-
CallStranger – CVE-2020-12695 (Reflected Amplified TCP DDOS via UPnP SUBSCRIBE Callback) – 29th July 2020
Preface: In the cyber world, many defense mechanisms can accomplish tasks well. However, the daily operations involves different business expectations and change management. As a result it create a lot of opportunity to the cyber criminals. Security focus today: With reference of US CERT announcement on 8th July 2020. US Cert urge the information technology…
-
Joint alert from CISA & NCSC – Potential Legacy Risk from Malware Targeting QNAP NAS Devices – 27th JUL, 2020
Preface: Do a simple search in Shodan and you will find many QNAPs on the Internet. Installation status of NAS(QNAP) around the world: We are not surprised that NAS (QNAP) equipment has a huge customer footprint. Because the price is reasonable (RAID-5), it is cost-effective. As a result, business operations including medium-sized enterprises are willing…
-
CISA urges F5 users to stay vigilant to deal with CVE-2020-5902 (24th Jul2020)
Preface: As of today, F5 BIG-IP Platform has market share 72%. Background: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published on 24th July, 2020. They urge to F5 customers that it should be stay alert. They has evidence proof that attackers are active exploit the vulnerability (CVE-2020-5902 – unauthenticated remote code execution (RCE)…
-
Citrix Workspace app for Windows Security Update CVE-2020-8207 (23-07-2020)
Preface: Input validation will be difficult if the environment contains different features. Even though software developer follow the guideline. Because it use http or https connection design , so it increase the difficulties! Background: Citrix Workspace app consists of the Citrix Receiver core, HDX engine, the new embedded browser engine, files view and mobile app…
-
Vulnerabilities in SICAM MMU, SICAM T and SICAM SGU (Jul 2020)
Preface: In industries, power plants and substations, the SICAM MMUis applied to measure and calculate parameters. Product background: SICAM T (transducer) is a digital measuring sensor that allows the measurement of electricity in non-electrical networks in a single unit. ICAM-MMU (Measurement and Monitoring Unit) is a power monitoring device that allows the measurement of electricity…
-
Trojan under the .NET platform remains unchanged for a hundred years (22nd Jul 2020)
Preface: SharePoint will simply not use Framework versions for which they do not apply. For example, SharePoint 2010 uses .NET 2.0. If you install .NET 4, it will remain unused by SharePoint 2010. SharePoint 2019 uses .NET 4.7 and any lower version will simply not be used. Background: Using Microsoft sharepoint as CRM, or external…
-
Windows 10 command “wsreset” co-exists with “mklink” generate a way of User Account Control bypass. (21st JUl 2020)
Preface: UAC bypass has following techniques – using Eventvwr and the Registry Key or using COM Handler Hijack A new way with different technique: WSReset[.]exe open the Windows Store app and clear Windows Store Cache when Windows store cache is damaged or you encounter problems when using Windows Store. If an attacker can create a…
-
Sometimes he is a friend, but suddenly….(MAR-10296782-1.v1 – SOREFANG) – 29th Jul 2020 [Recently goal: Targeting COVID-19 Research, Vaccine Development ]
Preface: It looks that who have vaccine of COVID-19 will be grant the dominance of the world. Reference: DVC APIs will help you to implement modules on the server and client side of a Remote Desktop Services connection that communicate with each other.A remote code execution vulnerability exists in Remote Desktop Services. When an unauthenticated…
-
Oracle cve-2020-14606 & CVE-2020-14701. It makes interested people want to know more (17-7-2020)
Preface: The addition of a forged TCP packet to an existing TCP session. Can only be performed on unsecured sessions (not HTTPS). About Oracle Critical Patch Update – July 2020 : When I open the related Oracle article. It was amazing that containing a whole bunch of vulnerability details. Meanwhile I had headache that how…
-
Point of view – CVE-2020-1350 Windows DNS Server RCE (14th Jul 2020)
Preface: Perhaps we ignore DNS server side design weakness so far. It is on the way impacting cyber security world. Background: DNS is a hierarchical client-server protocol. Each domain is served by one or more DNS servers, meaning requests for subdomains are sent to these servers. Replies can also be cached by intermediate servers in…