-
Sensitive Information into Log File, kubernetes is no exception. 7-12-2020
Preface: If you don’t see much useful in the logs, you could try turning on verbose logging on the Kubernetes component you suspect has a problem using –v or –vmodule, to at least level 4. Technical background: The cluster-level logging in Kubernetes is that Kubernetes has no native cluster-level logging. There are a few proven…
-
We try our best to avoid information leakage. But it is difficult to avoid vulnerability happen. Take care of your cat (Tomcat) – 7th Dec 2020
Preface: We encourages users and administrators to review the Apache security advisory for CVE-2020-17527 and upgrade to the appropriate version, said CISA (4th Dec 2020). Vulnerability details: With known HTTP/2 Protocol practice, HTTP headers are compressed using a combination of compression schemes (static Huffman coding and context adaptive coding). Flow control and dependency mechanisms that…
-
CVE-2020-29534: Perhaps this impact only apply to end user instead of IoT manufacturer. The fact is that 5.9 release just release ob Oct 2020. (3rd Dec 2020)
Preface: The new version of Linux kernel 5.1 will add this io_uring. The main purpose of io_uring is to improve the original Linux native AIO problem. For example:– MySQL and Nginx already support local AIO.– InnoDB uses the asynchronous I/O subsystem (native AIO) on Linux to perform read-ahead and write requests for data file pages.…
-
Xerox DocuShare (6.6.1, 7.0 and 7.5) involves potential data leakage vulnerabilities (3rd Dec 2020)
Preface: The official announcement did not mentioned too much. Do you have doubt of CVE-2020-27177 (Xerox DocuShare vulnerability)? Product details: DocuShare Scan and Print 7 (hereafter, Scan and Print) is a feature which allows you to print documents uploaded to DocuShare, or upload scanned documents to DocuShare. DocuShare security features protect content from unauthorized access…
-
New vulnerability found on Tesla Model X, perhaps the remedy solution is don’t let stranger seat on your car – 1st Dec 2020
Preface: Vulnerabilities found in products are not news. In short, a total of 3 vulnerabilities were found on the Tesla Model X this time. Vulnerability Details: About the new discoveries found on Model X. Please refer to the url below. In addition, the attached drawings will provide you with hints. https://www.wired.com/story/tesla-model-x-hack-bluetooth/ Information Supplement for reference:…
-
Iphone 6s owner have serious operation problem after upgrade their IOS to 12.4.9. Do you think vendor will be fixed?
Preface: Vendor insists to fix the cyber security weakness of CVE-2020-27929 & CVE-2020-27930. However, this iOS upgrade action was caused the specify iPhone product encounter operation difficulties especially 6s. Observation 1: On 5th November, 2020, apple implement security update to enhance the cyber security protection on their products. This enhancement including an remediation action to…
-
CVE-2020-27255 Software vulnerabilities that bypass the address space layout randomization (ASLR) protection (FactoryTalk Linx – Allen Bradley software product) 27th Nov 2020
Preface: To cope with Industrial automation and control system. The technology difference in between IT and OT are small. Perhaps they are close. For cyber security protection matters, seems they are no any difference. Product background: Formerly known as RSLinx® Enterprise, FactoryTalk® Linx is included with most FactoryTalk software and functions as the premier data…
-
Headline News: A hacker has now leaked the credentials for almost 50,000 vulnerable Fortinet VPNs. (26th Nov 2020)
Do you doubt whether you are a victim? A quick way to confirm the vulnerability of Fortinet SSL-VPN ( CVE-2018-13379). Preface: VPN client has design limitation causes information leakage not a news by today. However you should confirm your setup do not encounter this flaw. Background: An unknown person left the information online. The details…
-
Perspective VMware CVE-2020-4006
Preface: Within this week, the impression of VMware products vulnerabilities draw attention with a lot of people. It is because the vulnerabilities was found are high risk rating. But VMware is one of the pillar of virtual machine machine world. Do not worry too much. A good product should have space for improvement. Product background:…
-
VMware ESXi, Workstation and Fusion updates address use-after-free and privilege escalation vulnerabilities (24-11-2020)
Preface: Use After Free scenario can occur when “the memory in question is allocated to another pointer validly at some point after it has been freed. Background: If there is a process named vmware-vmx[.]exe in the process list then there is a virtual machine that is currently powered on. The Virtual Machine Monitor (VMM) process…