-
Boeing, U.S. regulator made series of errors ahead of 737 Max crashes: congressional report (SeP 2020)
Preface: From logical point of view, if input only relies on a standalone source (sensor). The integrity of the result all relies on the total amount of variable factors. Perhaps sensor install on airplane is a IoT device. So it lure my interest. Background: Traditionally the older (NG) 737 variants did not have fly-by-wire technology,…
-
CVE-2020-13991 JerryScript 2.2.0 vm/opcodes.c privilege escalation (25th Sep 2020)
Preface: JerryScript is the lightweight JavaScript engine intended to run on a very constrained devices such as microcontrollers. Background: In traditional programming environment.The source code is passed through a program called a compiler, which translates it into bytecode that the machine understands and can execute. Internet of Things devices have serious constraints on CPU performance…
-
Sourcecodester Seat Reservation System Version 1.0 vulnerabilities
Preface: It is common for application developers to use open source as a reference. Synopsis: If you are consider or has been used the free source code to develop the seat-reservation-system.You should stay alert for vulnerabilities in this software product. Vulnerability details: Seat Reservation System 1.0 Unauthenticated SQL Injection (CVE-2020-25762)Seat Reservation System version 1.0 suffers…
-
APT developing new evasion technique to conducting cyber attack – 23rd Sep 2020
Preface: The APT organization provides a hard-to-detect malware to attack other hostile campus. Synopsis: The evasion technique found recently by security expert team is that APT 29 exploit the design weakness of detection machanism. They do a re-engineering to covert a zip file to JPEG.“This technique works because JPEG files are parsed from the beginning…
-
Samba 4.0 and later drag in netlogon protocol vulnerability (CVE-2020-1472). As a matter of facts, the flaw not created by Microsoft – 22nd Sep 2020
Preface: CFB8 was created to have good error propagation properties over a noisy channel. It is well known that it is not fast; it is actually 16 times as slow, as it requires a block encrypt for each byte. Details: CVE-2020-1472, also known as “Zerologon,” was given a “critical” security rating from Microsoft. It has…
-
An issue was discovered in the sized-chucks crate through 0.6.2 for Rust. Software developer should be careful when make use of paypal-rs. (19-09-2020)
Preface: Companies large and small are using Rust in production all over the world, including Mozilla, Dropbox, npm, Postmates, Braintree and others. Vulnerability details: An issue was discovered in the sized-chucks crate through 0.6.2 for Rust CVE-2020-25791…CVE-2020-25796.Chunk:– Array size is not checked when constructed with unit() and pair()– Array size is not checked when constructed…
-
Should you have doubt for use the NFC on your android phone? (CVE-2020-0374 -17th Sep 2020)
Preface: The popularity of NFC mobile payments is owed to its ease of use and improved security options. Near-field communication (NFC) enables smartphones to exchange data and function as a payment device. It stores the customer’s credit card details and allows the user to pay at NFC POS terminals through smartphones. Vulnerability details: In NFC,…
-
Predict the cause let PAN OS has vulnerability occurred (CVE-2020-2040) – 15th Sep 2020
Preface: The firewall does not display the Captive Portal web form to users until you Configure Authentication Policy rules that trigger authentication when users request services or applications. Vulnerability details: A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a…
-
Homeland security urge that do not contempt CVE-2020-1472 – 14th Sep 2020 A new story to Overturn “Netlogon” crypto algorithm
Security Focus:By sending a number of Netlogon messages in which various fields are filled with zeroes, an attacker can change the computer password of the domain controller that is stored in the AD (refer to Index 1). This can then be used to obtain domain admin credentials and then restore the original DC password. Index…
-
Visa proactively urge public aware of Baka Skimmer attack. (Baka credit card skimmer bundles stealth, anti-detection capabilities) – Sep 2020
Preface: Visa identified a previously unknown eCommerce skimmer, and named the skimmer ‘Baka’. Synopsis: The malicious JavaScript code aimed to avoid detection for modern defense system. Baka is stealth, anti-detection capabilities.According to an alert from Visa’s Payment Fraud Disruption (PFD) division, the skimmer also attempts to avoid detection and analysis by “removing itself from memory…