-
To avoid malware misuse “PACKET_MMAP” function,from Linux environment. CISA Releases Free Detection Tool for Azure/M365 Environment (29th Dec 2020)
Preface: Neither shellcode or shellcode injection have anything to do with shell scripting. It is a sophisticated way of finding a vulnerable spot on the cyber security layer of an organization and exploiting it for malicious purposes. Background: Azure Sphere is a secured, high-level application platform with built-in communication and security features for internet-connected devices.…
-
Just heard Whirlpool hit in Nefilim ransomware attack (28th Dec 2020)
Preface: Do you have doubt? For example: Mimikatz tool & Psexec.exe will detected by antivirus. How ransomware disable antivirus? Technical Reference: Malware can no longer disable Microsoft Defender via the Registry.So it increase the difficulties to evade the defense mechanism. But it still cause great damage. A ransomware wreaked havoc on the digital world. The…
-
Reminder: For those who are using it (SCO Openserver) 28th Dec 2020
Preface: Today’s web design tools are quite mature, and you can complete large websites without even touching HTML syntax. Maybe the vulnerability can happen in this way! What’s HTTP Method?OPTIONS, GET, HEAD, POST, PUT, DELETE, TRACE, CONNECT What is the difference between GET and POST?In HTTP GET Method, it is not allowed to pass data…
-
CISA Insights for ongoing APT Cyber Activity One of the key topics: CISA Issues Emergency Directive to Mitigate the Compromise of SolarWinds Orion Network Management Products. (24th Dec 2020)
Design weakness on SolarWinds Patch Manager found April, 2019. The flaw is that when Notepad++ and 7-Zip do not requiure trust sign verification. Fundamentally, 7-Zip has never signed their packages. Meanwhile the certificate to sign Notepad++ is expired at that time. SolarWinds asks customers with any of the below products listed as known affected for…
-
Before the end of 2020, there are two important notes to remind Citrix users (22nd Dec 2020)
Preface: Many companies, especially law firms, and financial institutions will choose Citrix thin client functions. The decision seems to be correct, because their function looks perfect. For example, TCP offloading and network security protection. However, in order to cope with on demanding digital technology market. As a result, they are involved in some technologies and…
-
The other side of the Pyramid. Other episode of the human civilization (Dec 2020)
Preface: In according to my article (Quantum entanglement in Pyramid internal compartment) My idea defined it is a prequel. The following details are based on Exodus (Pentateuch of Moses). So far, the mainstream viewpoint of Catholicism hiding the old testament of bible. However, the unearthed cultural relics including “Death Sea Scrolls” and “Ancient Mesopotamia wedge…
-
CVE-2020-4829 – AIX owner should be staying alert! (14th Dec 2020)
Preface: When I was young, there were two giants in the mid-range system market. They are IBM and Sun Micro. Over the time, IBM won this market. To this day, the business world likes to use IBM AIX OS the most. Background: About twenty years ago, a well known buffer overflow vulnerabilities discovered in Kerberos…
-
FireEye detected APT activities go through Solarwinds product – 13th Dec 2020
Preface: SolarWinds Orion is an IT performance monitoring platform that helps businesses manage and optimize their IT infrastructure. Vulnerability details: SolarWinds.Orion.Core.BusinessLayer.dll is signed by SolarWinds. However, when connection come from trusted vendor (valid signature ) which carry malware. Existing design do not have defense mechanism. Impact: CISA has determined that this exploitation of SolarWinds products…
-
Chakra scripting engine countdown. However, you still need to patch (11th DEc 2020)
Preface: Microsoft Edge no longer uses Chakra. Microsoft will continue to provide security updates for Chakracore 1.11 until 9th March 2021 but do not intend to support it after that. Background: Chakra, a JavaScript engine that powers Windows applications written in HTML/CSS/JS and used to power Microsoft Edge. ChakraCore supports Just-in-time (JIT) compilation of JavaScript…
-
The CERT Coordination Center Bulletin – About the vulnerabilities affecting the open source TCP/IP Stack (8th Dec, 2020)
Preface: October 1, 2019 – A security firm has identified 11 vulnerabilities, named “URGENT/11. Background: TCP/IP stack was developed using subset of the āCā language. The open source TCP/IP stack design is widely used in embedded systems in the market. Briefly describe it as an IoT device. It runs in your business environment and in…