-
VMware Releases Security Updates Published Friday, April 12, 2019
Preface: A quick walk through on your VMware setup, see whether 3D acceleration feature is enabled. It is recommended to disabling the 3D-acceleration feature to protect your IT environment. Vulnerability Details: CVE-2019-5514 – Vulnerability due to certain unauthenticated APIs accessible through a web socket CVE-2019-5515 – Out-of-bounds write vulnerability in the e1000 and e1000e virtual…
-
Who is cookie? Is it cookie monster? Multiple VPN applications insecurely store session cookies – 11th Apr 2019
Preface: Who is cookie? Is it cookie monster? Multiple VPN applications insecurely store session cookies – 11th Apr 2019 Technical background: An HTTP cookie (web cookie, browser cookie) is a small piece of data that a server sends to the user’s web browser. The browser may store it and send it back with the next…
-
Hardcoded credentials concerns – MyCar mobile apps (8th Apr 2019)
Preface: MyCar add smartphone-controlled geolocation, remote start/stop and lock/unlock capabilities to a vehicle with a compatible remote start unit. Vulnerability details: MyCar Controls mobile applications prior to v3.4.24 on iOS and prior to v4.1.2 on Android contains hard-coded admin credentials. For specifics details, please refer to diagram. Reference:https://kb.cert.org/vuls/id/174715/
-
Samba Releases Security Updates (CVE-2019-3880 & CVE-2019-3870) – Apr 2019
Preface: Samba is an open-source software suite that runs on Unix/Linux based platforms. The design based on SMB network protocol. Samba is able to communicate with Windows clients like a native application. Synopsis: Windows OS and Linux opensource looks contains their market. A trend shown that Linux base OS well develop in automation industry. Perhaps…
-
Siemens – CVE-2019-6569 (Do not contempt this vulnerability)
Preface: Industrial Ethernet has been the network of choice in factory auto-mation for many years and offers a powerful communication basis with PROFINET-based solutions. Vulnerability details: A vulnerability has been identified in Scalance X-200 (All versions), Scalance X-300 (All versions), Scalance XP/XC/XF-200 (All versions <V4.1). The monitor barrier of the affected products insufficiently blocks data…
-
CVE-2019-1002101: kubectl fix potential directory traversal (4th Apr 2019)
Preface: The vulnerability if not require attacker conduct scam to persuade a user. It is a extreme dangerous vulnerability. Technical background of Kubernetes: Kubernetes (often referred to as K8s) is an open source system for automatically deploying, extending, and managing containerized applications. The system was designed by Google and donated to the Cloud Native Computing…
-
Apache Releases Security Update for Apache HTTP Server – 4th April 2019
Alert: The Apache Software Foundation has released Apache HTTP Server version 2.4.39 to address multiple vulnerabilities. mod_auth_digest access control bypass (CVE-2019-0217) mod_ssl access control bypass (CVE-2019-0215) mod_http2, possible crash on late upgrade (CVE-2019-0197) CVE-2019-0211 bring to my attention. For the synopsis of this matter, please refer to attached diagram. Remedy: The Apache Software Foundation has…
-
Client negligence (misconfiguration), AWS reputation suffer! 3rd Apr 2019
Preface: 540 Million Facebook Records Leaked Who bare the responsibility? Misconfiguration Headline News: Hundreds of millions of Facebook records exposed on Amazon S3 cloud! See the link below for details: https://www.forbes.com/sites/kateoflahertyuk/2019/04/03/facebook-exposes-540-million-user-records-what-you-need-to-know/#35a8f7043fd7 Observation: The incident shown that it is not difficult to keep track our web activities. A webhook (HTTP push API) is a way for…
-
CVE-2018-19466 – Portainer LDAP Credentials Storage Information Disclosure Vulnerability (3rd Apr 2019)
Preface: Today, the stored password is not encrypted like walking around without clothes! Technical background: Portainer is a lightweight management UI which allows you to easily manage your different Docker environments (Docker hosts or Swarm clusters). It allows you to manage your all your Docker resources (containers, images, volumes, networks and more) ! It is…
-
CVE-2019-5729 – Splunk Python SDK Improper TLS Server Certificate Verification Vulnerability(2nd Apr 2019)
Preface: Splunk is powerful, it can extract cookie of web connections. If client connection still alive, hacker can hijack and get the connection. Vulnerability details: A vulnerability in Splunk Python SDK could allow an unauthenticated, remote attacker to bypass security restrictions on a targeted system. An attacker could exploit this vulnerability by executing a man-in-the-middle…