-
Certain versions of WebHMI from Distributed Data systems has vulnerabilities occurs.The manufacturer recommends upgrading to version 4.1. (6th Dec 2021)
Preface: CISA Releases Security Advisory on WebHMI Vulnerabilities – https://us-cert.cisa.gov/ics/advisories/icsa-21-336-03 Background: The company Distributed Data Systems LLC is well-known in Ukraine and abroad for products with WebHMI and 7bit brands for remote monitoring and control of industrial equipment in Industry 4.0 format. Remark: 7Bit ModBus Proxy is a caching gateway from ModBus TCP protocol to…
-
The evasion technique of Ring 3 continues to improve. Since this is the entry point. Therefore Layer 7 with deep packet inspection is the bases for defensive technique. (6th Dec 2021)
Preface: In fact, despite the excel icon, the XLL file is a Dynamic Linked Library, a binary executable file. Background: The number of data breaches as of September 30, 2021 has exceeded 17% of the total number of incidents in 2020 (1,291 breaches in 2021, and 1,108 breaches in 2020). The fundamental objective of MS…
-
RAT targeting Nginx. Can we say that NGINX is secure than Apache? (2-12-2021)
Preface: dlopen() The function dlopen() loads the dynamic shared object (shared library) file named by the null-terminated string filename and returns an opaque “handle” for the loaded object. Background: NGINX Plus provides a supported and tested version.Starting at $2500 per year. NGINX is an open source software. Dynamic modules add functionality to NGINX Plus such…
-
CVE-2021-38575 – NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. For a bug discovered half a year ago, CVE assigned a CVE number this month.(1-12-2021)
Preface: If a network interface controller is intended to be used as a boot device for a UEFI operating system or UEFI applications, then a UEFI Driver must be implemented that produces Network Interface Identifier Protocol and UNDI, the Simple Network Protocol, or the Managed Network Protocol. Background: Tianocore EDK II is the UEFI reference…
-
CVE-2021-41256 The Android version of the Nextcloud news app has security issues (30-11-2021)
Preface: Nextcloud is a suite of client-server software for creating and using file hosting services. It is enterprise-ready with comprehensive support options. Being free and open-source software, anyone is allowed to install and operate it on their own private server devices. Background: The Nextcloud News Reader App makes it possible to synchronize feeds between Android…
-
About CVE-2021-3802, Fedora & Ubuntu already address this matter, it is a reminder (29-11-2021).
Preface: (2021-07-30) Reported to KDE and GNOME development teams – In response, patches for both kio and glib were implemented.However, both projects rely mainly on udisks and use own code only as fallback. Background: Ubuntu used to have Unity desktop in its default edition but it switched to GNOME desktop since version 17.10 release.Ubuntu offers…
-
CVE-2021-23654 – This affects all versions of package html-to-csv. The flaw let threat actor can embed or generate a malicious link or execute commands via CSV files (26-11-2021)
Preface: CSV file is a useful thing in today’s world when we are talking about machine learning, data handling, and data visualization. Background: There are many Raw storage bucket for big data analytic. You might store it in a text format such as JavaScript Object Notation (JSON) or comma-separated values (CSV), or perhaps even Apache…
-
About Zoom vulnerability CVE-2021-34423 (25-11-2021)
Preface: What if you need to decide to buy remote meeting software? In front of you, Microsoft Teams, Zoom, and Cisco WebEx. What is your final decision? Or you decide to buy all, because all three items have design weakness but it is under enhancement. Background: What is H.323 suite H.323 is a standard developed…
-
About CVE-2021-21980 – VMware found SSRF, arbitrary file read flaws in vCenter Server (24-11-2021)
Preface: VMware Flash End of Life and Supportability (78589) – https://kb.vmware.com/s/article/78589 Background: Flex is a powerful, open source application framework that allows you to build mobile applications for iOS, Android, and BlackBerry Tablet OS devices, as well as traditional applications for browsers and desktops using the same programming model, tool, and codebase. From a platform…
-
CVE-2021-28706 About Xen memory management design weaknesses (24-11-2021)
Preface: Who uses Xen? Amazon Web Services alone runs ½ million virtualized Xen Project instances according to a recent study and other cloud providers such as Rackspace and hosting companies use the hypervisor at extremely large scale. Xen is a type-1 bare-metal hypervisor. Background: A Xen host will run a number of virtual machines, VMs,…