Author: admin

  • Remediation announcement – Cisco Video Surveillance Manager Appliance Default Password Vulnerability 21st Sep 2018

    Does it a design flaw or it is a ………..? While exploring her new home, a girl named Coraline discovers a secret door, behind which lies an alternate world that closely mirrors her own but,….. Remediation announcement – Cisco Video Surveillance Manager Appliance Default Password Vulnerability – 2018 September 21 (below url for reference) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180921-vsm…

  • SCADA environment staying alert – Security updates for the OPC UA stacks on 12th Sep 2018

    SCADA helps people automate our world. It includes water, wastewater, and storm water management,Oil and Gas,Electricity,Transit systems and traffic,Facilities,Agriculture and Manufacturing. OPC UA can be used for supervisory control, now eliminating the use of Windows-based intermediate systems to streamline the data transfer process from the field and control levels vertically to the management and enterprise…

  • BIND 9 flaw – krb5-subdomain and ms-subdomain update policy rules ineffective

      What is BIND 9? BIND is open source software that enables you to publish your Domain Name System (DNS) information on the Internet, and to resolve DNS queries for your users. On 2006, named.conf parser design limitation found by Anonymous Monk. He list out the following. BIND::Conf_Parser – doesn’t deal with 9.x BIND::Config::Parser –…

  • Don’t underestimate – Adobe release security update – Sep 2018

    Adobe has released security updates to address vulnerabilities in Adobe Acrobat and Reader. Electronic document transform to an attacking tools are worry in cyber security world so far. The fact is that it is hard to detect such indirect attack. The simple we will know it is easy to evade the defense machanism. A malicious…

  • Vulnerability in SIMATIC WinCC OA V3.14 and prior – Sep 2018

    SIMATIC WinCC Open Architecture enables handling with bigger amounts of data with even smaller hardware solutions. However WinCC OA v3.14 found critical vulnerability. Do you think below detail is the root causes? A remote attackers execute arbitrary code or cause a denial of service (invalid pointer write) via a crafted packet to TCP port 5678.…

  • Quick review of OpenSC vulnerabilities – Sep 2018

    Basic Understanding: What is smart card? A smart card is a security token that has an embedded chip. Smart cards are typically the same size as a driver’s license and can be made out of metal or plastic Basicaly you can get smart card in two states: either blank or initialized. For blank cards OpenSC…

  • About Apple security update – released September 17, 2018

    We are free to download apps in Google Play Store and App Store. And we believe the Apps are secure without any problem. Apple has removed “Adware Doctor” from the macOS App Store and claims that the program was uploading browser histories. As far as we know, our browse history collect by 3rd party is…

  • The fundamental of data sharing versus data privacy

    Preface: What is “Fair Information Practices,” the principles of privacy protection are internationally recognized and are found in most privacy legislation around the world. These principles inform the way private organizations collect, secure, use and disclose personal information. What is the bottleneck of data sharing? Privacy is about respecting individuals. If a person has a…

  • It is a hurricane, but it happen in cyber world – Multiple vulnerabilities in PHP (Sep 2018)

    The United States and Asia were hit by hurricanes. It looks that the similar situation is happen in cyber world. MS-ISAC Releases Advisory on PHP Vulnerabilities urge technology world to staying alert. For more details, please refer below hyperlink: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-101/ Hacker exploit the PHP design weakenss (Arbitrary Code Execution or RCE) for attack must fulfill…

  • Sep 2018 – Veeam MongoDB left unsecured, 440 million records exposed

    Sanitization process is important in IT world. If without correct validation, it may allow malicious code pass to trust boundary. As a result it may causes remote code execution, SQL injection, trigger Zero day attack, ….etc. So…… Headline News this week. Should you have interest, my picture can tell my speculation. https://www.scmagazine.com/home/news/veeam-mongodb-left-unsecured-440-million-records-exposed/ Vulnerability looks scary!…