-
Even you have Phoenix shield, all depends on endpoint – 14th jul 2020
Preface: Mobile has 50.13%, Desktop has 47.06% – June 2019 – June 2020 Background: MobileIron helps you simplify the configuration of enterprise settings including email, Wi-Fi, and VPN and more. Meanwhile, MobileIron provides unified endpoint and enterprise mobility management (EMM) for mobile devices. Vulnerabilities details: Please refer to url https://www.mobileiron.com/en/blog/mobileiron-security-updates-available Comment: The official announcement did…
-
reflections on the poc – aruba clearpass policy manager multiple vulnerabilities (13th Jul 2020)
Preface: WiFi features from beginning phase a small group of access extended to enterprises infrastructure nowadays. Even the IoT 4.0 and Industrial system especially ICS and IACS system will be found his footprint. Background: Aruba’s ClearPass Policy Manager, part of the Aruba 360 Secure Fabric, provides role- and device-based secure network access control for IoT,…
-
security focus: Citrix security bulletin CTX276688 (9th JUl 2020)
Preface: Typically, North-South traffic is load balanced by Ingress devices such as Citrix ADCs while East-West traffic is load balanced by kube-proxy. Since kube-proxy only provides limited layer-4 load balancing, service owners can utilize the Citrix ingress controller to achieve sophisticated layer-7 controls for East-West traffic using the Ingress CPX ADCs. Security Focus: With reference…
-
VMware release security update for VeloCloud – 7th Jul 2020
Background: The VMware SD-WAN Orchestrator provides centralized enterprise-wide installation, configuration and real-time monitoring in addition to orchestrating the data flow through the cloud network. Technical highlight – The VeloCloud Orchestrator (VCO) stores only flow statistics with high resolution to provide visibility and troubleshooting capability.By default, a maximum of one million flows are rolled up per…
-
Bootstrap modal forms capable live add edit delete datatables records – stay alert (7th jul 2020)
Preface: Bootstrap modal forms are displayed-on-action pop-up forms that are used for gathering data from website visitors and to register or log users. Background: PHPZAG[.]COM is a programming blog that publishes practical and useful tutorials for programmers and web developers. Solution formulated by PHPZAG – Live Add, Edit and Delete Datatables Records with Ajax, PHP…
-
Cloud service providers remain vigilant – Nginx controller NATS vulnerability – CVE-2020-5910
Preface: Nginx was written specifically to address the performance limitations of Apache web servers Background: In March 2019, Nginx Inc was acquired by F5 Networks for US$670 million. According to statistic on 2020. Nginx server deployed by “375 million websites. There are 1,500 paying customers. Vulnerability detail : A malicious user with access to the…
-
Samba releases security updates – 4th Jul 2020
Preface: A set of unsafe default configurations for LDAP channel binding and LDAP signing exist on Active Directory domain controllers that let LDAP clients communicate with them without enforcing LDAP channel binding and LDAP signing. This can open Active Directory domain controllers to an elevation of privilege vulnerability, said Microsoft. Notice: If you are a…
-
Perhaps Microsoft Windows Codecs Library Remote Code Execution Vulnerability let attacker exploit “write4”. 2nd Jul 2020
Preface: Currently, there are no known workarounds or mitigations for these vulnerabilities. Thankfully, the Redmond adds that the flaws are not publicly disclosed and that there are no known exploits in the wild. The firm credits Trend Micro’s Zero Day Initiative for privately disclosing the bugs. Background:From security point of view, attacker who keen to…
-
CVE-2020-2021 PAN-OS: Authentication Bypass in SAML Authentication (29th Jun 2020)
Preface: SAML implements a secure method of passing user authentications and authorizations between the identity provider and service providers. When a user logs into a SAML enabled application, the service provider requests authorization from the appropriate identity provider. Design weakness: The design weakness of SAML was not XML edge cases nor attacker stealing your signing…
-
If so, how to avoid risk happen. Schneider Electric T300 design weakness (30th Jun 2020)
Preface: Dedicated to the specific industry, so called operation technology. Details: Schneider Electric announce to public that their Easergy T300 has design weakness. When you go through the document (see below url). It official inform that you have to trust your source and make use of your firewall or VPN enforcing the protection. Perhaps you…