-
Did you have trouble accessing internet on Sat (8th Jun 2019 GMT+8)
Synopsis: The users were temporarily unable to reach adjacent countries internet web sites for short period of time (less than 1 – 3 minutes) due to an issue of Internet BGP backbone. Description: On Sat, I was surprise that some internet web site looks unstable. It is not only happens on a single web site.…
-
We may ignore the vulnerabilities that happened in the past! Jun 2019
Preface: The virtual table is created in the same SQLite database in wich the Core Data content resides. To keep this table as light as possible only object properties relevant to the search query are inserted. Vulnerability details: A vulnerability in the rtreenode() function of SQLite3 could allow an unauthenticated, remote attacker to access sensitive…
-
CVE-2019-10981 AVEVA Security Advisory LFSEC00000136 (May 2019)
Preface: In the Ukraine hack, the utilities not only lost their visibility but also ceded control of their networks to remote attackers later linked to APT Group (Dec 2015). About AVEVA : AVEVA Group plc is a British multinational information technology company headquartered in Cambridge, United Kingdom. It provides engineering and industrial software. Schneider Electric…
-
Microsoft Windows RDP Network Level Authentication can bypass the Windows lock screen – Jun 2019
Vulnerability Note VU#576688 Original Release Date: 2019-06-04 | Last Revised: 2019-06-04 Preface: The more the power you have, the greater the risk is being infected. Synopsis: Microsoft Windows RDP Network Level Authentication can allow an attacker to bypass the lock screen on remote sessions. My observation: Observing that Microsoft re-engineering the RDP with create a…
-
CVE-2019-12439 Project Atomic Bubblewrap bubblewrap.c Arbitrary Code Execution Vulnerability – MAy 2019
Preface: With sandbox technology, Security DevOps team might have easy to conduct test. Since the user can specify exactly what parts of the filesystem should be visible in the sandbox. Technical Background: The introduction of user namespaces in the Linux kernel has opened the doors to running containers as default user logins via e.g. ssh…
-
When the Chinese mythology Shan Hai Jing 《山海經》meets aliens.
Preface: In ancient China, there was not only ancient times. Before ancient times, there was a ancient era that we could difficult to explore. With regard to the myth book of China, because of the many legends and myths left. It let me tirelessly exploring. Background of the Shan Hai Jing: Shan Hai Jing《山海經》, Chinese…
-
CVE-2019-0188 Apache Camel XML External Entity Injection Vulnerability – May 2019
Preface: The computing market trending on open source development and thus its growth rapidly. Believe it or not, see how many Apache server running now. Apache Camel background: You can use MQ (message queues) to enable applications to communicate at different times and in many diverse computing environments. This is the famous vendor proprietary toys…
-
Previous vulnerabilities, today’s emergency alert – 1st June 2019
Preface: If the victim of cybersecurity is a defensive device? What you can do? Background: Leading players in the Global It Asset Management (Itam) Software Market Research Report are: HP, Cherwell Software, Oracle & Dell KACE . Vulnerability details: The Dell Kace K1000 Appliance contains multiple vulnerabilities, including a blind SQL injection vulnerability and a…
-
CVE-2019-5018 Sqlite3 Window Function Functionality Use-After-Free Vulnerability
Preface: Use-After-Free vulnerability similar animal ruminating. Background: SQLite3 is a compact free database you can use easily create and use a database. It has become very popular with smart phone developers. SQLite runs many different computer systems such as Apple OS X, Linux, and Windows. Even though Airbus, they are the SQLite3 user. Vulnerability details:…
-
CVE-2019-10132 – libvirt virtlockd-admin.socket & virtlogd-admin.socket systemd Privilege Escalation Vulnerability (May 2019)
Preface: Business computing architecture now go to virtualization world, perhaps it is hard to imagine in five year ago! Technical background: The libvirt library is used to interface with different virtualization technologies. It is accessible from C, Python, Perl, Java and more. Meanwhilethe libvirt project supports KVM, QEMU, Xen, Virtuozzo, VMWare ESX, LXC & BHyve.…