-
802.1AB is the burden of Cisco Nexus 9000 series Fabric switches. it let cisco increase one more vulnerability (CVE-2019-1890) – 3rd Jul 2019
Preface: Switched Fabric or switching fabric is a network topology in which network nodes interconnect via one or more network switches. What is Cisco ACI? – Cisco ACI is a tightly coupled policy-driven solution that integrates software and hardware. The hardware for Cisco ACI is based on the Cisco Nexus 9000 family of switches. The…
-
2nd Jul 2019 – VMware product updates address Linux kernel vulnerabilities in TCP Selective Acknowledgement (SACK) (CVE-2019-11477, CVE-2019-11478)
Preface: ESXi is not built upon the Linux kernel, but uses an own VMware proprietary kernel (the VMkernel) and software, and it misses most of the applications and components that are commonly found in all Linux distributions. In common Linux circumstances to avoid SACK vulnerabilities. The workaround are: CVE-2019-11477 Workground – Disable sack: sudo sysctl…
-
cve-2019-7225 hmi hardcoded credentials vulnerability (jul 2019)
Preface: As time goes by, As time goes by, the common software design mistake found on business computer world now extend to industrial area. The impact includes SCADA , PLC and graphical user interfaces software. Design defect: On systems, a default administration account exists which is set to a simple default password which is hard-coded…
-
Orvibo smart home devices leak billions of user records – customer must staying alert – Jul 2019
Preface: If victim is not negligence. Can we give an excuse to him? Company background: Orvibo, a Chinese smart home solutions provider. Story begin: A technical report shown to the world that Orvibo (ElasticSearch cluster) leaked more than two billion user logs containing sensitive data of customers from countries all over the world.Does the admin…
-
Not a fashion famous brand. Hermes ransomware, the predecessor to Ryuk. NCSC Releases Advisory on Ryuk Ransomware.
Preface: The NCSC is investigating current Ryuk ransomware campaigns targeting organisations globally, including in the UK. In some cases, Emotet and Trickbot infections have also been identified on networks targeted by Ryuk. Technical details: Ryuk was first seen in August 2018. The Ryuk ransomware is often not observed until a period of time after the…
-
IoT world hiccups – CVE-2019-12951 Mongoose parse mqtt() Function Heap-Based Buffer Overflow Vulnerability – Now fixed – Jun 2019
Preface: Smart City look like a housekeeper. The sensor is his eye.But do you have question? He is a man or she is a woman. Background: Mongoose is a cross-platform embedded web server and networking library with functions including different protocol (TCP, HTTP, WebSocket, Server MQTT client and broker). What is MQTT? MQTT is a…
-
Cisco security advisory – DCNM – Jul 2019
Preface: The vendor announce that they found vulnerability on their product means they are responsible. Even though it is not a good news. But believe that it is under control. Product background: Data Center Network Manager (DCNM) is the network management platform for all NX-OS-enabled deployments . Vulnerability details: Authentication Bypass Vulnerability occurs due to…
-
A design flaw – The CVE dictionary entry submitted on 2018 (cve-2018-10239), vendor official announcement of the first publication on May 13, 2019.
Preface: You can still find the default username and password on your computer today! Coincidentally, they share common characteristics. They have super user capabilities. Synopsis: Infoblox delivers essential technology to enable customers to manage, control and optimize DNS, DHCP, IPAM . Vulnerability Details: A privilege escalation vulnerability in the “support access” feature on Infoblox NIOS…
-
Country to country APT attack mechanism not complex, believe that it exploit design flaw instead of backdoor – Jun 2019
Preface: It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness, … Synopsis: Mongoose is a cross-platform embedded web server and networking library with functions including different protocol (TCP, HTTP, WebSocket, Server MQTT client and broker). Since the footprint is small…
-
Microsoft Exchange server 2013 and new version of product are vulnerable to NTLM relay attacks (2019)
Preface: A privilege escalation is possible from the Exchange Windows permissions (EWP) security group to compromise the entire prepared Active Directory domain. Vulnerability details: A tool capable for performing ntlm relay attacks on Exchange Web Services (EWS). It spawns an SMBListener on port 445 and an HTTP Listener on port 80, waiting for incoming connection…