-
tomcat ajp (cve-2020-1938) – vendor patched immediately. problem resolved. Feb 2020
Preface: What is the best way for web server and the servlet container do a communications? Technical details: The ajp13 protocol is packet-oriented. A binary format was presumably chosen over the more readable plain text for reasons of performance. It communication between the web server and the servlet container. Vulnerability details: The vulnerability impact the…
-
OpenSMTPD (CVE-2020-7247) – How did it happen? 24th Feb 2020
Preface: OPENSMTPD – plagued by numerous vulnerabilities. Most recently – CVE-2020-8794 Details: Qualys has found another critical vulnerability in OpenSMTPD.In normal circumstance, the adjacent side connects to the SMTP server and sends commands such as EHLO, MAIL FROM, RCPT TO. The SMTP server responds with a single or multiple lines of response: The client-side exploitation…
-
A retrospective album of BlackEnergy – Feb 2020
Somewhere in time. This is 2015 – BlackEnergy2 exists in the form of a kernel-mode driver, which makes it harder for network administrators to discover the compromise. Black energy Group will mimics their custom tool(driver) thus made to look like a normal Windows component. They are interested in infecting Windows servers especially OPC server. But…
-
Staying alert of Emotet infection, even though you are a Mac User. Feb 2020
Preface: Apple Mac OS as not as easy to compromised compare with other popular operation system. Details (A): Emotet is malware originally engineered as a banking Trojan designed to steal sensitive information. It is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. But…
-
Vulnerabilities in VMware (RMI communication in vRealize Operations for Horizon) are also apply for those vendor who is using RMI in Java environment. (20th Feb 2020)
Preface: JMX is often described as the “Java version” of SNMP (Simple Network Management Protocol). Synopsis: A vulnerability in the Java Management Extensions (JMX) management agent included in the Java Runtime Environment (JRE) may allow a JMX client running on a remote host to perform unauthorized operations on a system running JMX with local monitoring…
-
APT Group attack major focus: time window before release and patched (19th Feb 2020)
Preface: In normal circumstance, the remediation of vulnerabilities is time consumption. Even though Software-based vulnerabilities policy allow up to 90 days for the vendor to provide a patch. Background: It looks that existing period of time can be happen plenty of matters. So far APT Group have talented and knowledge to discover the defect of…
-
Hacker exploit Coronavirus Crisis, send scam email to different industries – 18th Feb 2020
Synopsis: a. Attackers disguise their scam email as an official (WHO) alert issued by the Centers for Disease Control Health Alert Network. (Targeting individuals from the United States and the United Kingdom) b. Attackers disguise their scam email as an alert of Coronavirus status, they are target to shipping industry. Description: About the attack to…
-
Hong Kong Broadband Network customer staying alert! 17th Feb 2020
Synopsis: The threat actors hidden their email phishing package anywhere. As common we know, email phishing scam foot print are wide in area. But the antivirus and malware solution vendor setup blacklist domain name and content filtering function has reduced the infection ratio of malware and ransomware. It looks that the similar of idea to…
-
FIFO project problem tracker – SEND_FILE_WITH_HEADER Use-After-Free (Feb 2020)
Preface: The security of FIDO deployment largely depends on the choice of underlying security subsystems and their implementation. Background: An ioctl , which means “input-output control” is a kind of device-specific system call. There are only a few system calls in Linux (300-400), which are not enough to express all the unique functions devices may…
-
Perhaps you don’t use Internet Explorer, you could still be at risk. Conduct patch install on IE today – 12th Feb 2020
Preface: If you try to open an .MHT file on a computer including Windows 10, or Windows Server 2012 R2 then it will attempt to load the file using Internet Explorer eventhough of the default browser in place! Security Focus: Microsoft released an emergency security update on Monday (February 10, 2020) to fix a vulnerability…