-
A flaw was found in xorg-x11-server – Oct 2018
A flaw was found in xorg-x11-server. X.Org Server is the free and open-source implementation of the display server for the X Window System. It is very common in computing environment. But IT administrator must stay alert whether your have Linux Desktop install on top of your VM infrastructure. Since a flaw was found in xorg-x11-server…
-
Advantech WebAccess remain vulnerable (8.3.1 & 8.3.2) – Oct 2018
Advantech WebAccess remain vulnerable (8.3.1 & 8.3.2) When vulnerability allows an attacker to execute “arbitrary code”, it typically means that the hacker can run any command. Although critical facilities especially Petroleum, electricity, Gas and water SCADA infrastructure are prohibited setup internet access function. However to cope with modernization. It is hard to avoid to do…
-
Off-color humor – Cathay Pacific hack (9.4 million airline passengers data stolen by data thief)
Asia world seems feel shot of the Cathay Pacific Airline cyber security incident. To be honest, it is hard to avoid computer vulnerabilities occurs in business circumstances today. Why? It is a demanding environment includes comprehensive competition. Business man try a way to find out the cost efficiency solution. Meanwhile, it unintended to push a…
-
Cathay Pacific hack: Personal data of up to 9.4 million airline passengers stolen.
From public safety point of view, if a enterprise firm found 9.4 million personal records steal by hacker. Since the firm postpone the announcement schedule. From technical point of view. the law enforcement must require to interview with the firm top management to understand the root cause. Regarding to my observation, the cyber security incident…
-
Cisco Webex Productivity Tools and the Cisco Webex Meetings Desktop App Releases Security Updates – October 24, 2018
Cisco Webex Productivity Tools and the Cisco Webex Meetings Desktop App Releases Security Updates – October 24, 2018 Due to design weakness of ACL, WebExService that can execute arbitrary commands at SYSTEM-level privilege. Below remedy only reset the service to the default permission. sc sdset webexservice D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPLORC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) But you should update your Cisco Webex Meetings…
-
Security Alert! Moxa ThingsPro IIoT Gateway and Device Management Software (Oct 2018)
Security Alert – Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. MQTT (formerly MQ Telemetry Transport) is an ISO standard (ISO/IEC PRF 20922) publish-subscribe-based “lightweight” messaging protocol for use on top of the TCP/IP protocol. Since the original design objective of this protocol not for handling confidential information and therefore cyber security…
-
What is a smart city from an security point of view?
Preface The objective of the smart city is design to incorporates information and communication technologies (ICT) to enhance the quality of life. The Smart City derivatives the cost effective solution. As a result, it benefits to urban services such as energy, transportation and utilities in order to reduce resource consumption, wastage and overall costs.…
-
Security Advisories and Alerts – LAquis SCADA Versions 4.1.0.3870 and prior
Since it build and run on top of Microsoft windows platform and speculated that vulnerabilities might given from Microsoft itself. For instance: LAquis SCADA Versions 4.1.0.3870 and prior Integer overflow to buffer overflow vulnerabilities, which may allow remote code execution. Hints: Microsoft GDI+ is prone to an integer-overflow vulnerability. An attacker can exploit this issue…
-
LIVE555 Streaming Library vulnerability – Oct 2018
The VLC is a packet-based media player it plays almost all video content. It can play some, even if they’re damaged, incomplete, or unfinished, such as files that are still downloading via a peer-to-peer (P2P) network. So it is very popular in the IoT Environments especially video streaming in vehicular IoT (VSV-IoT) environments. However…
-
Libssh Server-Side State Machine Unauthorized Access Vulnerability – 17thOct2018
Background: Libssh is a library written in C implementing the SSH protocol. It can be used to implement client and server applications. Vulnerability found on 17th Oct 2018: By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate without…