Independent

IndependentSecuriteam

SSD Advisory–D-Link DSL-6850U多个漏洞

Credit to Author: SSD / Maor Schwartz| Date: Sun, 07 Jan 2018 06:28:24 +0000

漏洞概要 以下安全公告描述了在D-Link DSL-6850U BZ_1.00.01 – BZ_1.00.09中的发现的两个漏洞。 D-Link DSL-6850U是一款“以色列Bezeq制造的路由器”,在这款路由器中发现的漏洞是: 默认凭证 远程命令执行 漏洞提交者 一位独立的安全研究人员向 Beyond Security 的 SSD 报告了该漏洞 厂商响应 Bezeq在6月9日被告知了这个漏洞,并且发布了补丁来解决这些漏洞。 漏洞详细信息 该设备定制的固件存在以下问题: 默认启用远程Web管理 不能禁用默认帐户 默认凭证 默认帐户用户名是:support 密码是:support 远程命令执行 shell界面只允许执行一组内置命令,但是你可以通过’&’ ‘||’ 插入命令到shell: [crayon-5a529cda84c8f912287642/] 上述命令执行后返回一个BusyBox shell

Read More
ComputerWorldIndependent

Browser makers build bulwarks to stump Spectre attacks

Credit to Author: Gregg Keizer| Date: Sat, 06 Jan 2018 12:58:00 -0800

Amid the panicked response this week to the news of significant, though not-yet-exploited, vulnerabilities in the vast bulk of the world’s microprocessors, it went almost unnoticed that most browser makers responded by updating their wares in the hope of fending off possible web-based attacks.

The Google-driven revelations – it was members of the search firm’s Project Zero security team who identified the multiple flaws in processors designed by Intel, AMD and ARM – were to go public next week, on Jan. 9, this month’s Patch Tuesday. At that time, a coordinated effort by multiple vendors, from OS developers to silicon makers, was to debut with patches to protect, as best could be done without replacing the CPU itself, systems against flaws grouped under the umbrella terms of Meltdown and Spectre. That plan went out the window when leaks started to circulate earlier this week.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Win7 Monthly Rollup KB 4056894 signals early, abbreviated Patch Tuesday

Credit to Author: Woody Leonhard| Date: Fri, 05 Jan 2018 06:48:00 -0800

Last night Microsoft released KB 4056894, the 2018-01 Security Monthly Quality Rollup for Windows 7. Spurred by early disclosure of the Meltdown and Spectre vulnerabilities, Microsoft has done yeoman work getting the software part of the patches pushed out the Automatic Update chute.

That said, Windows patches are only part of a very formidable picture.

Where we stand with Windows patches

As of this morning, all of the supported versions of Windows have Meltdown-related patches, except for Windows 8.1. In particular:

To read this article in full, please click here

Read More
ComputerWorldIndependent

How Apple users can protect themselves against Spectre and Meltdown

Credit to Author: Jonny Evans| Date: Fri, 05 Jan 2018 06:26:00 -0800

Apple has confirmed that all Macs, iPhones, iPads and other devices (bar Apple Watch) are vulnerable to the newly-revealed Spectre and Meltdown Intel, ARM and AMD processor vulnerabilities.

What’s the problem?

Taking advantage of a vulnerability that has been around for 20-years, Meltdown and Spectre exploit a CPU performance feature called “speculative execution”. Speculative execution exists to improve computer speed by enabling the processor to work on multiple instructions at once, sometimes in non-sequential order.

To read this article in full, please click here

Read More
IndependentSecuriteam

Know your community – Sergi Alvarez AKA Pancake

Credit to Author: SSD / Maor Schwartz| Date: Thu, 04 Jan 2018 11:13:19 +0000

The creator of Radare2, vulnerability researcher, chef and a family man – meet Sergi Alvarez also known as Pancake! Questions Q: How many years have you been working in the security field? A: I started programming BASIC in Spectrum and PC/M. Then I switched to MSDOS and assembly (TASM) as a main language. From there … Continue reading Know your community – Sergi Alvarez AKA Pancake

Read More
ComputerWorldIndependent

Windows, Meltdown and Spectre: Keep calm and carry on

Credit to Author: Woody Leonhard| Date: Thu, 04 Jan 2018 08:13:00 -0800

I’m increasingly skeptical of security holes that have their own logos and PR campaigns. Yesterday’s sudden snowballing of disclosures about two groups of vulnerabilities, now known as Meltdown and Spectre, has led to enormous numbers of reports of varying quality, and widespread panic in the streets. In the case of Intel’s stock price, that’s more like blood in the streets.

While it’s true that both vulnerabilities affect nearly every computer made in the past two decades, it’s also true that the threat — especially for plain-vanilla Windows users — isn’t imminent. You should be aware of the situation, but avoid the stampede. The sky isn’t falling.

To read this article in full, please click here

Read More