Author: admin

  • VMware Releases Security Updates – especially cloud base users must staying alert! 12th Apr 2018

    In java world, it has plenty of areas are allow hacker to do some tricks. VMware announced that found so called DOM Based Cross-site Scripting Vulnerability and Missing renewal of session tokens vulnerability. In regards to my comment, both vulnerabilities similar modern java applications security weakness, we are able to apply filter to do that.…

  • Juniper JunOS – The giant is sick! April 2018

    Kernel crash upon receipt of crafted CLNP packets (CVE-2018-0016) https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10844&cat=SIRT_1&actp=LIST Denial-of-service vulnerability in flowd daemon on devices configured with NAT-PT (CVE-2018-0017) https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10845&cat=SIRT_1&actp=LIST Crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies (CVE-2018-0018) https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10846&cat=SIRT_1&actp=LIST Denial-of-service vulnerability in SNMP MIB-II subagent daemon (mib2d) (CVE-2018-0019) https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10847&cat=SIRT_1&actp=LIST rpd daemon cores due to…

  • Why REST (API) is so popular? But how to hardening the API security features?

    REST (API) is key component to building powerful, scalable web-based applications today. So how to enhance the security feature, since it is working with HTTP communication method. Thence: 1. We should ensure that the HTTP method is valid for the API key/session token and linked collection of resources, record, and action. 2. Authentication – It is better to…

  • Microsoft security update – April 10, 2018 – KB4093112

    The security update of Microsoft this week included provides support to control usage of Indirect Branch Prediction Barrier (IBPB) within some AMD processors (CPUs) for mitigating CVE-2017-5715. Apart from that it also provides Windows Client Guidance for IT Pros to protect against speculative execution side-channel vulnerabilities. However I was wondering the mitigation plan coverage provided…

  • Allen Bradley – The design flaw of the programmable logic controller – system vulnerability

    Traditional layer 2 communication system (without TCP/IP), proprietary OS system and without internet technology similar as a antibody protect the important facilities especially electricity power supply, water supply and natural gas facilities. But the element of civilization like a non stop vehicles moving forward. Whereby the man kind went through industrial revolution till today digital technology…

  • Adobe Security Bulletin – PhoneGap Push plugin vulnerability and the other

    Coin has two sides, the computer has vulnerabilities on the other hand show benefits. Why, it provides a influence effect causes people found out resolution.And such a way go to advanced technology zone. Security announcement by Adobe urge adobe users following the requirement apply the fix. Since there are total 5 items of security update.…

  • US-CERT Ransomware Guidance – 2018

    An article issued by US-CERT with subject. Protecting Your Networks from Ransomware. Their aim is going to provide a guidance to fight against ransomware. Before you read the articles. There are few slogans are able to enhance your data protection framework. For instance: 1. Ransomware and Phishing Work Together 2. For whom who visiting online…

  • Cisco IOS XE Software CLI command injection vulnerabilities CVE-2018-0193

    The design objective of the Command Line Parser is used to parse the command line arguments. The parser parsing a string and returns an object representing the values extracted. This is the the regular expression design objective. The Cisco IOS XE is a train of Cisco Systems’ widely deployed Internetworking Operating System (IOS), introduced with the…

  • Bank ATM Framework QUICK TOUR

    Believe that ATM scammer or criminal activities will be signigicant dropped after ATM thief are under sentence. It looks that I am overlook the attraction of bank note since a new jackpotting malware is under development. I surprise to me that the malware originate country is in Hong Kong. We known that bank of China…

  • A quick way to do the remediation (CVE-2018-0171(smart install vulnerability))

    Headline news posted by Reuters report that Iran hit by global cyber attack that left U.S. flag on screens. As we know, this vulnerability will be conducted the following: Triggering a reload of the device. Allowing the attacker to execute arbitrary code on the device. Causing an indefinite loop on the affected device that triggers…