-
Fastly CDN outage, perhaps not cyber attack (4th Oct, 2021)
Preface: In addition to cyber security attacks. Cloud service providers face different technical challenges, including software and hardware levels. Background: Fastly is a company that provides content delivery network (CDN) services, mainly providing host static content and quickly showing it to Internet users. Fastly peers with other Internet Service Providers (ISPs) and Content Networks with…
-
About CVE-2021-29249, IoT vendor should stay alert! (1st Oct, 2021)
Preface: BPF is available on most Unix-like operating systems and eBPF for Linux and for Microsoft Windows. In addition, if the driver for the network interface supports promiscuous mode, it allows the interface to be put into that mode so that all packets on the network can be received, even those destined to other hosts.…
-
About GriftHorse Malware (30th Sep 2021)
Preface: Large portion of smartphone will not installed antivirus software. Even though it is installed. The antivirus vendor similar doing racing campaign with cyber criminals. Nowadays, vendor established malware sinkhole to find zero day vulnerability and existing cyber attack. If cyber criminals relies on software design limitation hiding itself on phone. Perhaps sinkhole not easy…
-
Stealth attack of UEFI bootkit (29th Sep 2021)
Preface: Digital spyware and monitoring tech that allows the user to covertly monitor a target’s communications, or collect personal data emitted from their devices. Background: FinFisher, also known as FinSpy, is surveillance software marketed by Lench IT Solutions plc, which markets the spyware through law enforcement channels. On August 6, 2014, FinFisher source code, pricing,…
-
About CVE-2021-20034 – (SMA 100 series) Unauthenticated SMA100 arbitrary file delete vulnerability – 27th Sep 2021
Point of view: More than 20 years ago, the firewall function was independent, excluding the firewall policy service and vpn function.The advantage is that when the firewall box is compromised. Nothing else will be found in the box by the attacker.Over time, the trend of unified threat management has grown. From a technical point of…
-
About BTCPayment server – CVE-2021-3830 (26th Sep, 2021)
Preface: Cryptocurrency look like myth. Someone avoid to use. But somebody like it. If Cryptocurrency only provide payment function. That is no investment value. Furthermore if someone going to transfer money will be know who is sender and recipient. If it come true, what is the result? Background: BTCPay Server is an open source, P2P…
-
Does SpaceX use C language? 23rd Sep, 2021
Preface: SpaceX was founded in 2002 by Elon Musk with the goal of reducing space transportation costs to enable the colonization of Mars. Background: Exploring Mars helps scientists understand major changes in climate that can fundamentally change the planet. It also allows us to look for biological features that might reveal whether there was abundant…
-
It is not mystery. The findings address that an original function for CEIP feature is able to misuse (CVE-2021-22005) – 22nd Sep, 2021
Preface: Rapid7 Labs estimates there are over 2,700 vulnerable vCenter servers exposed to the public internet. Background: As of May 1 2020, the Pivotal Telemetry program is governed by VMware’s Customer Experience Improvement Program.Data and continuous feedback loops play an important role in shaping the way Pivotal builds software. VMware analytics service consists of components…
-
Closer look – CVE-2021-25751 (21-09-2021)
Preface: As we know that Kubernetes (K8s) is a container orchestration tool and Docker helps to create a container that is managed by us using Kubernetes. Background: What is subPath in volume mount?Subpath references files or directories that are controlled by the user, not the system. Volumes can be shared by containers that are brought…
-
Security Focus on Microsoft windows CMD Stack Buffer Overflow (19-09-2021)
Preface: Twenty years ago, content filter firewalls were not popular. A quick way to harden the Microsoft Internet Information server is to delete all cmd commands to avoid network attacks. Background: If you would like to run cmd in privileged mode. You have to do the following: type “CMD” you can hit Ctrl+Shift+Enter to open…