-
CVE-2020-10143 – Macrium Reflect :Vendor slogan claims that there are 12 million of devices had installed their software around the world.
Preface: Sometimes vulnerability causes by misconfiguration. Vulnerability details: MinGW (http://www.mingw.org/) provides a complete Open Source programming tool set which is suitable for the development of native MS-Windows applications, and which do not depend on any 3rd-party C-Runtime DLLs. For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets assume that resulting programs and libraries are…
-
New variant of the Zebrocy (smqft_exe & sespmw_exe). They are design to perform various functions on the compromised system, said USCERT (3rd Nov 2020)
Preface: Some expert comment that because of Go language programming file will be large than usual. It might have possibilities to evade virus scanning. So malware author like to use. Perhaps this is not the major factor. Background: In July 2019, a security researcher found nearly 10,700 unique samples of malware written in Go programming…
-
If you are Incorporating Oracle Business Intelligence Results into External Portals or Applications, you should stay alert! Oct 2020
Preface: Integrating Oracle BI Presentation Services into Corporate Environments Using HTTP and JavaScript. Java made business operation perfect. Meanwhile, it make people headache! Background: When called from within an Oracle BI Presentation Services screen, such as a dashboard or an HTML result view, the URL should begin with the following characters: saw.dll?Go When called from…
-
CVE-2020-15157 – Vulnerability in Containerd (before version 1.2.14 )
Preface: Cloud computing build civilization chain. The strongest of AI, Smart City technology will be according to the foundation of cloud. Technical background: Google Container Registry (GCR) is a service in Google Cloud Platform (GCP) to manage your own docker container repository. This is fully managed service and you can store your custom container images…
-
VMware Horizon Server and VMware Horizon Client updates address multiple security vulnerabilities (CVE-2020-3997 & CVE-2020-3998) 22-10-2020
Preface: Cross-site scripting (XSS), is a type of attack in which malicious scripts are injected into websites and web applications for the purpose of running on the end user’s device. Background: VMware Horizon provides virtual desktop and app capabilities to users utilizing VMware’s virtualization technology. A desktop operating system – typically Microsoft Windows – runs…
-
Closer look of CVE-2020-1953 – it was impact Oracle OHF Self Service Analytics (20th Oct 2020)
Preface: As healthcare organizations look to reduce cost, IT rationalization and process transformation is accelerating as providers adopt cloud strategies. Background: Oracle Healthcare Foundation is a feature-rich analytics platform that supports more than 35 subject areas relevant to health data analytics,giving healthcare providers more granular data regarding the requirements of individuals and populations. Vulnerability details:…
-
Security Focus – ESXi OpenSLP RCE vulnerability (CVE-2020-3992)
Preface: If you like open source application. You should also like the bug he given. OpenSLP has been ported to a wide variety of systems. For example: Linux (32/64),Windows (32/64),SCO Unix,FreeBSD,Solaris,Tru64,Mac OS X,Darwin,… OpenSLP eliminates the need for users to know the names of network hosts. With OpenSLP, the users need only know the description…
-
Does it whether a myth or it is true? Quantum entanglement in Pyramid internal compartment.
Preface: The pyramid of Egypt. It is a mystery to mankind on the Earth. What is it use for? According to scientists evaluation by far. It is hard to believed that the ancient mankind have such knowledge and capabilities to build this facility. This article was used current known materials. Furthermore, it includes my imagination…
-
CVE-2020-16951 – SharePoint users staying alert! (17th Oct 2020)
Preface: Perhaps it is a design limitation. SharePoint did not check the source markup of an application package which provides an opportunity to attacker. However when you read the prerequisite requirement of the proof of concept. You will feel that it might have difficulties to exploit this vulnerability. However it found a way to trigger…
-
CVE-2020-13943 – Apache Tomcat HTTP/2 DoS (16th Oct 2020)
Preface: Slow HTTP attacks are denial-of-service (DoS) attacks. It was happened near decade ago. Such vulnerability let the people aware application security. Background: Why do we need HTTP/2? HTTP/2 allows the client to synchronously send multiple requests to the server through the same TCP connection, and the server can also use the same TCP connection…