
Preface: A privilege escalation is possible from the Exchange Windows permissions (EWP) security group to compromise the entire prepared Active Directory domain. Vulnerability details: A tool capable for performing ntlm relay attacks on Exchange Web Services (EWS). It spawns an SMBListener on port 445 and an HTTP Listener on port 80, waiting for incoming connection…
-
Linux world worries! CVE-2019-11477 TCP SACK PANIC – Kernel vulnerability (Jun 2019)
Preface: Router, SD-WAN,Load-balancer, Firewall and IDS and virtual machine. Their operations are based on Linux operation system. Background: A Selective Acknowledgment (SACK) mechanism, combined with a selective repeat retransmission policy, can help to overcome these limitations. The receiving TCP sends back SACK packets to the sender informing the sender of data that has been received.…
-
CVE-2019-1625 Cisco SD-WAN Solution Privilege Escalation Vulnerability – Jun 2019
Preface: Add the Viptela SD-WAN technology to the IOS XE software running the ISR/ASR routers. Both Cisco ASR and ISR routers offer secure WAN connectivity. Vulnerability details: A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level privileges to the root user on an affected device. Root…
-
CVE-2019-4103 IBM Tivoli Netcool Impact Arbitrary Command Execution Vulnerability – Jun 2019
Preface – You never know what will be happened tomorrow. Synopsis: A vulnerability in IBM Tivoli Netcool Impact could allow an authenticated, adjacent attacker to execute arbitrary commands on a targeted system. Vulnerability details: A vulnerability in IBM Tivoli Netcool Impact could allow an authenticated, adjacent attacker to execute arbitrary commands on a targeted system.At…
-
It is hard to judge it was a self defense or attack. New York Times cyber attack news – 16th Jun 2019