Author: admin

  • Linux (systemd) current status update – 7th Nov 2018

    Linux (systemd) current status update – 7th Nov 2018 If you are the old folk. Perhaps you will familiar with (init)? The trend is going to replace the old mechanism (init) with new one (systemd). From techincal point of view, people satisfy the techincal features of “systemd”. However they are concern that such design are…

  • 5th Nov 2018 – Apache Releases Security Advisory for Apache Struts. Is there any concern by Cisco?

    US-CERT urge that stay alert for the former Apache Struts design weakness (CVE-2016-1000031 – Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution) See whether does it effect cisco products? Since this vulnerability just happened yesterday. And therefore no response from Vendor (Cisco) in the moment. For details about this vulnerability. Please refer below URL…

  • Schneider Electric Security Notification – Nov 2018

    A reminder to Schneider customer – official security alert! Preface: DLL file is in SysWOW64 folder and someone places a counterfeit dll in a folder that has higher priority compared to SysWOW64 folder, the operating system will use the counterfeit dll file, as it has the same name as the DLL requested by the application.…

  • CVE-2018-5407: new side-channel vulnerability on SMT/Hyper-Threading architectures (Fri, 2 Nov 2018)

    CVE-2018-5407: new side-channel vulnerability on SMT/Hyper-Threading architectures (Fri, 2 Nov 2018) Spectre is a vulnerability that affects modern microprocessors that perform branch prediction. On most processors, the speculative execution resulting from a branch misprediction may leave observable side effects that may reveal private data to attackers. As predicted, there are more and more branch prediction…

  • Texas Instrument Microcontrollers (CC2640 and CC2650) vulnerability made vendor headache! (Nov 2018)

    As time goes by, we seen the cyber security coverage not limit to desktop, notebook and server. Even though WiFi chip set will be involved zero day vulnerability management cycle. Texas Instrument Microcontrollers expose that CC2640 and CC2650 has vulnerable to cyber attack. If the incoming data is over a certain length and continuous execution.…

  • libssh Authentication Bypass Vulnerability Affecting Cisco Products and additional critical item – 31st October 2018

    Background: Libssh is a library written in C implementing the SSH protocol. It can be used to implement client and server applications. Vulnerability found on 17th Oct 2018: The technical details are as follows, please refer to the URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181019-libssh In addition, another important vulnerability announced this week is for your consideration. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180502-prime-upload Reference: Libssh…

  • Cisco zero-day interfer ASA 9.4+ and FTD 6.0+ software operation – 31st Oct 2018

    Just read articles recommend of my friend. It reminded me that Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software encounter Denial of Service Vulnerability.This vulnerability recorded CVE-2018-15454. A design weakness resides in the Session Initiation Protocol (SIP) inspection engine of ASA and FTD software. The interim remedy solution shown as below: hostname(config)#…

  • Apache Releases Security Update for Apache Tomcat JK Connectors – 31st Oct 2018

    A reverse proxy is not totally transparent to the application on the backend. When the application on the backend returns content including self-referential URLs using its own backend address and port, the client will usually not be able to use these URLs. Deploy Apache Tomcat Connector (mod_jk) can easy to solve these technical problem. It…

  • Qualcomm Technologies Security Bulletin – October 2018

    Few years ago, when your friend ask you which is the best smartphone in the world. Seems it is easy to answer. Perhaps the zero day attack and malware wreak havoc today. So it is hard to answer those question in quick! We are now familiar with vulnerability terms especially stack-based buffer overflow, privilege escalation…

  • Apple Releases Multiple Security Updates – 30th Oct 2018

    Apple Releases Multiple Security Updates on product especially IOS 12.1. Are you going to update as soon as possible or observe for a moment then action? Can we say, we are now alive Insane technology world and suffer with vulnerability daily! Safari 12.0.1 https://support.apple.com/en-us/HT209196 iCloud for Windows 7.8 https://support.apple.com/en-us/HT209198 iTunes 12.9.1 https://support.apple.com/en-us/HT209197 watchOS 5.1 https://support.apple.com/en-us/HT209195…