Our web Application is going to live next month!! We can't afford any security issues after launch.

e-Securitylabs's application security assessments will provide you with an objective review and analysis, ultimately providing you with the assurance that your critical application can withstand common Internet and internal threats.

I need to know the bottom line. Can someone break into my mobile!!!

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

We got hacked. Is there anyone who can help us in this situation???

e-Securitylabs helps in finding the real root cause of the issue as well as ensures that it will not happen again.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Showing posts with label Patch. Show all posts
Showing posts with label Patch. Show all posts

Tuesday, 6 August 2024

Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution vulnerability

Severity: Zero day

Date of Publish: 06,Aug'24

Affected System:

Apache OFBiz: through 18.12.14

Summary

Apache OFBiz open-source enterprise resource planning ERP Allows Remote Code Execution vulnerability

Description

a zero-day pre-authentication remote code execution vulnerability was  identified  in the Apache OFBiz open-source enterprise resource planning (ERP) system that could allow remote attacker to execute arbitrary code in the affected systems..

Recommendations /Solutions

upgrade to version 18.12.15

 

Vendor Reference:

https://issues.apache.org/jira/browse/OFBIZ-13128
https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w
https://ofbiz.apache.org/download.html
https://ofbiz.apache.org/security.html

 

CVE:

CVE-2024-38856


NOTE : The information is provide is on “as is “ basis, without assurance of any kind .

 Revision history

1. 06-Aug-24 - First advisory released. ---update -update version avaible

 

Saturday, 20 July 2024

Windows Crashes Due to Crowdstrike Updates

Windows Crashes Due to Crowdstrike Updates

Date of Publish : July 20,2024

Severity-Critical

System Affected

  • Windows hosts

Non Affected systems

  • MacOS
  • Linux system

Summary

Crowdstrike released an update that is causing widespread "blue screens of death" (BSOD) on Windows systems.

Description,

This situation occur may be by sending a phishing emails circulating claiming come from "Crowdstrike Support" or "Crowdstrike Security" to update the component. One domain possibly associated with these phishing attacks is : crowdfalcon-immed-update [ .] com .once copned and download it will cause BSOD attack.

Workaround steps for individual hosts:

  • Reboot the host to give it an opportunity to download the reverted channel file. We strongly recommend putting the host on a wired network (as opposed to WiFi) prior to rebooting as the host will acquire internet connectivity considerably faster via ethernet.
  • If the host crashes again, then:
    • Boot Windows into Safe Mode or the Windows Recovery Environment
      • NOTE: Putting the host on a wired network (as opposed to WiFi) and using Safe Mode with Networking can help remediation.
    • Navigate to the %WINDIR%\System32\drivers\CrowdStrike directory
      • Windows Recovery defaults to X:\windows\system32
        • Navigate to the appropriate partition first (default is C:\), and navigate to the crowdstrike directory:
          • C:
          • cd windows\system32\drivers\crowdstrike
      • Note: On WinRE/WinPE, navigate to the Windows\System32\drivers\CrowdStrike directory of the OS volume
    • Locate the file matching “C-00000291*.sys” and delete it.
      • Do not delete or change any other files or folders
    • Cold Boot the host
      • Shutdown the host.
      • Start host from the off state.

Note: BitLocker-encrypted hosts may require a recovery key

References.

Vendor Reference.

https://www.crowdstrike.com/blog/statement-on-windows-sensor-update/.

NOTE : The information is provide is on “as is “ basis, without assurance of any kind .

Revision history

1. 19-Jun-24 - First advisory released. ---update -workaround available 

Thursday, 20 June 2024

Multiple remote code execution in VMWare products

Multiple remote code execution in VMWare products.

Date of Publish: June 20,24

Severity:Critical

Affected Software:

  • VMware vCenter Server
  • VMware Cloud Foundation

Summary:

Multiple remote code execution vulnerabilities in VMware products  which can allow attacket to take over the contrl of the affected systems.

Description:

The list of vulnerabilities is as follows -

  • CVE-2024-37079 & CVE-2024-37080- Multiple heap-overflow vulnerabilities in the implementation of the DCE/RPC protocol that could allow a,n attacker with network access to vCenter Server can do remote code execution by sending a specially crafted network packet
  • CVE-2024-37081 - Multiple local privilege escalation vulnerabilities in VMware vCenter arising due to the misconfiguration of ("sudo") that an authenticated local user with non-administrative privileges could exploit to obtain root permissions.

Impacted CVE:

CVE-2024-37079
CVE-2024-37080
CVE-2024-37081

 Solution:

https://core.vmware.com/resource/vmsa-2024-0012-questions-answers#introduction

 

Vendor reference:

https://core.vmware.com/resource/vmsa-2024-0012-questions-answers#introduction

Broadcom:

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 

 

NOTE : The information is provide is on “as is “ basis, without assurance of any kind 

Tuesday, 30 April 2024

Palo Alto Networks under attack-zero-day attack

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

 

Affected version:

  • PAN-OS 11.1    < 11.1.0-h3,< 11.1.1-h1, < 11.1.2-h3                               
  • PAN-OS 11.0    < 11.0.0-h3,< 11.0.1-h4, < 11.0.2-h4, < 11.0.3-h10, < 11.0.4-h1    
  • PAN-OS 10.2    < 10.2.0-h3,< 10.2.1-h2, < 10.2.2-h5, < 10.2.3-h13, < 10.2.4-h16, < 10.2.5-h6, < 10.2.6-h3, < 10.2.7-h8, < 10.2.8-h3, < 10.2.9-h1

Summary

This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls configured with GlobalProtect gateway or GlobalProtect portal (or both). Device telemetry does not need to be enabled for PAN-OS firewalls to be exposed to attacks related to this vulnerability.

You can verify whether you have a GlobalProtect gateway or GlobalProtect portal configured by checking for entries in your firewall web interface (Network > GlobalProtect > Gateways or Network > GlobalProtect > Portals).

Solution

It is recommended to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied.

issue is fixed in PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. These fixes and those listed below completely prevent the initial remote command execution, stopping subsequent post-exploitation or persistence.

In addition, to provide the most seamless upgrade path for customers, additional hotfixes have been made available as a courtesy for other commonly deployed maintenance releases.

Workarounds and Mitigations

it is suggested to use Threat Prevention subscription can block attacks for this vulnerability using Threat IDs 95187, 95189, and 95191 (available in Applications and Threats content version 8836-8695 and later). Please monitor this advisory and new Threat Prevention content updates for additional Threat Prevention IDs around CVE-2024-3400.

To apply the Threat IDs, customers must ensure that vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device. Please see https://live.paloaltonetworks.com/t5/globalprotect-articles/applying-vulnerability-protection-to-globalprotect-interfaces/ta-p/340184 for more information.

Reference :

Palo alto Networks

https://security.paloaltonetworks.com/CVE-2024-3400


NOTE : The information is provide is on “as is “ basis, without assurance of any kind.

 

 

 

 

 

Friday, 3 August 2012

Opera Security Patch Released

Opera released version 12.01 which contains some recommended security updates. Information regarding security and stability enhancements for the various version are available here: Windows changelog, Mac changelog, Unix changelog.

http://www.opera.com/docs/changelogs/windows/1201/
http://www.opera.com/docs/changelogs/mac/1201/
http://www.opera.com/docs/changelogs/unix/1201/
https://ssl.opera.com:8062/desktopteam/blog/2012/08/01/opera-12-01-security-and-stability-release

Reference:
http://www.dshield.org/diary/Opera+Security+Update/13825

Thursday, 19 July 2012

Critical Unpatched Oracle Vulnerability


Critical Patch Update for oracle listed a vulnerability in the TNS Listener services as one of the patched vulnerabilities. It turns out that current versions of Oracle are not patched. Instead, the vulnerability will apparently only be fixed in future versions of the Oracle database. According to a statement from Oracle quoted by the discoverer of the vulnerability, the fix would have possible had stability issues for current versions of Oracle.

The vulnerability was responsibly reported to Oracle back in 2008. Upon release of the April CPU, Joxean Koret, who originally found the vulnerability, came forward with additional details including a proof of concept exploit, fully expecting that a patch is now available.

Reference:
http://isc.sans.edu/diary.html?storyid=13069

Wednesday, 18 July 2012

Oracle July 2012 Critical Patch Pre-Release update

Oracle is to release 88 new security vulnerability fixes On Tuesday, July 17, 2012 for multiple Oracle products. Some of the vulnerabilities addressed in this Critical Patch Update affect multiple products.The pre-announcement list of affected product is posted here.
References
http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html

Monday, 9 July 2012

Microsoft's XML 0-day fix expected in July Patch

Microsoft is planning to release nine bulletins, three critical, as part of the July edition of its Patch Tuesday monthly update cycle.

One of the three crucial advisories is expected* to offer patches for a serious XML Core Services vulnerability, disclosed but not fixed in June’s Patch Tuesday. This vulnerability has been actively exploited in attacks over recent weeks. The other two crucial bulletins cover unspecified problems in Internet Explorer and Windows

Friday, 6 July 2012

Microsoft advanced notification for July 2012

Microsoft have released the advanced notification for the upcoming July 2012 patch Tuesday and reboot Wednesday extravaganza. There are 16 vulnerabilities to be addressed in 9 bulletins. 3 of the bulletins are rated as critical, the remaining 6 as important. The notification is here:

http://blogs.technet.com/b/msrc/archive/2012/07/05/advance-notification-service-for-july-2012-security-bulletin-release.aspx