Category: Application Development

  • Advantech WebAccess/SCADA – CVE-2018-5443 – CVE-2018-5445

    Preface: SCADA systems are the backbone of many modern industries, including: Energy, Food and beverage, Manufacturing, Oil and gas, Power, Recycling, Transportation, Water and waste water,….etc SCADA evolution: The first generation of SCADA system relies with mainframe computers. As time goes by, the evolutionary of SCADA build on top of open system foundation (Unix) in…

  • Say Goodbye to 2017 cyber incidents

    We are going to say goodbye to 2017. What is your expectation in the new year? Cyber World activities especially cyber attacks looks intensive this year. Perhaps we cannot imagine ransomware threat which contain powerful destruction power last decade.The crypto worm (WANNACRY) break the Cyber incident world records which suspended huge volume of workstations and…

  • Out of memory bounds implication – a never ending story

    Preface In cyber security world, we are in frequent heard a term privileges escalation. IT guy familiar buffer overflow causes privileges escalation vulnerability of Windows 2000 operating system. Seems buffer overflow issue not only happened in Microsoft product, even through you are using Linux. It will happen. As of today, Apple iPhone and Google Android…

  • Perspective of e-Wallet Vulnerability

    Preface: Java, NodeJS, Python, ObjC with Xcode and GO are the popular programming language for develop of e-wallet application. It looks that some of the programmer favor of Java language since it is a common programming language. New technology, but targeting approach by hacker remain unchanged Reporting of Cybersecurity Incidents – InfoSec Resources Jul 2017 –…

  • Layer 7 (application layer) – What is the information security key factors?

    Preface: We heard shocking news this year especially EQUIFAX breach. The hackers accessed up to 143 million customer account details earlier this year. Thereafter a data breach happened on July 29 and the details taken include names, social security numbers, drivers licences, and credit card numbers of around 200,000 people. Perhaps you could said that the…

  • I am a Microsoft OS. Just wonder why I was hacked even though I have protective system?

    Preface: A simple question was asked by kernel? Why I was hacked even though I have comprehensive protective system? Background: The windows Operating System development team fully understand relies on market anti virus might not protecting their core OS significantly. Since the computer user not only using Microsoft word processing application. They are allow the…

  • Common vulnerability on application – who’s the perpetrator – Part 1

    Preface We heard cyber security incident daily, seems like a habit forming or it will be happened daily. We wasn’t gutted ( Feeling sad and unhappy) since we have already become insensitive! Who’s the perpetrator? The design limitation not only found on hardware (BIOS), OS (system kernel , dynamic link library and software driver). Besides,…

  • The other side of the story on cyber attack (Electronic war between countries)

    Preface We heard  that the new age transformation is coming.  As a result it transform the traditional military weapons to electronic codes. The computer  technologies such as DDOS (Distributed denial of services), malware and virus similar a killer. It can disrupt the financial activities,  daily network communication and health care services. An idea bring to…

  • Who spying on me? Da Vinci or Archimedes?

    Preface: Archimedes’ principle is a law of physics fundamental to fluid mechanics. Leonardo Da vinci  is widely considered one of the most diversely talented individuals ever to have lived. Since they are the famous scientists. They dedicate their inventions to the world. But we known the infamous tools in cyber world for the government surveillance program. The most famous eavesdropping feature…

  • Conduct self assessment enhance your cyber security setup

    Preface: Although your in house IT setup has SIEM, IDS, IPS, ..etc. But you may have questions? What is the defense criteria. Yes, we fully understand that install full scope of defense mechanism might mitigate the risk, right? Implement the IT strategic outsourcing.  Enforce the follow the Sun policy. Deploy the management security service.  But…