Author: admin

  • Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability

    Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability (below url for reference) severity level – critical https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1 We heard denial of service vulnerability to UTM firewall device in frequent. It looks that there is no any strange or feeling surprise. However similar XML Exploit method not new, it announced in RSA…

  • Doubt – $530 million cryptocurrency heist

    As we know the most common cryptocurrencies are Bitcoin, Ethereum,Ethereum Classic, Monero, Litecoin, OmiseGO, Ripple & Zcash. Fundamentally NEM Smart Asset System more secure than bitcoin. The NEM Blockchain utilizes a Proof-of-Importance calculation (rather than Bitcoin’s Proof-of-Work or PIVX’s Proof-of-Stake) to accomplish accord through a procedure that boosts dynamic support in the system. NEM is…

  • My speculation – How’s coincheck loses ¥58 billion dollars value of cryptocurrency

    Incident background: Japan-based company said hackers broke in at 02:57am local time on Friday (12:57pm EST on Thursday, 25 January). Financial lost: ¥58 billion dollars value of cryptocurrency Cryptocurrency type: NEM (XEM) Victim: coincheck.com Cyber attack historical incident record The most recent cryptocurrency heist happened on February 2014. The victim firm is Mt. Gox. A…

  • Data Privacy Day 2018 Livestream on 28th Jan 2018

    In last hundred years, the record of information includes storage of information without big changes. A revolution appears enforce computer technology jump to another generation computer world with big data and digitization technology. Cyber attack wreak havoc recently. In order to avoid any mistake given by antivirus program. The antivirus vendor enforce their defensive technique.…

  • cpp-ethereum vulnerabilities do not ignore!

    Preface: The cyber attack wreak havoc today. Perhaps system applications and operation system hard to avoid vulnerability occurs because of short development cycle. Crypto currency might change the financial world. However there are more and more topics are under development. Technology background Ethereum is an open software platform based on blockchain technology that enables developers…

  • CVE-2018-0486 Staying alert with your single sign-on application especially IDP vulnerability

    CVE-2018-0486: Shibboleth(SAML IDP) open source vulnerability is currently awaiting analysis. For more details, see below url for reference: https://nvd.nist.gov/vuln/detail/CVE-2018-0486 During my penetration test engagement in past. I was surprised that no matter airline , financial and retail industries web online application solutions are deployed open source single-sign on resources. An incident occurred in Equifax which…

  • Apple enforce Meltdown and Spectre vulnerabilities remediation

    About Apple security updates announcement (see below url for reference) https://support.apple.com/en-us/HT208463 About security updates announcement, the objectives is going remediate multiple vulnerabilities.As usual, apple released security update but no descriptions are available yet. Perhaps without detail information provided by vendor (Apple). However I  was speculated  that the remediation step will be focus on the following protection…

  • Lawful interception – How’s your personal privacy value today?

    Cloud computer platform looks like a fight carrier in the data world. Meanwhile, the data stored inside the cloud are under cloud protection. However different country implement different data protection law and data custodian policy. Perhaps development countries unaware this topics last decade. However big data upgrade his political position progressively. It looks that government…

  • Smart City & IoT -Mandatory 3 principles for working with Big data

    We frequently heard smartcity project and usage of big data. Such key terms for the 1st impression to people is that it is a advanced technique and techology trend in future. In fact it was not possible to say we are keen to enjoy the benefits of smart city and big data analytic but we…

  • Staying alert with CSRF and XSS vulnerabilities

    Perhaps there are a lot of vulnerabilities sometimes will be ignored. Why? For instance cross-site scripting will be occurred on client or server side. If there is a cross-site scripting (XSS) vulnerability in the web application, it is not possible to prevent CSRF (cross site request forgery) since the cross site scripting will allow the…