-
About GriftHorse Malware (30th Sep 2021)
Preface: Large portion of smartphone will not installed antivirus software. Even though it is installed. The antivirus vendor similar doing racing campaign with cyber criminals. Nowadays, vendor established malware sinkhole to find zero day vulnerability and existing cyber attack. If cyber criminals relies on software design limitation hiding itself on phone. Perhaps sinkhole not easy…
-
Stealth attack of UEFI bootkit (29th Sep 2021)
Preface: Digital spyware and monitoring tech that allows the user to covertly monitor a target’s communications, or collect personal data emitted from their devices. Background: FinFisher, also known as FinSpy, is surveillance software marketed by Lench IT Solutions plc, which markets the spyware through law enforcement channels. On August 6, 2014, FinFisher source code, pricing,…
-
About CVE-2021-20034 – (SMA 100 series) Unauthenticated SMA100 arbitrary file delete vulnerability – 27th Sep 2021
Point of view: More than 20 years ago, the firewall function was independent, excluding the firewall policy service and vpn function.The advantage is that when the firewall box is compromised. Nothing else will be found in the box by the attacker.Over time, the trend of unified threat management has grown. From a technical point of…
-
About BTCPayment server – CVE-2021-3830 (26th Sep, 2021)
Preface: Cryptocurrency look like myth. Someone avoid to use. But somebody like it. If Cryptocurrency only provide payment function. That is no investment value. Furthermore if someone going to transfer money will be know who is sender and recipient. If it come true, what is the result? Background: BTCPay Server is an open source, P2P…
-
Does SpaceX use C language? 23rd Sep, 2021
Preface: SpaceX was founded in 2002 by Elon Musk with the goal of reducing space transportation costs to enable the colonization of Mars. Background: Exploring Mars helps scientists understand major changes in climate that can fundamentally change the planet. It also allows us to look for biological features that might reveal whether there was abundant…
-
It is not mystery. The findings address that an original function for CEIP feature is able to misuse (CVE-2021-22005) – 22nd Sep, 2021
Preface: Rapid7 Labs estimates there are over 2,700 vulnerable vCenter servers exposed to the public internet. Background: As of May 1 2020, the Pivotal Telemetry program is governed by VMware’s Customer Experience Improvement Program.Data and continuous feedback loops play an important role in shaping the way Pivotal builds software. VMware analytics service consists of components…
-
Closer look – CVE-2021-25751 (21-09-2021)
Preface: As we know that Kubernetes (K8s) is a container orchestration tool and Docker helps to create a container that is managed by us using Kubernetes. Background: What is subPath in volume mount?Subpath references files or directories that are controlled by the user, not the system. Volumes can be shared by containers that are brought…
-
Security Focus on Microsoft windows CMD Stack Buffer Overflow (19-09-2021)
Preface: Twenty years ago, content filter firewalls were not popular. A quick way to harden the Microsoft Internet Information server is to delete all cmd commands to avoid network attacks. Background: If you would like to run cmd in privileged mode. You have to do the following: type “CMD” you can hit Ctrl+Shift+Enter to open…
-
CVE-2021-22941 – May be it is not related, or else was getting the User Enumeration incident waiting to happen (17-09-2021)
Preface: With storage zones controllers, the ShareFile Software-as-a-Service (SaaS) cloud storage also offers private storage for ShareFile data, which is known as storage zones. What is the difference between Dropbox and ShareFile?The goal of ShareFile is to help your team easily share, sync and store large files from any device without compromising important data. And…
-
IS there any related security matter of session (CVE-2021-37535)?
Preface: Did you check your JMS Security Authorization, fix your JMS application immediately. Background: The basic building blocks of a JMS application are: Administered objects: connection factories and destinations Connections Sessions Message producers Message consumers Messages The JMS Connector Service is an enterprise messaging system that provides a way for business applications to exchange datawithout…