Author: admin

  • Interested in this vulnerability CVE-2019-5541?

    Preface: As far as I know, VMware announced CVE-2019-5541 on April 2019. But the security update just released two days ago. Perhaps this products not in profitable area. But the flaw awaken quite a lot of people to concerning the weakness in virtual machine design. Background: VMware Workstation is for Windows/Linux while Fusion is for…

  • CVE-2019-0721, CVE-2019-1397, CVE-2019-1398, CVE-2019-1399 – Hyper-V Remote Code Execution Vulnerabilities

    Preface: Virtualization in the virtualization platform. It is definitely a microsystem architecture. Technical background: Windows Sandbox requires a Type 1 hypervisor. Therefore, to run Sandbox on a virtual machine, nested virtualization must be enabled. Nested virtualization allows running Hyper-V on a virtual machine. In addition, it allows Windows Sandbox to run on a virtual machine.…

  • The arbitrary code execution (ACE) is on your wrist CVE-2019-8718

    Preface: XNU is an operating system kernel developed by Apple Computer for the macOS operating system. It is part of the Darwin operating system. XNU is a hybrid kernel combining the Mach kernel . Background: IOKit – Gain user-space access to hardware devices and drivers. The IOKit object representing a hub device on the USB…

  • Nov 2019 – malware samples, staying alert!

    Preface: The Trojan mostly arrive via email or spread from infected websites that users visit. Background: U.S. Cyber Command has released seven malware samples. The malware hash shown as below: a2a77cefd2faa17e18843d74a8ad155a061a13da9bd548ded6437ef855c14442 fdb87add07d3459c43cfa88744656f6c00effa6b7ec92cb7c8b911d233aeb4ac 738ba44188a93de6b5ca7e0bf0a77f66f677a0dda2b2e9ef4b91b1c8257da790 04d70bb249206a006f83db39bbe49ff6e520ea329e5fbb9c758d426b1c8dec30 618a67048d0a9217317c1d1790ad5f6b044eaa58a433bd46ec2fb9f9ff563dc6 1ea6b3e99bbb67719c56ad07f5a12501855068a4a866f92db8dcdefaffa48a39 b6811b42023524e691b517d19d0321f890f91f35ebbdf1c12cbb92cda5b6de32 Our observation: VC++ method of injecting code into other programs is popular (see below): Put your code into…

  • When you receive a word document. Perhaps document contained evasion technique. But you can do a basic health check by yourself. Nov 2019

    Preface: Hot topic in the city this week perhaps is uncover the secret of surveillance power. My focus: Perhaps quite a lot of reader are interested of the program code of the surveillance program ( sigs.py ). As far as we know, similar of surveillance program infection technique will be relied on email attachment (especially…

  • Apache solr 8.2.0 remote code execution (nov 2019)

    Preface: Apache Solr is an application based on J2EE and uses Lucene libraries internally to provide user-friendly search as well as to generate the indexes. Background: Apache Solr powers the search and navigation features of many of the world’s largest internet sites. Vulnerability details: When an attacker can directly access the Solr console, he can…

  • Security focus -malicious cyber activity 1 st November 2019

    Preface: U.S Homeland security released a report that urge the public to protect computer facilities to avoid Trojan attack. The Trojan found on 2014 which continuous upgrade itself in last half decade. Background: Trojan.Hoplight is a Trojan horse that opens a backdoor on the compromised computer. It may also download potentially malicious files. Security focus:…

  • Oct 2019 – The crisis of Indian nuclear power plant’s

    Preface: In fact, of system design weakness, the chances of a hacker getting remote access to systems significantly intensifies. About Indian nuclear power plant’s network was hacked -They have confirmed its newest nuclear power plant was the victim of a cyber attack, exposing the vulnerability of one of the country’s most critical sectors to cyber…

  • past history, new attacks (cve-2015-0008) – 28th Oct 2019

    Preface: Microsoft will be ending support for Windows 7 and Server 2008 on January 14, 2020. This means no more security patching and no more support from Microsoft. Vulnerability details: Found design flaw on 2015. Microsoft Windows Group Policy could allow a remote attacker to take complete control of the system, caused by improper application…

  • samba releases security updates – Oct 2019

    Samba releases security updates – Oct 2019 Preface: Samba like a middle man bridging all the races in cyber world. Background: Samba is a free software for connecting the UNIX operating system to the SMB/CIFS network protocol of the Microsoft Windows operating system. The third edition not only accesses and shares SMB folders and printers,…