-
CyberArk – CVE-2021-31798 (Quick and dirty way to understand the details) – 1st Sep, 2021
Preface: Cyberark provides the perfect authentication solution for enterprises. Because of their solutions, traditional authentication methods have evolved. However, there is no absolute anti-hacking solution in the world. The following explanation is to let you quickly understand this vulnerability. Even if this is not the right way, you will find out what they are doing.…
-
Do you think CVE-2020-20486 (IEC104 v1.0) will impact your services? (31st Aug 2021)
Preface: IEC 60870-5-104 protocol (aka IEC 104) is a part of IEC Telecontrol Equipment and Systems Standard IEC 60870-5 that provides a communication profile for sending basic telecontrol messages between two systems in electrical engineering and power system automation. Background: IEC 104 enables communication between control station and a substation via a standard TCP/IP network.…
-
Not a critical flaw, but it is commonly found on web UI applications – VMware vRealize log Insight (CVE-2021-22021) – 24-8-2021
Preface: Log event collection without data normalization , it is hard to managed. And you will be crazy. If you do not have log event aggregation and correlation functions. Your IT life will become not easy. Background: vRealize Log Insight delivers indexing and machine learning based Intelligent Grouping, to enable searching, for faster troubleshooting across…
-
Another flaw prompted an urgent U.S. government warning and providing Guidance (Azure Cosmos DB) – 29th Aug 2021
Preface: Data scientists are big data wranglers, gathering and analyzing large sets of structured and unstructured data. Jupyter Notebooks allow data scientists to create and share their documents, from codes to full blown reports (Help them streamline their work). Background: Azure Cosmos DB built-in Jupyter Notebooks are directly integrated into the Azure portal and Azure…
-
VMware security update (25th AUg 2021)
Preface: VMware has released a security update on August 24, 2021 to address vulnerabilities in multiple products. In addition, the risk level of these vulnerabilities is between 4.4-8.6 (CVSS-V3). So it attracted my interest in reading it. Background: The vRealize Operations Manager API Programming Guide provides information about the vRealize Operations Manager REST APIs, including…
-
If you are the Open Source Platform (Istio) user, please stay alert! 24-9-2021
Preface: Today developers are using Docker to build modules called Microservices, which decentralize packages and divide tasks into separate, stand-alone apps that collaborate with each other. Background: A sidecar proxy is an application design pattern which abstracts certain features, such as inter-service communications, monitoring and security, away from the main architecture to ease the tracking…
-
Do you know the design weaknesses of Eclipse Cyclone DDS? 23-08-2021
Preface: DDS is used in the following industries. DDS is used to share Flight data within and across Air Traffic control centers. DDS is used to Smart Factories to provide horizontal and vertical data integration across the traditional SCADA layers.DDS used to control the 100.000 mirrors that make up ELT’s optics. Technical background: DDS applications…
-
CISA cyber Security Alert – About the May 2021 MS patch (21st Aug, 2021)
Preface: With Exchange Server vNext, Microsoft is phasing out the on-premise delivery model, making Exchange Server 2019 the last on-premise product version. Point of view: Perhaps quite a lot of people will be surprised of this notification. Since more and more organizations has been migrated the mail server to office 365. The patch issued on…
-
There’s no best of both sides – CVE-2021-25218: BIND 9.16.19 and 9.17.16 triggered denial of service when applied too-strict assertion check. (19th Aug, 2021)
Preface: (BIND) is the most popular Domain Name System (DNS) server in use today. It was developed in the 1980s at the University of Berkleyand is currently in version 9. Technical Background: For IPv4 packets, Path MTU Discovery works by setting the Don’t Fragment (DF) flag bit in the IP headers of outgoing packets. Some…
-
As an end user, are you concerned about the CVE-2021-28372 vulnerability? 17th Aug 2021
Preface: The Kalay platform contains a major vulnerability that will allow hackers to remotely access IoT devices. Background: Kalay Platform 2.0 This newly developed decentralized structure simplifies the role of the primary server to work as an intermediary transmitter,which reduces the chances of a server being compromised or data being intercepted. Kalay 2.0 is designed…