-
Another alert in the medical industry (ZOLL Defibrillator Dashboard design weakness) 15th Jun 2021
Preface: A defibrillator is a device that gives a high energy electric shock to the heart of someone who is in cardiac arrest. What is Defibrillator Dashboard ? A Web-based application provides ability to login. The Dashboard contained monitoring the defibrillators function. Vulnerability details: The U.S. Department of Homeland Security urges the medical industry to…
-
Closer to reality: one of the ways of ransomware infection (15th June, 2021)
Preface: Ransomware infection not merely boots by vulnerability of the windows OS and or products components. Web site programming technique is the accomplice. Perhaps we can say, how successful of ransomware attacks will depends on the total number of compromised web server. What I call the trigger point. Background: Ransomware is often spread through phishing…
-
Rising Ransomware Threat To Operational Technology Assets, US (CISA) urge to critical facilities to tighten their cyber security incident management and protection. 10-6-2021
Preface: When the TCP/IP network protocol replaces the classic MODBUS protocol on a large scale. At the same time, there is a large demand for the deployment of Windows operating system servers and workstations. From the perspective of cyber security, information technology and operational technology are the same. Synopsis: On May (9th May 2021), 2017,…
-
Security Focus : CVE-2021-27610 – Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform (8th Jun, 2021)
Preface: The proof of concept for this vulnerability has been announced. As usual, vendors use their patch release cycle. Therefore, an announcement was issued today (June 8, 2021). Background: SAP NetWeaver is a software stack for many of SAP SE’s applications. It can be used for custom development and integration with other applications and systems,…
-
CVE-2021-20292 – Flaw found in Nouveau DRM subsystem (8th June 2021)
Preface: Nouveau is a free and open source graphics card driver. It is written for Nvidia’s graphics card and can also be used in the NVIDIA Tegra series of system chips. This driver is written by a group of independent software engineers. Nvidia sometimes will be assistance. Background: What is DRM subsystem? The Direct Rendering…
-
CVE-2021-28091 – Lasso incorrect assertion validation and verification – Published: 01 June 2021
Preface: This vulnerability affects other vendors’ use of this product for their single sign-on function. Background: Lasso is a free software C library aiming to implement the Liberty Alliance standards; it defines processes for federated identities, single sign-on and related protocols.Lasso is built on top of libxml2, XMLSec and OpenSSL and is licensed under the…
-
Strangers read your data silently, Smart City infrastructure no exception (VU#799380) 27thMay2021
Preface: Open data indeed is a foundation base of smart City. Since it is not only provide function. Meanwhile it also analyses the daily activities make the IoT function more efficiency. If no hacker in the world. We can living in world more comfortable because we do not need to concern about cyber security. As…
-
CVE-2021-23017 – Nginx DNS Resolver Off-by-One Heap Write Vulnerability (27-05-2021)
Synopsis: Retrospectively of 2019 Apache load balancer setup – Install Apache on the Load Balancer Server. Enable Proxy Server Modules. Configure Apache Load Balancing. The Apache server architecture includes the Apache Core and modules. Nginx found 2004, it is a performance-oriented HTTP server. Compared with Apache and lighttpd, it has the advantages of less memory…
-
Ransomware hard to hunt because they are doing the Guerrilla warfare! 31st May,2021
Preface: A Russian-speaking outfit called DarkSide offered would-be computer crooks not just the tools, but also customer support, New York Times said. My observation: My observation: Perhaps cyber criminals learn from practice. They know the system infrastructure weakness of industrial especially oil, powers supply facilities even logistic industry. Since Java has large capability. The test…
-
Headline News – unauthorized access to japan government systems via Fujitsu ProjectWeb – 28-05-2021
Headline News – The incident affected the Ministry of Land, Infrastructure, Transport and Tourism, Ministry of Foreign Affairs, Cabinet Office and Narita Airport. The stolen data included files stored by government employees on the cloud-based collaboration and file sharing platform ProjectWEB, which was launched by Fujitsu in the mid-2000s and was very popular among Japanese…