-
CVE-2019-1346 A denial of service vulnerability exists when Windows improperly handles objects in memory.
Preface: Doing web browsing and open document is our daily life. Opps! But it will hit a DoS vulnerability. Background: x64 extends x86’s 8 general-purpose registers to be 64-bit, and adds 8 new 64-bit registers. The 64-bit registers have names beginning with “r”, so for example the 64-bit extension of eax is called rax. The…
-
About Emotet malware (2019)
Preface: Emotet malware found in 2015. But he is still aggressive nowadays. It shown that it is a long life cyber attack product . Details: Australian Cyber Security Centre (ACSC) released an advisory that Emotet malware widespread in rapidly. The Emotet malware is distributed mostly by means of phishing email that contains either links to…
-
Please be vigilant. Spyware will be installed on your phone at any time – Oct 2019
Preface: Since the spyware runs in a stealth mode, it will let you track the device without being detected. Background: Patroit Act empower law enforcement agency or related department can legally monitor the movements of suspect especially Terrorism. And therefore law enforcement agency will be used spyware monitor what’ the target movement. As time goes…
-
CVE-2019-12941 – AutoPi ( Wi-Fi/NB and 4G/LTE) devices wifi password vulnerability (Oct 2019)
Preface: Are you afraid of someone suddenly controlling your car? Background: AutoPi is a small device that plugs into the OBD-II port of your car. What is OBD-II port? OBD-II port of the car which gives the dongle access to the cars internal systems. AutoPi also provides a cloud service that lets you communicate with…
-
Oct 2019 – When hostile countries are prepared to take military action. They took cyber attacks as a 1st step.
Preface: Both ransomware and malware are powerful cyber attack tools. This is equivalent to the army entering a hostile country. Background: On yesterday 21st Oct 2019, NSA and NCSC release joint advisory on Turla Group Activities article. The attack target is the aspx shell. It appeared to use these ASPX shells to preparing 2nd round…
-
CVE-2019-6475 Bind 9 vulnerability
Preface: Existing internet service require DNS lookup function. See whether artificial intelligence world will be replaced this function? Background: There are currently 13 root servers in operation. In order to avoid DNS request in high volume could not handle immediately. And therefore when requests are made for a certain root server, the request will be…
-
(CVE-2019-16919) VMware Cloud Foundation and VMware Harbor Container Registry for PCF address broken access control vulnerability 16th oct 2019
Preface: It seems that humans are hard to avoid living with robots and AI, because this is our destiny. Background: VMware Harbor Registry is an enterprise-class registry server that stores and distributes container images. The release of Harbor 1.8 revealed a number of new features, including the ability to share Harbor with other registries. The…
-
CVE-2019-14379 (Oracle Banking Platform & Oracle Financial Services Analytical Applications Infrastructure) – Oct 2019
Preface: Vendor vulnerability management program sometimes have doubt to public. They frequent ask, how to do the protection before patch release? Perhaps not require worry too much because zero-day vulnerabilities are go with us all the time. Synopsis: On October 2019, Oracle has released its Critical Patch Update for October 2019 to address 219 vulnerabilities…
-
Suspected that Podman-Varlink encounter Remote Code Execution – Under observation (14th Oct 2019)
Preface: Red Hat is investing in CRI-O and Podman. Meanwhile they are involved in the Open Container Initiative Standards Organization. The goal is to contribute and introduce drive innovation in their products, such as Red Hat OpenShift and Red Hat Enterprise Linux. Background: Podman decide to provide a simple CLI for managing pods and containers.…
-
CVE-2019-17132 vBulletin through 5.5.4 mishandles custom avatars
Preface: vBulletin™ is the world leader in forum and community publishing software. Vbulletin messenger make use of AJAX-based chat functionality.The main benefit of developing websites using Ajax is to help web browsers retrieve more data without causing a Web page to refresh. Vulnerability details: User input passed through the “data[extension]” and “data[filedata]” parameters to the…