= End-of-Shift report =
Timeframe: Donnerstag 06-04-2017 18:00 − Freitag 07-04-2017 18:00
Handler: Stephan Richter
Co-Handler: n/a
*** Ransomware Gang Made Over $100,000 by Exploiting Apache Struts Zero-Day ***
For more than a month, at least ten groups of attackers have been compromising systems running applications built with Apache Struts and installing backdoors, DDoS bots, cryptocurrency miners, or ransomware, depending if the machine is running Linux or Windows. [...]
*** Upcoming Security Updates for Adobe Acrobat and Reader (APSB17-11) ***
A prenotification Security Advisory (APSB17-11) has been posted regarding upcoming releases for Adobe Acrobat and Reader scheduled for Tuesday, April 11, 2017. We will continue to provide updates on the upcoming releases via the Security Advisory as well as the...
*** Tracking Website Defacers with HTTP Referers, (Fri, Apr 7th) ***
In a previous diary, I explained how pictures may affect your website reputation[1]. Although asuggestedrecommendation was to prevent cross-linking by using the HTTP referer, this is a control that I do not implement on my personal blog, purely for research purposes. And it successfully worked! My website and all its components are constantly monitored but Im also monitoring online services like pastebin.com to track references to...
*** Brickerbot: Hacker zerstören das Internet of Insecure Things ***
Unbekannte versuchen zurzeit, sich in ungesicherte IoT-Geräte zu hacken und diese aktiv zu zerstören. Offenbar ein Versuch, die Geräte unschädlich zu machen, bevor sie Teil von Botnetzen wie Mirai werden.
*** Global DDoS Threat Landscape: What's new? ***
The Current Global DDoS Threat Landscape In this post, we analyze the current Global DDoS threat landscape focusing on the economic aspect of this kind of criminal activity. The extortion crimes continue to represent a serious threat to businesses and organizations worldwide; ransomware infections and DDoS attacks are becoming daily problems. Security experts at Imperva...
*** QNAP NAS devices open to remote command execution ***
If you're using one of the many QNAP NAS devices and you haven't yet upgraded the QTS firmware to version 4.2.4, you should do so immediately if you don't want it to fall prey to attackers. Among the vulnerabilities fixed by QNAP in this latest firmware version, released on March 21, are three command injection flaws in the web user interface that can be exploited to gain remote command execution on a vulnerable device as...
*** ClearEnergy - The "In the Wild" SCADA Ransomware Attacks That Never Were ***
A mini-controversy broke out this week in the infosec community after cyber-security firm CRITIFENCE led journalists and other security experts to believe that theyve detected in-the-wild attacks with a new ransomware called ClearEnergy, specialized in targeting ICS/SCADA industrial equipment. [...]
*** Sathurbot: Distributed WordPress password attack ***
This article sheds light on the current ecosystem of the Sathurbot backdoor trojan, in particular exposing its use of torrents as a delivery medium and its distributed brute-forcing of weak WordPress administrator accounts.
*** New IoT/Linux Malware Targets DVRs, Forms Botnet ***
Unit 42 researchers have identified a new variant of the IoT/Linux botnet "Tsunami", which we are calling "Amnesia". The Amnesia botnet targets an unpatched remote code execution vulnerability that was publicly disclosed over a year ago in March 2016 in DVR (digital video recorder) devices made by TVT Digital and branded by over 70 vendors worldwide. Based on our scan data shown below in Figure 1, this [...]
*** [2017-04-07] Server-Side Request Forgery in MyBB forum ***
The "Change Avatar" function in MyBB allows an attacker to perform server-side request forgery (SSRF) attacks if the cURL functions are disabled. It is possible to send requests to internal networks and perform port scans.
*** IBM Security Bulletin: IBM Connections Docs is Vulnerable to a Denial of Service ( CVE-2016-3627 ) ***
DESCRIPTION: libxml2 is vulnerable to a denial of service, caused by an error in the xmlStringGetNodeList() function when parsing xml files while in recover mode. An attacker could exploit this vulnerability to exhaust the stack and cause a segmentation fault.
= End-of-Shift report =
Timeframe: Mittwoch 05-04-2017 18:00 − Donnerstag 06-04-2017 18:00
Handler: Stephan Richter
Co-Handler: n/a
*** Forscher warnen vor Gefahr durch Viren-Signaturen ***
Mit Hilfe der von Antiviren-Software eingesetzten Signaturen könnten Angreifer gezielt Fehlalarme auslösen. Im schlimmsten Fall kann das ein Opfer das komplette Mail-Archiv kosten.
*** Teenager Arrested in Austria for Spreading Philadelphia Ransomware ***
Austrian police arrested a 19-year-old teenager from Linz for infecting the network of a local company with the Philadelphia ransomware. [...]
*** Trust issues: Know the limits of SSL certificates ***
Certificate authorities (CAs) have given themselves a black eye lately, making it hard for users to trust them. Google stopped trusting Symantec after discovering the CA had mis-issued thousands of certificates over several years, and researchers found that phishing sites were using PayPal-labeled certificates issued by Linux Foundation's Let's Encrypt CA. Even with these missteps, the CAs play a critical role in establishing trust on the internet.To read this article in full or to...
*** Cisco Access Points: Zugriff mit offenen Default-Accounts ***
Bis zum Mittwoch konnten sich Angreifer mittels Default-Zugangsdaten Zugriff auf Cisco WLAN Access Points der Aeronet-Serie verschaffen. Ein Sicherheits-Update fixt das. Drei weitere schließen Einfallstore für DoS-Angriffe auf WLAN-Controller.
*** Wie Sie verschlüsselte Dateien wiederherstellen können ***
Mit einem Verschlüsselungstrojaner können Kriminelle Dateien von Opfern unbrauchbar machen. Sie verlangen Geld dafür, dass sie den Schaden beseitigen. Die Website nomoreransom.org/de hilft Opfern, die Dateien selbstständig wiederherzustellen, ohne dass sie dafür Geld an die Verbrecher/innen zahlen müssen.
*** Moodle Bugs Let Remote Users Conduct Cross-Site Scripting Attacks and Remote Authenticated Users Obtain Usernames and Conduct SQL Injection Attacks ***
*** Bugtraq: Trend Micro Enterprise Mobile Security Android Application - MITM SSL Certificate Vulnerability (CVE-2016-9319) ***
*** SECURITY BULLETIN: Trend Micro Smart Protection Server (Standalone) 3.x Command Injection Remote Code Execution Vulnerability ***
Trend Micro has released new Critical Patches (CP) for Trend Micro Smart Protection Server (Standalone) versions 3.0 and 3.1. These CPs resolve a vulnerability in the product that could potentially allow a remote attacker to execute arbitrary code on vulnerable installations.
*** BlackBerry powered by Android Security Bulletin - April 2017 ***
*** Certec EDV GmbH atvise scada ***
This advisory contains mitigation details for cross-site scripting and header injection vulnerabilities in the Certec EDV GmbH atvise scada.
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Financial Transaction Manager for ACH Services, Check Services and Corporate Payment Services session identifier vulnerability (CVE-2017-1152) ***
*** IBM Security Bulletin: Multiple vulnerabilities may affect IBM SDK, Java Technology Edition, affect IBM Tivoli Netcool Configuration Manager (ITNCM) (CVE-2016-5549) (CVE-2016-5548) (CVE-2016-5547) (CVE-2016-5546) ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Mobile Connect (CVE-2017-3272,CVE-2017-5548,CVE-2017-3261,CVE-2017-3231,CVE-2016-2183) ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect AIX ***
*** Novell Patches ***
*** eDirectory 8.8 SP8 Patch 10 ***
*** iManager 3.0.3 ***
*** iManager 2.7 Support Pack 7 - Patch 10 ***
*** eDirectory 9.0.3 ***
*** Cisco Security Advisories ***
*** Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers Shell Bypass Vulnerability ***
*** Cisco Wireless LAN Controller Management GUI Denial of Service Vulnerability ***
*** Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms Shell Bypass Vulnerability ***
*** Cisco Wireless LAN Controller IPv6 UDP Denial of Service Vulnerability ***
*** Cisco Wireless LAN Controller RADIUS Change of Authorization Denial of Service Vulnerability ***
*** Cisco Wireless LAN Controller 802.11 WME Denial of Service Vulnerability ***
*** Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance CLI Command Injection Vulnerability ***
*** Cisco UCS Director Virtual Machine Information Disclosure Vulnerability ***
*** Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance Debug Plug-in Privilege Escalation Vulnerability ***
*** Cisco Unified Communications Manager Cross-Site Scripting Vulnerability ***
*** Cisco Unified Communications Manager SQL Injection Vulnerability ***
*** Cisco Registered Envelope Service Open Redirect Vulnerability ***
*** Cisco IOS XE Software Startup Script Local Command Execution Vulnerability ***
*** Cisco IOS XR Software Denial of Service Vulnerability ***
*** Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Web Interface Information Disclosure Vulnerability ***
*** Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance CLI Command Injection Vulnerability ***
*** Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance CLI Command Injection Vulnerability ***
*** Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance local-mgmt CLI Command Injection Vulnerability ***
*** Cisco Integrated Management Controller Redirection Vulnerability ***
*** Cisco Firepower Detection Engine SSL Denial of Service Vulnerability ***
*** Cisco Firepower Detection Engine SSL Denial of Service Vulnerability ***
*** Cisco ASR 903 and ASR 920 Series Devices IPv6 Packet Processing Denial of Service Vulnerability ***
*** Cisco Aironet 1830 Series and 1850 Series Access Points Mobility Express Default Credential Vulnerability ***
= End-of-Shift report =
Timeframe: Dienstag 04-04-2017 18:00 − Mittwoch 05-04-2017 18:00
Handler: Stephan Richter
Co-Handler: n/a
*** WordPress Security - Unwanted Redirects via Infected JavaScript Files ***
We've been watching a specific WordPress infection for several months and would like to share details about it. The attacks inject malicious JavaScript code into almost every .js file it can find. Previous versions of this malware injected only jquery.js files, but now we remove this code from hundreds of infected files. Due to a bug in the injector code, it also infects files whose extensions contain ".js" (such as .js.php or .json).
*** Encryption inside Utility Industrial Control Systems (ICS) communication protocols: a must to preserve the confidentiality of information and reliability of the industrial process, (Tue, Apr 4th) ***
Industrial control systems are sensitive systems that must make decisions in real time to ensure the operation of the industrial process they govern. The latency and reliability in packet transmission is fundamental, since the protocols are connection-oriented but because of the main speed goal, many of them do not have included error recovery schemes other than those included in the TCP / IP stack. Where is it possible to use encryption without affecting the operation of the industrial control...
*** Schneider Electric still shipping passwords in firmware ***
Youd think a vendor of critical infrastructure would at least pretend to care about security That "dont use hard-coded passwords" infosec rule? Someone needs to use a needle to write it on the corner of Schneider Electrics developers eyes so they dont forget it.
*** Internetplattform unterstützt Opfer von digitaler Erpressung ***
Für Betroffene von digitaler Erpressung ist es besonders wichtig, ihre Dateien schnell und einfach wiederherzustellen. Unter www.nomoreransom.org können verschiedene Entschlüsselungstools nun auch auf Deutsch aufgerufen werden.
*** 500.000 US-Dollar Lösegeld: Ransomware-Gangs nehmen Unternehmen aufs Korn ***
Sicherheitsforscher haben mindestens acht Gruppen ausgemacht, die sich auf Ransomware-Attacken auf Unternehmen spezialisiert haben. Je nach Anzahl der infizierten PCs und Server steigt das Lösegeld. Summen von bis zu 500.000 US-Dollar sind im Spiel.
*** Whitelists: The Holy Grail of Attackers, (Wed, Apr 5th) ***
As a defender, take the time to put yourself in the place of a bad guy for a few minutes. Youre writing some malicious code and you need to download payloads from the Internet or hide your code on a website. Once your malicious code spread in the wild, it will be quickly captured by honeypots, IDS, ... (name your best tool) and analysed automatically of manually by the good guys. Their goal of this is to extract abehavioural analysis of the code and generate indicators (IOCs) which will help to...
*** Broadcom-Sicherheitslücke: Angriff über den WLAN-Chip ***
Googles Project Zero zeigt, wie man ein Smartphone per WLAN übernehmen kann. WLAN-Chips haben heute eigene Betriebssysteme, denen jedoch alle modernen Sicherheitsmechanismen fehlen.
*** Report: 30% of malware is zero-day, missed by legacy antivirus ***
At least 30 percent of malware today is new, zero-day malware that is missed by traditional antivirus defenses, according to a new report."Were gathering threat data from hundreds of thousands of customers and network security appliances," said Corey Nachreiner, CTO at WatchGuard Technologies. "We have different types of malware detection services, including a signature and heuristic-based gateway antivirus. What we found was that 30 percent of the malware would have been missed...
*** Changes coming to TLS: Part Two ***
In the first part of this two-part blog we covered certain performance improving features of TLS 1.3, namely 1-RTT handshakes and 0-RTT session resumption. In this part we shall discuss some security and privacy improvements.Remove Obsolete and insecure cryptographic primitivesRemove RSA HandshakesWhen RSA is used for key establishment there is no forward secrecy, which basically means that an adversary can record the encrypted conversation between the client and the server and later if it is...
*** Broadcom: Heap overflow in TDLS Teardown Request while handling Fast Transition IE ***
[...] Then, if the IE is present, its contents are copied into a heap-allocated buffer of length 256. The copy is performed using the length field present in the IE, and at a fixed offset from the buffers start address. Since the length of the FTIE is not verified prior to the copy, this allows an attacker to include a large FTIE (e.g., with a length field of 255), causing the memcpy to overflow the heap-allocated buffer.
*** Citrix XenServer Multiple Security Updates ***
A number of security issues have been identified within Citrix XenServer. The most significant of these issues could, if exploited, allow a malicious administrator of a 64-bit PV guest VM to compromise the host.
*** Django Input Validation Flaws Let Remote Users Conduct Cross-Site Scripting and Open Redirect Attacks ***
*** HPE Business Process Monitor Unspecified Flaw Lets Remote Users Access Data on the Target System ***
*** Asterisk Buffer Overflow in Processing CDR User Data Lets Remote Authenticated Users Execute Arbitrary Code ***
*** Security Advisory - Multiple Buffer Overflow Vulnerabilities in Bastet of Huawei Smart Phone ***
*** Security Advisory - Information Leak Vulnerability in Some Huawei Smart Phones ***
*** Schneider Electric Interactive Graphical SCADA System Software ***
This advisory contains mitigation details for a DLL hijacking vulnerability in Schneider Electric's Interactive Graphical SCADA System Software.
*** Marel Food Processing Systems ***
This advisory contains mitigation details for hard-coded passwords and unrestricted upload vulnerabilities in Marel's Food Processing Systems.
*** Rockwell Automation Allen-Bradley Stratix and Allen-Bradley ArmorStratix ***
This advisory contains mitigation details for an improper input validation vulnerability in Rockwell Automation's Allen-Bradley Stratix and ArmorStratix Industrial Ethernet and Distribution switches.
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Vulnerability in Apache Struts affects IBM Opportunity Detect (CVE-2017-5638) ***
*** IBM Security Bulletin: IBM Security Guardium is affected by Open Source Oracle MySQL Vulnerability (CVE-2017-3302) ***
*** IBM Security Bulletin: IBM Security Guardium is affected by Open Source Oracle MySQL Vulnerabilities (multiple CVEs) ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Security Guardium Database Activity Monitor ***
*** Fortinet PSIRT Advisories ***
*** FortiClient SSLVPN Linux - Root privilege escalation with subproc ***
*** FortiClient SSLVPN Linux - Arbitrary write to log file ***
*** Multiple vulnerabilities in Linux kernels through 4.6.3 ***
*** Unauthenticated XSS (Cross Site Scripting) in FortiMail ***
*** Linux kernel - challenge ack information leak ***
*** F5 Security Advisories ***
*** BIG-IP file validation vulnerability CVE-2015-8022 ***
*** OpenSSL vulnerability CVE-2015-3195 ***
*** OpenSSH vulnerability CVE-2016-6210 ***
*** Expat XML library vulnerability CVE-2015-1283 ***
*** glibc vulnerability CVE-2016-3075 ***
*** libxml2 vulnerability CVE-2016-1834 ***
*** glibc vulnerability CVE-2016-4429 ***
*** TMM vulnerability CVE-2016-5023 ***
*** Linux kernel vulnerability CVE-2013-7446 ***
*** OpenSSH vulnerability CVE-2015-8325 ***
*** NTP vulnerability CVE-2015-7976 ***
*** Linux kernel vulnerability CVE-2011-5321 ***
*** TMM vulnerability CVE-2016-9245 ***
*** glibc vulnerability CVE-2015-8776 ***
*** OpenSSL vulnerability CVE-2016-0800 ***
*** libarchive vulnerability CVE-2016-5844 ***
*** ISC DHCP vulnerability CVE-2016-2774 ***
*** Java commons-collections library vulnerability CVE-2015-4852 ***
*** PHP vulnerability CVE-2016-4070 ***
*** NTP vulnerability CVE-2016-2519 ***
*** GnuPG vulnerability CVE-2013-4402 ***
*** libarchive vulnerability CVE-2016-8688 ***
*** PHP vulnerability CVE-2016-3074 ***
*** OpenSSL vulnerability CVE-2016-7056 ***
*** OpenSSH vulnerability CVE-2016-10009 ***
*** BIG-IP APM access logs vulnerability CVE-2016-1497 ***
= End-of-Shift report =
Timeframe: Montag 03-04-2017 18:00 − Dienstag 04-04-2017 18:00
Handler: Robert Waldner
Co-Handler: Stephan Richter
*** Lazarus Under The Hood ***
Today wed like to share some of our findings, and add something new to whats currently common knowledge about Lazarus Group activities, and their connection to the much talked about February 2016 incident, when an unknown attacker attempted to steal up to $851M USD from Bangladesh Central Bank.
*** APT10 - Operation Cloud Hopper ***
Written by Adrian Nish and Tom RowlesBACKGROUNDFor many businesses the network now extends to suppliers who provide management of applications, cloud storage, helpdesk, and other functions. With the right integration and service levels Managed Service Providers (MSPs) can become a key enabler for businesses by allowing them to focus on their core mission while suppliers take care of background tasks. However, the network connectivity which exists between MSPs and their customers also provides a...
*** WLAN-Lücke: Apple reicht Bugfix-Update für iOS 10.3 nach ***
iOS 10.3.1 behebt einen schwerwiegenden Fehler, über den ein Angreifer Code auf dem WLAN-Chip ausführen könnte. Außerdem lassen sich 32-Bit-Versionen nun wieder direkt auf dem Gerät installieren.
*** NSO Group: Pegasus-Staatstrojaner für Android entdeckt ***
Nach der iOS-Version des Staatstrojaners Pegasus haben Sicherheitsforscher auch eine Version für Android gefunden. Diese nutzt keine Zero-Day-Exploits und kann auch ohne vollständige Infektion Daten übertragen.
*** Cloudmark kündigt überraschend DANE/TLSA für Mail-Sicherheit an ***
Der überraschende Schritt des Internet-Schwergewichts erscheint bedeutsam, weil er die Mail-Sicherheitstechnik stärkt und zugleich als eine deutliche Absage an das Konzept der Certification Authorities gelesen werden kann.
*** Betriebssystem Tizen für Samsung-Geräte von Sicherheitslücken durchsiebt ***
Ein Sicherheitsforscher hat den Code von Samsungs Tizen analysiert und zieht ein desaströses Resümee. Das Betriebssystem dient als Basis für mobile Geräte und Fernseher des Herstellers.
*** Kaspersky: Geldautomaten mit 15-US-Dollar-Bastelcomputer leergeräumt ***
Am Ende bleibt nur ein golfballgroßes Loch und das Geld ist weg: Kaspersky hat einen neuen Angriff auf Geldautomaten vorgestellt. Bei dem Angriff werden physische Beschädigung und Hacking kombiniert. Betroffen sind weit verbreitete Modelle aus den 90er Jahren.
*** How Hackers Hijacked a Bank's Entire Online Operation ***
Researchers at Kaspersky say a Brazilian banks entire online footprint was commandeered in a five-hour heist.
*** Workshop on Software Security in industrial area ***
May 09, 2017 - 4:00 pm - 6:30 pm Bachmann electronic GmbH Kreuzäckerweg 33 Feldkirch
*** CVE-2017-7228 - x86: broken check in memory_exchange() permits PV guest breakout ***
A malicious or buggy 64-bit PV guest may be able to access all of system memory, allowing for all of privilege escalation, host crashes, and information leaks.
*** Bugtraq: The password for the project protection of the Schneider Modicon TM221CE16R is hard-coded and cannot be changed. ***
*** Bugtraq: OS-S-2017-01: The password for the application protection of the Schneider Modicon TM221CE16R can be retrieved without authentication. Subsequently the application may be arbitrarily downloaded, uploaded and modified. CVSS 10. ***
*** VU#307983: AMF3 Java implementations are vulnerable to insecure deserialization and XML external entities references ***
Vulnerability Note VU#307983 AMF3 Java implementations are vulnerable to insecure deserialization and XML external entities references Original Release date: 04 Apr 2017 | Last revised: 04 Apr 2017 Overview Several Java implementations of AMF3 are vulnerable to insecure deserialization and XML external entities references. Description Several Java implementations of AMF3 are vulnerable to one or more of the following implementation errors:CWE-502: Deserialization of Untrusted DataSome Java...
*** DFN-CERT-2017-0569: Google Android Operating System: Mehrere Schwachstellen ermöglichen u.a. die komplette Systemübernahme ***
*** DFN-CERT-2017-0571: Red Hat JBoss A-MQ, JBoss Fuse: Mehrere Schwachstellen ermöglichen u.a. das Ausführen beliebigen Programmcodes ***
*** Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection ***
Topic: Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection Risk: High Text:# Exploit Title: Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection # Date: 2017-04-02 # Exploit Author: Fluffy Huffy (t...
*** D-Link DIR 615 HW T1 FW 20.09 Cross-Site Request Forgery ***
Topic: D-Link DIR 615 HW T1 FW 20.09 Cross-Site Request Forgery Risk: Medium Text:*Title:* = D-Link DIR 615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability *Credit...
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM License Metric Tool v9 and IBM BigFix Inventory v9 ***
*** IBM Security Bulletin: Vulnerability in Apache ActiveMQ affects IBM Control Center (CVE-2016-6810) ***
*** IBM Security Bulletin: IBM Maximo Asset Management could allow an authenticated user to view incorrect item sets that they should not have access to view (CVE-2016-8987) ***
*** IBM Security Bulletin: Potential security vulnerability in IBM WebSphere Application Server in Bluemix MQ JCA Resource adapter (CVE-2016-0360) ***
*** IBM Security Bulletin: Vulnerabilities in krb5, giflib and freetype2 affect IBM BladeCenter Advanced Management Module (AMM) and IBM Flex System Chassis Management Module (CMM) ***
= End-of-Shift report =
Timeframe: Freitag 31-03-2017 18:00 − Montag 03-04-2017 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** EvilEye: Malware kapert Webcam, um Werbung zu personalisieren ***
Eine auf "EvilEye" getaufte Spyware sucht per übernommener Webcam nach Produkten des Computernutzers, um ihm gezielt personalisierte Werbung anzuzeigen und daran ..
*** Gigabyte Firmware Flaws Allow the Installation of UEFI Ransomware ***
Yesterday, at the BlackHat Asia 2017 security conference, researchers from cyber-security firm Cylance disclosed ..
*** Weitere Lücke in LastPass geschlossen, neue Version verfügbar ***
Lastpass hat eine vor wenigen Tagen gefundene Sicherheitslücke in seinen Erweiterungen für diverse Browser geschlossen. Anwender sollten umgehend aktualisieren.
*** Vuln: Moodle CVE-2017-7298 Cross Site Scripting Vulnerability ***
*** Angriffswerkzeug Metasploit hackt jetzt auch Zombie-IIS ***
Etwa ein Prozent der weltweiten Webserver laufen mit einer verwundbaren Version von Microsofts Internet ..
*** Miele Professional PG 8528 Vulnerability ***
NCCIC/ICS-CERT is aware of a public report of a directory traversal vulnerability with proof-of-concept ..
*** Smart-TV-Hack: Schadcode über DVB-T ermöglicht Übernahme aus der Ferne ***
Einem Sicherheitsexperten ist es gelungen, volle Kontrolle über einen Fernseher zu übernehmen, in dem er in das DVB-T-Signal Code einschleuste, der eine Sicherheitslücke in der HbbTV-Applikation des Geräts ausnutzt.
*** Tech support scams persist with increasingly crafty techniques ***
Millions of users continue to encounter technical support scams. Data from Windows Defender SmartScreen (which is used ..
*** IBM Security Bulletin:Open Source Apache Poi Vulnerability in IBM eDiscovery Manager ***
*** IBM Security Bulletin:Open Source Apache Tomcat,Commons FileUpload Vulnerabilities affects WebSphere App Server in IBM eDiscovery Manager ***
*** IBM Security Bulletin: Vulnerabilities in OpenSSL affect PowerKVM ***
*** IBM Security Bulletin: Persistent cross-site scripting vulnerability in IBM Business Process Manager (CVE-2017-1140) ***
*** IBM Security Bulletin: Vulnerabilities in BIND affect Power Hardware Management Console ***
*** IBM Security Bulletin: Vulnerabilities in the Linux Kernel affect PowerKVM ***
*** Skype: Bösartige Werbung verteilt Fake-Flash-Update ***
Anwender berichten davon, in Skype Werbebanner untergeschoben bekommen zu haben, die beim Klick ein gefälschtes Flash-Update herunterladen. Dabei handelt es sich um Schadcode.
*** Cryptowars: Ahnungslose EU-Kommissarin redet über Whatsapp-Daten ***
EU-Justizkommissarin Vera Jourová will der Polizei ermöglichen, leichter Zugang zu Daten von Internetdienstleistern ..
= End-of-Shift report =
Timeframe: Donnerstag 30-03-2017 18:00 − Freitag 31-03-2017 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Security SiteProtector System ***
*** IBM Security Bulletin: IBM Cognos Analytics is affected by multiple vulnerabilities ***
*** Spotting a Hidden SEO Hack: “Play One” ***
SEO hacks continue to plague websites as attackers abuse SERP rankings for their own gain. The time and effort spent by the website owner creating content, optimizing pages and building ..
*** Schneider Electric Modicon PLCs ***
This advisory contains mitigation details predictable value range from previous values, use of insufficiently random values, and insufficiently protected credentials vulnerabilities in Schneider Electrics Modicon PLCs.
*** Researchers steal data from shared cache of two cloud VMs ***
All of a sudden dedicated instances are looking a lot better than multi-tenancy A group of researchers, one ..
*** Novell: Sentinel 8.0 SP1 (Sentinel Build 3512 ***
*** Celebrate World Backup Day the Smarter Way ***
In an effort to help the community be more cyber aware, WorldBackupDay.com celebrates on March 31st ..
*** Samsung Galaxy S8s Facial Unlocking Feature Can Be Fooled With A Photo ***
All users need to do is simply hold their Galaxy S8 or S8 Plus in front of their eyes or their entire ..
*** Studie: TK-Infrastruktur hoffnungslos unsicher – Verschlüsselung Fehlanzeige ***
Der amerikanische Pendant zur Bundesnetzagentur hat die Sicherheit des für die Telekommunikations-Infrastruktur unverzichtbaren SS7-Protokolls untersucht. Die Bilanz ist haarsträubend; die Arbeitsgruppe empfiehlt Ende-zu-Ende-Verschlüsselung.
*** l+f: Flash für eine Handvoll Dollar ***
FedEx Office macht seinen Kunden ein unmoralisches Angebot.
*** Pornhub und Youporn stellen auf https um ***
Die beiden Pornoseiten wollen ihren Nutzern mehr Datenschutz ermöglichen
= End-of-Shift report =
Timeframe: Mittwoch 29-03-2017 18:00 − Donnerstag 30-03-2017 18:00
Handler: Robert Waldner
Co-Handler: n/a
*** Tech support scammers and their banking woes ***
We all know about tech support scams by this point. Unfortunately for the scammers, banks know this as well, making it quite difficult at times to maintain an account to store the criminal's ill-gotten gains. So how does the enterprising criminal cash out with your money? Let's take a look.
*** Security Advisory - Exposed System Interface Vulnerability on Huawei Smart Phones ***
There is a exposed system interface vulnerability on smart phones. The software provides a system interface for interaction with external applications, but calling the interface is not properly restricted. An attacker could trick the user into installing a malicious application to call the interface and modify the system properties.
*** Widespread Email Scam Targets Github Developers with Dimnie Trojan ***
Open source developers who use the popular code-sharing site GitHub were put on alert after the discovery of a phishing email campaign that attempts to infect their computers with an advanced malware trojan. Dubbed Dimnie, the reconnaissance and espionage trojan has the ability to harvest credentials, download sensitive files, take screenshots, log keystrokes on 32-bit and 64-bit ...
*** Vuln: EMC Isilon OneFS CVE-2017-4980 Directory Traversal Vulnerability ***
EMC Isilon OneFS is prone to a directory-traversal vulnerability.
A remote attacker could exploit the vulnerability using directory-traversal characters ('../') to access arbitrary files that contain sensitive information.
*** [SANS ISC] Diverting built-in features for the bad ***
I published the following diary on isc.sans.org: 'Diverting built-in features for the bad'. Sometimes you may find very small pieces of malicious code. Yesterday, I caught this very small Javascript sample with only 2 lines of code
*** Trend Micro InterScan Web Security Virtual Appliance Unspecified Flaws Let Remote Users Execute Arbitrary Code on the Target System ***
*** Mirai-Botnetz lernt neue Tricks ***
Das IoT-Botnetz Mirai beherrscht neuerdings auch DDoS-Angriffe auf dem Application Layer. Diese sind schwer zu entdecken und damit auch relativ schwer abzuwehren.
*** Hashfunktion: Der schwierige Abschied von SHA-1 ***
Die Hashfunktion SHA-1 ist seit kurzem endgültig gebrochen. Doch an vielen Stellen ist SHA-1 noch im Einsatz. Beispielsweise in Git, in Bittorrent und - was manche überraschen wird - auch in TLS. (SHA-1, Google)
*** IBM Security Bulletins ***
*** IBM Security Bulletin: IBM Algo One - Algo Risk Application (ARA) could allow retrieval of restricted files ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Spectrum Scale packaged the Elastic Storage Server and the GPFS Storage Server ***
*** IBM Security Bulletin: Vulnerability in the GSKit component of Tivoli Netcool/OMNIbus (CVE-2016-2183) ***
*** IBM Security Bulletin: IBM Tivoli Monitoring Basic Services component. (CVE-2012-6702, CVE-2016-5300) ***
*** IBM Security Bulletin: Vulnerabilities in Expat affect Intel (R) Manycore Platform Software Stack (MPSS) for Linux and Windows ***
*** IBM Security Bulletin: IBM TRIRIGA Document Manager Privilege Escalation (CVE-2017-1180) ***
*** IBM Security Bulletin: Security vulnerabilities have been identified in data server connection and product integration shipped with InfoSphere Optim Query Workload Tuner [for LUW, z/OS ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect Content Manager Enterprise Edition ***
*** IBM Security Bulletin: A vulnerability in IBM Java Runtime affects IBM WebSphere MQ and IBM MQ Appliance (CVE-2016-5597) ***
*** IBM Security Bulletin: IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management vulnerable to cross-site request forgery (CSRF) ***
= End-of-Shift report =
Timeframe: Dienstag 28-03-2017 18:00 − Mittwoch 29-03-2017 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** World Backup Day is as good as any to back up your data ***
In today’s security landscape, there are more threats to data than ever before. Beyond corruption caused by hardware or human failure, malware and cyberattacks can put data in serious danger. That’s why it’s .. ---------------------------------------------
*** Siemens RUGGEDCOM ROX I ***
This advisory contains mitigation details for improper authorization, cross-site scripting, and cross-site request forgery vulnerabilities in the Siemens RUGGEDCOM ROX I.
*** 3S-Smart Software Solutions GmbH CODESYS Web Server ***
This advisory contains mitigation details for arbitrary file upload and stack buffer overflow vulnerabilities in the 3S-Smart Software Solutions GmbH CODESYS Web Server.
*** FBI warns of attacks on anonymous FTP servers ***
The FBI warns that attackers are targeting vulnerable FTP servers used by small medical and dental ..
*** About the security content of iCloud for Windows 6.2 ***
*** Ransomware: Scammer erpressen Besucher von Pornoseiten ***
Über einen Fehler in Apples Safari für iPhone blockieren Unbekannte den Browser mit einem immer ..
*** Benutzt hier jemand JSON Encryption?If you are using ... ***
Benutzt hier jemand JSON Encryption?If you are using go-jose, node-jose, jose2go, Nimbus JOSE+JWT or jose4 with ECDH-ES please update to the latest version. RFC 7516 aka JSON Web ..
*** Vuln: ImageMagick Incomplete Fix CVE-2017-7275 Memory Corruption Vulnerability ***
*** "Cyber-Angriff" im Bundestag: Anscheinend eine gewöhnliche Malvertising-Kampagne ***
Deutsche Medien berichten von einem erneuten Hackerangriff auf den Bundestag. Dabei scheint es sich um Abgeordnete zu handeln, die Opfer von verseuchter Werbung auf der Webseite einer israelischen Zeitung geworden sind. Infektionen gab es keine.
*** Escaping a Python sandbox with a memory corruption bug ***
*** DFN-CERT-2017-0543: AppArmor: Eine Schwachstelle ermöglicht das Umgehen von Sicherheitsvorkehrungen ***
Ein entfernter, nicht authentisierter Angreifer kann eine speziell präparierte Anwendung uneingeschränkt auf einem betroffenen System einsetzen, da über AppArmor ..
*** Ausbruch aus der VM: VMware schließt kritische Pwn2Own-Lücken ***
VMware hat Sicherheitslücken in VMware Workstation, Fusion und ESXi geschlossen, mit deren Hilfe Sicherheitsforscher beim Pwn2Own-Wettbewerb aus virtuellen Maschinen ausgebrochen und das Host-System gekapert hatten.
*** PMASA-2017-8 ***
*** Ebury-Rootkit: Russischer Hacker bekennt sich schuldig ***
Ein russsischer Staatsbürger hat in den USA seine Beteiligung am Auf- und Ausbau des Ebury-Botnetzes eingestanden. Ebury befällt vor allem Linux-Server und greift SSH-Logins ab.
*** Browser-Plug-in Crusader injiziert falsche Support-Telefonnummern in Webseiten ***
Eine neue Schadcode-Variante integriert sich in den Browser und tauscht Suchergebnisse aus. Dadurch kann der Anwender auf Affiliate-Seiten umgelenkt werden. Außerdem ist es möglich, ihm falsche Support-Telefonnummern unterzuschieben.
*** GitHub Users Targeted with Dimnie Trojan ***
= End-of-Shift report =
Timeframe: Montag 27-03-2017 18:00 − Dienstag 28-03-2017 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** Bugtraq: APPLE-SA-2017-03-27-1 Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac; Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS ***
*** APT29 Used Domain Fronting, Tor to Execute Backdoor ***
APT29, a/k/a Cozy Bear, has used Tor and a technique called domain fronting in order to secure backdoor access to targets for nearly two years running.
*** New Clues Surface on Shamoon 2’s Destructive Behavior ***
Researchers report new connections between Magic Hound and Shamoon 2, along with descriptions of how the Disttrack malware component of campaigns moves laterally within infected networks.
*** Vuln: GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities ***
GnuTLS GNUTLS-SA-2017-3 Multiple Security Vulnerabilities
*** Neue Sicherheitslücke im Passwort-Manager LastPass ***
Bereits zum zweiten Mal innerhalb kurzer Zeit ist der populäre Passwort-Manager mit einer Schwachstelle konfrontiert.
*** Symantec API Flaws reportedly let attackers steal Private SSL Keys and Certificates ***
A security researcher has disclosed critical issues in the processes and third-party API used by Symantec certificate resellers to deliver and manage Symantec SSL ..
*** Threat Landscape for Industrial Automation Systems, H2 2016 ***
On average, in the second half of 2016 Kaspersky Lab products across the globe blocked attempted attacks on 39.2% of protected computers that Kaspersky Lab ICS CERT classifies as being part of industrial enterprise technology infrastructure.
*** From DDoS to Server Ransomware: APACHE STRUTS 2 - CVE-2017-5638 Campaign ***
As soon as a zero-day remote code execution vulnerability is disclosed, it is common to see many scans in the wild. Some of these scans are researchers, but many of ..
*** This book reads you - using JavaScript ***
Apple just released a fix for one issue I reported last year in iBooks that allowed access to files on a users system when a book was opened. iBooks on El Capitan would ..
*** Gefahr durch Exploit für Zombie-IIS ***
Microsofts Internet Information Services 6.0 sind eigentlich Alteisen, für das es nicht einmal Sicherheits-Updates gibt. Trotzdem gibt es noch über 30.000 allein in Deutschland. Und die sind durch einen öffentlich bekannten Exploit akut bedroht.
*** Verschlüsselung: Schwachstellen in zahlreichen VoIP-Anwendungen entdeckt ***
Das ZRT-Protokoll soll für sichere Verbindungen und verschlüsselte VoIP-Telefonate sorgen. Forscher haben Schwachstellen in zahlreichen ZRTP-Anwendungen ..
*** IronWASP – Part 1 ***
Considering not all vulnerability scanners are open source, a great deal of them are available such as: IronWASP OpenVAS Retina CS Community W3af Grabber, etc. In this article, we shall be discussing more about IronWASP.
*** Docs.com-Nutzer teilen Kennwörter und vieles mehr mit der Welt ***
Über Microsofts Dienst Docs.com lassen sich Dokumente teilen. Allerdings sind diese oft öffentlich einsehbar. Viele Anwender scheinen sich dem nicht bewusst zu sein – zu einfach finden sich Informationen wie Kennwörter.
*** Apache / ModSecurity Tutorials ***
This is a series of Apache web server tutorials that will span from the basics to advanced topics like ModSecurity and logfile visualization.
*** Xen Security Advisory XSA-206 - xenstore denial of service via repeated update ***
Unprivileged guests may be able to stall progress of the control domain or driver domain, possibly leading to ..
*** With iOS 10.3, iDevices get new Apple File System with native encryption support ***
On Monday, Apple released updates for its various products. As usual, they fix flaws and add capabilities, but the iOS update (v10.3) is more noteworthy than usual, ..
*** Ransomware: Scammer erpressen Besucher von Porno-Seiten ***
Über einen Fehler in Apples Safari für iPhone blockieren Unbekannte den Browser mit einem immer wiederkehrenden Javascript-Popup. Darin werden Nutzer aufgefordert, Lösegeld zu zahlen. Mit einem einfachen Trick lässt sich der Falle aber entgehen.
= End-of-Shift report =
Timeframe: Freitag 24-03-2017 18:00 − Montag 27-03-2017 18:00
Handler: Robert Waldner
Co-Handler: n/a
*** SAP NetWeaver J2EE Platform Security ***
In the previous article, we discussed SAP NetWeaver ABAP Platform and its vulnerabilities. Today's topic is the J2EE platform, its architecture, vulnerabilities, and the latest trends in its cyber security.
*** [Update] Ungepatchte SAP-Systeme angreifbar für Remote Code Execution ***
Wenn die im Rahmen des SAP Security Patch Day im März 2017 veröffentlichten Patches nicht umgehend eingespielt werden, droht die Kompromittierung zentraler Datenbestände, warnen SAP-Kenner.
*** Amazon-Phishingmail: Rechnung über Ihre Verkäufergebühren ***
In einer angeblichen Nachricht von "Europe Amazon" erhalten Kund/innen die Information, dass ihr "Duplikat der elektronisch erzeugten Steuerrechnung" verfügbar sei. Sie können es in einem beigefügten Dokument, das den Login-Bereich von Amazon imitiert, herunterladen. Es handelt sich um einen Phishingversuch.
*** Detecting and mitigating elevation-of-privilege exploit for CVE-2017-0005 ***
On March 14, 2017, Microsoft released security bulletin MS17-013 to address CVE-2017-0005, a vulnerability in the Windows Win32k component that could potentially allow elevation of privileges. A report from a trusted partner identified a zero-day exploit for this vulnerability. The exploit targeted older versions of Windows and allowed attackers to elevate process privileges on these platforms.
*** IBM Security Bulletins ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect WebSphere Dashboard Framework ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect IBM Web Experience Factory ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Process Designer used in IBM Business Process Manager and WebSphere Lombardi Edition ***
*** IBM Security Bulletin: Vulnerabilities in zlib affect IBM Sterling Connect:Direct for Microsoft Windows (CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843) ***
*** IBM Security Bulletin: Privilege Escalation vulnerability affects Cognos Business Intelligence (CVE-2016-8960) ***
*** IBM Security Bulletin: Vulnerability in OpenSSL affects LCM8 & LCM16 KVM Switch Firmware and GCM16 & GCM32 KVM Switch Firmware (CVE-2016-8610) ***
*** IBM Security Bulletin: Vulnerabilities in SSH affect IBM DataPower Gateways (CVE-2016-10009, CVE-2016-10012) ***
*** IBM Security Bulletin: Vulnerabilities in OpenSSH and OpenSSL affect GPFS for Windows V3.5 ***
*** IBM Security Bulletin: IBM Sterling Selling and Fulfillment Foundation is affected by Cross Site Scripting (XSS) Vulnerability (CVE-2016-8917) ***
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Jazz Team Server affect IBM Rational products based on IBM Jazz technology ***
*** IBM Security Bulletin: Vulnerability in GSKit affects IBM Sterling Connect:Direct for UNIX (CVE-2016-2183) ***
*** IBM Security Bulletin: Fix Available for IBM iNotes Cross-site Scripting Vulnerability (CVE-2016-9990) ***