-
Microsoft Addresses Windows TCP/IP RCE/DoS Vulnerability – US Homeland security urge for public attention. (14th Oct 2020)
Preface: Before the release of IP version 6, we had a good impression of its features. Technical background: The official technical article provides the definition of IPv6 RDNS option address length (Details refer to attached diagram – point 3). Potential Impact: If an even length value is provided, the attacker intentionally causes the Windows TCP/IP…
-
Homograph Attack (Puny-code) – CVE-2020-25779
Preface: In order to avoid malware attack, DNS is the 1st door for quarantine. This step not difficult, see whether the domain name which calling will be included in the black list. What is Punycode?Unicode that converts words that cannot be written in ASCII. Background: There are two different scenarios for the cyber threat actor…
-
CVE-2020-26947 – Monero-wallet-gui design weakness (12th Oct 2020)
Preface: Monero price US$132.36 today – (12th Oct 2020). Monero (XMR) stands at the top of the list. This cryptocurrency’s popularity has been on the rise, primarily due to its ability to help anonymize users. Monero transactions are much more difficult to trace because they use ring signatures and stealth addresses. Vulnerability details: monero-wallet-gui in…
-
Official alert – APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations (9th Oct 2020)
Preface: Zero-day attacks don’t have signatures; no one in the security community has analyzed the exploited vulnerability yet. It was probably only discovered after the victim reported it. And therefore we should setup a comprehensive vulnerability management program. Risk management – In reality, it’s not easy applying every patch as soon as it comes out.…
-
CVE-2020-12505 & CVE-2020-12506 CODESYS impacting WAGO, not sure who is the next victim? – 7th Oct 2020
Preface: CODESYS is the leading manufacturer-independent IEC 61131-3 automation software for engineering control systems.However the design weakness jeopardize the Industrial world. Highlights: According to the CVE announcement on 30th September 2020. A series of WAGO PLC-ETHERNET fieldbus controllers are vulnerable to cyber attack. Vulnerability details: The authentication can be disabled for the port 11740 when…
-
Security Focus About Samsung mobile phone vulnerabilities. (NVD release date: October 6, 2020)
Preface: So far, it is difficult to detect the PendingIntent vulnerability from a tool. Background: “PendingIntends” insecure usage can lead to serverBY exploiting vulnerable but benign applications that are in securely using PendingIntents. A malicious application without any permissions can perform many critical operations, such as sending text messages (SMS) to a premium number. Known…
-
CVE-2020-24231 – Are you using SymmetricDS for Database Replication on your Docker or cloud environment?
Preface: Cutting-edge technology companies like open source software. Big data analytics companies may need to pay attention. Observation: According to our observation for advanced technology development firm. No matter they are small size or it is a enterprise firm. They do not mind to use the opensource software application. From business point of view, since…
-
Trend Micro Antivirus for Mac Symbolic Link Privilege Escalation Vulnerability (CVE-2020-25776) 5th Oct 2020
Preface: On a Linux system, chmod never changes the permissions of symbolic links; the chmod system call cannot change their permissions. This is not a problem since the permissions of symbolic links are never used. However, for each symbolic link listed on the command line, chmod changes the permissions of the pointed-to file. VULNERABILITY DETAILS:…
-
Ransomware attacks are raging recent. The victim firm including famous watch manufacture, Bank, Health Services, etc. (30th Sep 2020)
Background: Cyber attack commonly based on vulnerability and user negligence. Ransomware also use the same concept. An example of ransomware today: Conti and Ryuk code is similar. Conti uses a similar ransomware note template to Ryuk and that it appeared to be deploying the same TrickBot infrastructure.When the attack campaigns send unsolicited emails that it…
-
Aveva Edna Enterprise Data Historian Vulnerabilities (CVE-2020-13508,CVE-2020-13505,CVE-2020-13503,CVE-2020-13501,CVE-2020-13500,CVE-2020-13499 & CVE-2020-13507) – Sep 2020
Preface: AVEVA has reached agreement to acquire OSIsoft, a pioneer and global leader in real-time industrial operational data software and services. Background: Under normal circumstance, authorized user can navigate to the ASMX file through your browser. So, you can fill in the form with the parameters and post to the DB. If attacker finds the…