by Bill Sempf
30. June 2019 09:46
Fascinating look into Internet routing that caused an outage last week. We are really building this city on a bed of sticks.
https://blog.cloudflare.com/how-verizon-and-a-bgp-optimizer-knocked-large-parts-of-the-internet-offline-today/
Not my normal fare for this newsletter, but Microsoft added a secure vault to OneDrive. Not in the US yes, but my Australian friends can give it a try.
https://www.windowscentral.com/microsoft-announces-onedrive-personal-vault-secure-area-within-your-onedrive
There is a directory traversal vulnerability in ... this blog! Please don't hack my. I'll update later today.
https://seclists.org/fulldisclosure/2019/Jun/44
MongoDB is adding field level encryption. Now if folks would just use the authentication features ...
https://www.wired.com/story/field-level-encryption-databases-mongobd/
Found a VERY cool tool that lists known vulnerabilities in default containers.
https://vulnerablecontainers.org/
A weird enge case forces the npm deployment script to push the .git folder. Remember, complexity is the enemy of security.
https://npm.community/t/npm-6-9-1-is-broken-due-to-git-folder-in-published-tarball/8454/2
And that's the news folks.
ace2fb39-8ff5-40cb-84a6-1f9a33b97963|0|.0|96d5b379-7e1d-4dac-a6ba-1e50db561b04
Tags:
AppSec
by Bill Sempf
23. June 2019 14:03
Google has decided that the API that underpins the Chrome extension kit is too powerful - and they aren't wrong. But the changes appear to be killing adblockers. Strange, that.
https://www.theregister.co.uk/2019/06/17/chrome_extensions_security/
No, you aren't reading an old edition of this newsletter. There really is another Orable Weblogic deserialization bug.
https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2729-5570780.html
https://www.theregister.co.uk/2019/06/19/oracle_weblogic_emergency/
Good writeup on the current state of 2 factor authorization.
https://blog.trailofbits.com/2019/06/20/getting-2fa-right-in-2019/
That's the news, folks.
630de077-3291-4457-85c9-cba06f59ba47|0|.0|96d5b379-7e1d-4dac-a6ba-1e50db561b04
Tags:
by Bill Sempf
16. June 2019 19:34
f5a21139-8009-4ef5-b485-16653cf0a888|0|.0|96d5b379-7e1d-4dac-a6ba-1e50db561b04
Tags:
by Bill Sempf
2. June 2019 10:09
Accidentally Took Memorial Day Weekend Off Edition
New tool: FinalRecon- OSINT Tool For All-In-One Web Reconnaissance
https://blog.hackersonlineclub.com/2019/05/finalrecon-osint-tool-for-all-in-one.html?m=1
Permanent URL Hijack Through 301 HTTP Redirect Cache Poisoning
https://blog.duszynski.eu/domain-hijack-through-http-301-cache-poisoning/
Didier Stevens, one of my favorite researchers, mentioned that one of his readers has made a docker container with all of his tools.
https://blog.didierstevens.com/2019/05/27/dssuite-a-docker-container-with-my-tools/
There is a POC for CVE-2019-0708. Certainly is worth a look.
https://github.com/Ekultek/BlueKeep
Speaking of Docker, there is a bug that allows a hypervisor jump.
https://duo.com/decipher/docker-bug-allows-root-access-to-host-file-system
https://nakedsecurity.sophos.com/2019/05/31/unpatched-docker-bug-allows-read-write-access-to-host-os/
Finally, the always-wonderful folks at Portswigger have a cool analysis of Behavioral Fuzzing.
https://portswigger.net/blog/provoking-browser-quirks-with-behavioural-fuzzing
And that's the news! Have a great week.
9b5fb343-612e-4faf-8e07-fc72c555e1aa|0|.0|96d5b379-7e1d-4dac-a6ba-1e50db561b04
Tags: