Author: admin

  • Mar 2018 – A remote attacker could exploit some of these vulnerabilities to take control of an affected Cisco system.

    The IT technology vulnerability like cough, running nose,..etc. Medicine please. Cisco Prime Collaboration Provisioning Hard-Coded Password Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-cpcp Cisco Secure Access Control System Java Deserialization Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-acs2 Cisco Web Security Appliance FTP Authentication Bypass Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-wsa Reminder: Cisco Secure Access Control System NOTE: This product is no longer being sold and might not be supported.…

  • Google has released Chrome version 65.0.3325.146 – use-after-free vulnerability remediation

    To be honest, web browser architecture looks messy due to plug-in, Flash,etc. Google has released Chrome version 65.0.3325.146 for Windows, Mac, and Linux. This version addresses vulnerabilities that an attacker could exploit to obtain access to sensitive information. A design flaw looks strange. I speculate that Chrome browser shared previous Flash vulnerability.A memory write is…

  • Authentication Bypass Vulnerability in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway – CVE-2018-5314

    A Cantonese mantra so called “蝦碌”. “蝦碌” means similar exclamation. Citrix product now falling into this situation. It allow remote attackers to execute a system command or read arbitrary files via SSH login prompt. From technical point of view it is similar Authentication Bypass Vulnerability. In short, the official announcement shown below url: https://support.citrix.com/article/CTX232199

  • Undetected malware on android

    Preface: Till 2018-02-01, the official announcement provides the following details. Security patch level—Vulnerability details Start discussion: ART (Android RunTime) is the next version of Dalvik. Unlike Dalvik, ART introduces the use of ahead-of-time (AOT) compilation by compiling entire applications into native machine code upon their installation. Regarding to Android security bulletin on February 2018, the official announcement did not…

  • Volkswagen Customer-Link App 1.30 CAN Message privilege escalation

    Auto Pilot system has been implemented in many countries. Perhaps Auto Pilot function enabled become a hot topic. You are allow to install mobile apps on your Android phone keep track the status of your car. We are really appreciate for Controller Area Network (CAN bus) technology assistance. The vulnerability found on car automation not…

  • A never ending of Intel CPU design hiccups story – SgxPectre Attack

    The design limitation of Intel Software Guard eXtensions (SGX) start discussion end of 2017. The security expertise focusing the topic on software development for SDK. Since the programming language are mainly written by programming language C and C++. A possibility factor predict that it will be lured for threat actors interest. And therefore a conference…

  • ISC Releases Security Advisories for DHCP, BIND

    US-CERT encourages users and administrators to review ISC Knowledge Base Article. https://kb.isc.org/article/AA-01565/75/CVE-2018-5732 https://kb.isc.org/article/AA-01562/74/CVE-2018-5734 Perhaps it is out of end user control! What is ISC(Internet Systems Consortium)? F Root System (ISC) – Enables users around the world to find top-level domains such as .com, .uk, .edu; Reliable anycast network with over 125 nodes; Hosted in local…

  • Microsoft working with Intel to deliver CPU Microcode Fixes via Windows Updates

    Cyber computer world news similar Hollywood celebrity scandal. It can’t maintain longer and easy to forget. Intel learned by experience. Thus invite Microsoft for assistance. About CPU platforms around Spectre Variant 2 (CVE 2017-5715 (“Branch Target Injection”)). I speculate that a technical problem occurs by Intel patch program last time cause by the following issue.…

  • Application security awareness – Before Html5 full cover up, we must stay alert of Html4

    Preface: The bitcoin mining malware, cyber espionage program and malicious malware merely relies on iframe. Where are they from? Understanding Frame: The main advantage of frames is that it allows the user to view multiple documents within a single Web page. It is possible to load pages from different servers in a single frameset. iframe:…

  • When will the dream comes true – Retail business operate cryptocurrency as a exchange

    Former Chairman of the Communist Party of China (Mao) said that sailed on the sea must relies on helmsman(大海航行靠舵手). The statement looks true. The drinking coffee trend found by STARBUCKS. The STARBUCKS, a founder and leading the coffee market. The founder has business sense to dig out the potential business pipeline in the market. Schultz’s…