-
CVE-2021-2018 Vulnerability in the Advanced Networking Option component of Oracle DB Srv (20-01-2021)
Preface: When Oracle has security advisory announce each time, I feel headache because vendor not willing to provide the details. Vulnerability details: CVE-2021-2018 -Please refer to the link for details: https://nvd.nist.gov/vuln/detail/CVE-2021-2018 Technical Supplement: A large computer foot print around the world in the office is Microsoft window base machine. Therefore DB infrastructure integrate to Active…
-
Bugs in popular chat apps let attackers spy on users. (21-01-2021)
Preface: I found logic bugs that allow audio or video to be transmitted without user consent in five mobile applications including Signal, Duo and Facebook Messenger, said Natalie Silvanovich. Background: Bugs in Signal, Google chat apps let attackers spy on users. Such vulnerability is given by programming code, and was not due to WebRTC functionality.…
-
Cyber security focus – dnsmasq vulnerabilities (20th Jan, 2021)
Preface: On August 27, 2015 Cisco announced it has completed the acquisition of OpenDNS (now branded as Cisco Umbrella). Perhaps they predict that this day will come. Background: dnsmasq is free software providing Domain Name System (DNS) caching, a Dynamic Host Configuration Protocol (DHCP) server,router advertisement and network boot features, intended for small computer networks.…
-
Are you worried about UEFI BIOS attacks? (19th Jan, 2021)
Preface: Quite a lot of UEFI vulnerabilities and hardware misconfigurations have been found in past. This is an alert signal. As a matter of fact, the problem is that it’s very difficult to get malicious code into UEFI systems. Background: Reading the first sector from a disk and loading it to 0x7C00 is a BIOS…
-
CVE-2021-24122 Apache Tomcat Information Disclosure (14th Jan 2021)
Synopsis:What is a Reparse Point? According to official information by Microsoft, In NTFS Filesystem, there is a concept called “reparse point. The traditional NTFS junctions and Win10 “Unix-like” symlinks are two different kinds of reparse points.Starting in Windows 10, version 1607, for the unicode version of this function (FindFirstFileW), you can opt-in to remove the…
-
Stack-based buffer overflow – the biggest enemy of IoT world
Preface:ASLR, NX Zones, and Stack Canaries is hard to avoid such memory design weakness exploit by malware authors. Background: EIP is a register in x86 architectures (32bit). It is a register that points to the next instruction. In order to avoid malware infiltration. How to keep track of memory location when instructions that are being…
-
While astrologers view planetary alignments as foretellers of disasters. Or is this a rare astronomical phenomenon?
This article was published in January 2021. Preface: If nine different balls are running on a circular orbit. They always have chance to meet up. Synopsis: The order of magnitude of the nine planets is Jupiter, Saturn, Uranus, Neptune, Earth, Venus, Mars, Mercury, and Pluto. The moon orbits the Earth once every 27.322 days. It…
-
NSA releases urgent Guidance (ORN U/OO/800922-17), thus urge to public that not to use obsolete TLS configurations (6th Jan,2020)
Preface: However, obsolete TLS configurations are still in use in U.S. Government systems. Perhaps it is being change. According to the Office of Management and Budget (OMB) memorandum M-15-13 all public accessible federal websites and web services are require to only provide through secure connections. Synopsis: The Internet Engineering Task Force (IETF) published TLS 1.3…
-
CVE-2020-27780 – Linux-pam vulnerability – Improper Authentication (18th Dec 2020)
Background: Linux pam originated from the open source implementation of the software DCE-RFC of Sun, a well-known manufacturer later acquired by Oracle. PAM is called Pluggable Authentication Modules, which can be inserted into authentication modules. Various authentication modules and plug-ins can be dynamically introduced for authentication without reloading the system, very flexible. Vulnerability details: When…
-
CVE-2021-3006 (Loopring(LRC) Protocol Incident)- If you are passionate about cryptocurrency. You should be alert of this. (4th Jan 2021)
Background: In November 2020, lots of DeFi platforms in Ethereum encounters a security incident, such as Pickle Finance, 88mph. What Is Decentralized Finance (DeFi)?By deploying immutable smart contracts on Ethereum, DeFi developers can launch financial protocols and platforms that run exactly as programmed and that are available to anyone with an Internet connection. What Are…