-
June 2018 – Google Releases Security Update for Chrome
Content Security Policy (CSP) provides a standard HTTP header that allows website owners to declare approved sources of content that browsers should be allowed to load on that page. Browser based XXS protection mechanism. Least privilege approach that whitelists content you trust. Nothing else will execute. Assumes that inline scripts are bad. But…………. High CVE-2018-6148:…
-
May 2018 – Moodle security announcements
LMS (Learning Management System) become popular because it wasn’t limit learning area and time zone. Learner or student can start the tution when computer connect to internet. Such learning atomosphere are popular in the world. LMS not restricted to high school and university educations. It also covered internal training in business environment. Moodle is a…
-
June 06, 2018 – Cisco Releases Security Updates for Multiple Products
CVE-2018-0321 – Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-rmi CVE-2018-0315 – Cisco IOS XE Software Authentication, Authorization, and Accounting Login Authentication Remote Code Execution Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-aaa CVE-2018-0353 – Cisco Web Security Appliance Layer 4 Traffic Monitor Security Bypass Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-wsa CVE-2018-0320 – Cisco Prime Collaboration Provisioning SQL Injection Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-sql CVE-2018-0318 –…
-
The influence of CVE-2018-11235 more than expected. Even the Hyperledger project is included.
Git community disclosed a high serverity of vulnerabilies (CVE-2018-11235). Since the impact of this vulnerabilities might influence many software application. The major design weakness of this vulnerability is that when you git clone a repository, there is some important configuration that you don’t get from the server includes .git/config file, and things like hooks, which…
-
4th June 2018 – SAML Authentication Bypass ((Symantec) CVE-2018-5241)
SAML for single sign-on (SSO) makes it possible for your users to authenticate through your company’s identity provider when they log in to Cloud computing platform. SSO allows a user to authenticate once and then access multiple products during their session, without needing to authenticate with each of those. Please be remind that SSO will…
-
Hyperledger Iroha v1.0 beta-2 version to remediate CVE-2018-3756 (May 2018)
The earlier generation of blockchain technology empower encryption power let the world know his capability. As times goes by people found the design weakness of blockchain technology is the performance of synchoization of the peer nodes. Such design weakness cause double spending vulnerability. The next generation of technology so called HYPERLEDGER. It enhance the design…
-
Dark power (malware) jeopardize the open geospatial data
Preface The geospatial digital environment supports planning, management, modeling, simulation and visualization related to smart initiatives across the city. Quick understanding – Basic data structure for GIS Vector Raster Tringulate irregular network 4. Tabular data (attribute table) You use Global Positioning System (GPS) on your smartphone for directions to a particular place, or if you…
-
1st June 2018 – Visa Card Payment Systems Go Down Across Europe
Visa Card Payment Systems Go Down Across Europe Visa Card Payment Systems Go Down Across Europe on 1st June 2018. The Visa payment service resumed on 2nd June 2018. Visa announced that systems now operating at ‘full capacity’ after crash cripples payments (See below url for reference) https://finance.yahoo.com/quote/V180608P00095000?p=V180608P00095000 The service interruption because of hardware failure,…
-
A vulnerability found in becton dickinson DB Manager (CVE-2018-10593 and CVE-2018-10595)
On May 2017, Ransomware attack suspended UK healthcare system services. It shown the security weakness in hospital and clinic IT system infrastructure. BD is a global medical technology company that is advancing the world of health by improving medical discovery, diagnostics and the delivery of care. A vulnerabilitiy found on Becton Dickinson causes a series…
-
22nd May 2018: Security Advisory – Privilege escalation vulnerability found in some Dahua IP products
Based in Hangzhou, China, Dahua Technology is one of the world’s leading manufacturers of security and video surveillance equipment. According to its unaudited results for 2017, it had a turnover of $2.89bn representing a year-on-year increase of 41%, and a gross profit of $404m, growing by 31%.Based on above details, you can imagine that how…