Securiteam

IndependentSecuriteam

SSD Advisory – Bitdefender Code Signing organizationName Buffer Overflow

Credit to Author: SSD / Maor Schwartz| Date: Thu, 18 May 2017 05:34:17 +0000

Vulnerability Summary The following advisory describes a Buffer Overflow vulnerability found in Bitdefender Engine PE. Bitdefender provides the Bitdefender “antimalware” engine for integration with other security vendors products. The engine is used in Bitdefender’s own products, for example in Bitdefender Internet Security 2017 and below. The antimalware engine is the core of the product, among … Continue reading SSD Advisory – Bitdefender Code Signing organizationName Buffer Overflow

Read More
IndependentSecuriteam

Know your community – Simone Margaritelli (@evilsocket)

Credit to Author: SSD / Maor Schwartz| Date: Tue, 16 May 2017 11:57:33 +0000

The guy that published a first hand account of how an allegedly government-sponsored firm, Dark Matter, tried to hire him to help them spy on civilian in the UAE. A former BlackHat that switch sides Bug Bounty hunter The author of the most known offensive open source software – BetterCAP, dSploit, AndroSwat and more! Please … Continue reading Know your community – Simone Margaritelli (@evilsocket)

Read More
IndependentSecuriteam

SSD Advisory – AContent Multiple Vulnerabilities

Credit to Author: SSD / Maor Schwartz| Date: Tue, 16 May 2017 05:32:18 +0000

Vulnerabilities Summary The following advisory describes two (2) vulnerabilities types found in AContent version 1.3. AContent is an open source learning content management system (LCMS) used to create interoperable, accessible, adaptive Web-based learning content. It can be used along with learning management systems to develop, share, and archive learning materials. For those familiar with ATutor, … Continue reading SSD Advisory – AContent Multiple Vulnerabilities

Read More
IndependentSecuriteam

SSD Advisory – Xiaomi Air Purifier 2 Firmware Update Process Vulnerability

Credit to Author: SSD / Maor Schwartz| Date: Sun, 14 May 2017 13:06:52 +0000

Vulnerability Summary The following advisory describes an Firmware Update Process Vulnerability found in Xiaomi Air Purifier 2. Mi Air Purifier is a High performance smart air purifier (IoT) that can be controlled remotely. According to the manufacture (Xiaomi) “Monitor your home air quality in real time from absolutely anywhere when you sync with the Mi … Continue reading SSD Advisory – Xiaomi Air Purifier 2 Firmware Update Process Vulnerability

Read More
IndependentSecuriteam

SSD Advisory – Cisco DPC3928 Router Arbitrary File Disclosure

Credit to Author: SSD / Maor Schwartz| Date: Wed, 10 May 2017 07:43:17 +0000

Vulnerability Summary The following advisory describes an arbitrary file disclosure vulnerability found in Cisco DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway. The Cisco DPC3928AD DOCSIS is a home wireless router that is currently "Out of support" but is provided by ISPs world wide. Credit An independent security researcher has reported this vulnerability to Beyond Security’s SecuriTeam … Continue reading SSD Advisory – Cisco DPC3928 Router Arbitrary File Disclosure

Read More
IndependentSecuriteam

SSD Advisory – TerraMaster Operating System (TOS) File Disclosure

Credit to Author: SSD / Maor Schwartz| Date: Sun, 07 May 2017 00:33:00 +0000

Vulnerability Summary The following advisory describes a File Disclosure vulnerability found in TerraMaster Operating System (TOS) version 3. TerraMaster Operating System, TOS is a Linux platform-based operating system developed for TerraMaster cloud storage NAS server. TOS 3 is the third generation operating system newly launched. Credit An independent security researcher has reported this vulnerability to … Continue reading SSD Advisory – TerraMaster Operating System (TOS) File Disclosure

Read More
IndependentSecuriteam

Know your community – @unixfreaxjp, founder and team leader of MalwareMustDie

Credit to Author: Maor Schwartz| Date: Thu, 04 May 2017 08:56:45 +0000

Every once in a while you hear on the news that cyber criminals were arrested, today I have the honor to interview the man who put them behind bars! Please meet @unixfreaxjp, founder and team leader of MalwareMustDie, NPO (malwaremustdie.org) and Kendo master (3rd Dan). Disclaimer: A lot of criminals are looking for him, so … Continue reading Know your community – @unixfreaxjp, founder and team leader of MalwareMustDie

Read More
IndependentSecuriteam

SSD Advisory – WordPress Unauthorized Password Reset

Credit to Author: Maor Schwartz| Date: Wed, 03 May 2017 13:09:31 +0000

Vulnerability Summary The following advisory describe Unauthorized Password Reset vulnerability found in WordPress version 4.3.1. WordPress is web software you can use to create a beautiful website or blog. We like to say that WordPress is both free and priceless at the same time. The core software is built by hundreds of community volunteers, and … Continue reading SSD Advisory – WordPress Unauthorized Password Reset

Read More