Triad Square Infosec Pvt.Ltd

Triad Square Infosec Pvt.Ltd Information security company providing quality services of Consulting, Information security & IT Training and Talent acquisition in Bangalore

We are an Information Security company headquartered in Bangalore with highly qualified skilled of experience & expertise people. We provide technology solutions, professional services and consultation in the Information Security domain. Our unique blend of Security Expertise enables us to give our customers most practical solutions to their problems. We provide three vertical services to our cust

omers.

>Information Security Consulting.
>Information Security Training.
>Staff Augmentation Services

13/02/2020

**Urgent update for windows 99 Vulnerabilitys**

There are 12 critical and five previously disclosed bugs in the February 2020 Patch Tuesday Update.

Microsoft has issued one of its largest Patch Tuesday updates for the shortest month of the year, addressing 99 security vulnerabilities across a range of products. Twelve of the bugs are listed as critical – and the rest are rated as being important.

The update includes a patch for the zero-day memory-corruption vulnerability disclosed in late January that’s under active attack. The bug tracked as CVE-2020-0674 is a critical flaw for most Internet Explorer versions, allowing remote code-ex*****on and complete takeover.

“This browser bug impacts IE and the other programs that rely on the Trident rendering engine,” explained Dustin Childs, researcher with Trend Micro’s Zero Day Initiative, in his Patch Tuesday analysis. “Attackers can execute code on affected systems if a user browses to a specially crafted website. Even if you don’t use IE, you could still be affected by this bug though embedded objects in Office documents. Considering the listed workaround – disabling jscript.dll – breaks a fair amount of functionality, you should prioritize the testing and deployment of this patch.”

Also of note: February 2020 marks the first security updates for the new Edge Chromium browser edition. There were 41 vulnerabilities fixed in the Chromium-based Edge version that were technically not part of Patch Tuesday – which brings the total number of bugs fixed by Microsoft this week to 140.

Critical Patches for February 2020
The update includes a wealth of “standout” bugs, according to researcher analyses, including several critical vulnerabilities in addition to the zero day.

According to Jay Goodman, technical marketing manager at Automox, bugs to watch include CVE-2020-0618 and CVE-2020-0662 (only the latter is listed as critical), which are nearly identical remote code-ex*****on (RCE) bugs in SQL Server 2012, 2014 and 2016 (32 and 64 bit) and Windows 7, 8.1, 10, Server 2008, 2012, 2016 and 2019, respectively.

“These vulnerabilities allow attackers to access a system and read or delete contents, make changes or directly run code on the system,” he said via email. “This gives an attacker quick and easy access to not only your organization’s most critical data stored in the SQL server but also a platform to perform additional malicious attacks against other devices in your environment.”

The critical bug can lead to RCE if an attacker has Domain User credentials, according to Jimmy Graham, researcher with Qualys.

“While this vulnerability is labeled as ‘exploitation less likely,’ this vulnerability can be attacked over the network with no user interaction according to the CVSS Vector Strings set by Microsoft,” he explained in an analysis. “The impacted service is not stated in the bulletin. Based on the information given, this should be prioritized across all Windows servers and workstations.”

Additionally, two critical remote code-ex*****on vulnerabilities in Remote Desktop (CVE-2020-0681 and CVE-2020-0734) were patched, and are likely to be exploited, according to Microsoft.

“Exploitation of these requires an attacker to either persuade their victim into connecting to a vulnerable Remote Desktop Server operated by the attacker, or plant malicious code on a compromised Remote Desktop Server and wait for the vulnerable user to connect to it,” Satnam Narang, senior research engineer at Tenable, explained via email.

Richard Tsang, senior software engineer at Rapid7, told Threatpost that CVE-2020-0734 is a critical Windows Remote Desktop Client vulnerability that exists in how connection requests are handled.

“The stream of Windows Remote Desktop vulnerabilities continues, albeit having slowed down,” he said. “In this scenario, a compromised legitimate server (or a malicious server) can be used to trigger the remote code ex*****on. Given the extra eyes on RDP vulnerabilities of late, prioritizing operating system patches on this front would be a prudent move.”

One other critical bug to note is CVE-2020-0729, a .LNK RCE vulnerability, which Childs said is similar to the bug that was exploited by the Stuxnet malware. Stuxnet was used to take out Iranian nuclear enrichment facilities in 2012. The new bug can also be used to attack air-gapped “secure” systems, he said, by exploiting shortcut .LNK files.

“Bugs impacting link files (.LNK) never fail to amaze me,” said Childs. “An attacker could use this vulnerability to get code ex*****on by having an affected system process a specially crafted .LNK file. This could be done by convincing a user to open a remote share, or – as has been seen in the past – placing the .LNK file on a USB drive and having the user open it. It’s a handy way to exploit an air-gapped system.”

The other critical bugs fixed by Microsoft in February are CVE-2020-0738, a Media Foundation Memory Corruption Vulnerability allowing RCE; and several Scripting Engine Memory Corruption Vulnerabilities allowing RCE. This latter group includes CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0673 and CVE-2020-0767.

Important-Rated Patches
As for the important-rated patches, the volume of elevation-of-privilege (EoP) bugs being patched is “somewhat staggering,” ZDI’s Childs noted, with 55 patches in all. Also, information-disclosure bugs are well-represented, with 16 patches in February, including a publicly known bug (CVE-2020-0706) impacting IE and Edge. Childs said that six of them exist in the Cryptography Next Generation (CNG) portion of the Windows Key Isolation service.

Childs also flagged CVE-2020-0688, a memory-corruption bug in Microsoft Exchange, which could be trivially exploited to grant an attacker the ability to create a new account, install programs, and view, change or delete data.

“This code-ex*****on bug in Exchange is only listed as important, but you should treat it as a critical-rated vulnerability,” he said. “An attacker could gain code ex*****on on affected Exchange servers by sending a specially crafted email. No other user interaction is required. The code ex*****on occurs at System-level permissions, so the attacker could completely take control of an Exchange server through a single email.”

Racing Against Exploitation
Microsoft’s February update is the largest in quite some time, researchers said, with flaws disclosed for Windows, Edge (EdgeHTML-based), ChakraCore, Internet Explorer (IE), SQL Server, Exchange Server, Office, Office Services and Web Apps, Azure DevOps Server, Team Foundation Server and the Microsoft Malware Protection Engine.

And, five of the CVEs (including the previously mentioned zero day and the info-disclosure bug affecting browsers) have been publicly disclosed — and thus offer a threat actors a head start on exploitation.

“Overall, this is a very heavy Patch Tuesday on the Microsoft end. The race to patch critical vulnerabilities on your systems within the next 72 hours is on,” Goodman advised. “Attackers will have no shortage of exploitable vulnerabilities and new attack vectors to bring to bear in the coming days with nearly every build of Windows accounted for with critical vulnerabilities.”

Also, for the first time, Microsoft is not updating Windows 7 this month.

“Today is a significant Patch Tuesday, marking the first time there will be no patches for Windows 7,” Rui Lopes, engineering and technical support director at Panda Security, told Threatpost. “However, that doesn’t mean there aren’t vulnerabilities. In fact, today’s release features several critical and zero-day patches to be deployed, so any machines still running Windows 7 are now, by default, exceptionally vulnerable—providing open doors for hackers to walk through and exploit. Therefore, if you have any devices running Windows 7, it is top priority to update them immediately.”

The good news, according to Todd Schell, senior product manager for security at Ivanti, is that most of the CVEs can be resolved by applying just a few Microsoft updates.

“On average, your OS updates will resolve around 50 CVEs,” he explained, via email. “The normal updates still apply. OS, browsers, and Office will resolve most of your vulnerabilities from the Microsoft side. SQL and Exchange Admins do get a bit of extra work this month as both of those products are included in the updates released…[but with] a couple of patches per system you can take the teeth out of the majority of the risk this month.”

One vulnerability worth mentioning in this context this month is CVE-2020-0689, a security feature bypass that was also previously disclosed; an attacker could bypass secure boot and load untrusted software.

Both Childs and Tsang noted that while the vulnerability itself is not that interesting, what stands out is the fact that the remediation steps are different from the usual patching practices.

“Whereas most operating system-level vulnerabilities are bundled in either a Security-Only/Monthly Rollup or Cumulative Update stream, this fix is segregated out in separate KB patches that also have explicit Servicing Stack Update prerequisites,” Tsang said. “The idea that there’s a change in process, in itself, is something to note.”

Childs added, “While this is certainly a bug to scrutinize, it’s compounded by a non-standard patching process. This month’s servicing stack must first be applied, then additional standalone security updates need to be installed. If you have the Windows Defender Credential Guard (Virtual Secure Mode) enabled, you’ll need to go through two additional reboots as well. All this is needed to block impacted third-party bootloaders.”

This Flaw Could Have Allowed Hackers to Hack Any Instagram Account Within 10 Minutes
16/07/2019

This Flaw Could Have Allowed Hackers to Hack Any Instagram Account Within 10 Minutes

How a vulnerability in password recovery feature of vulnerability could have allowed hackers to hack any Instagram account

17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device
04/07/2019

17-Year-Old Weakness in Firefox Let HTML File Steal Other Files From Device

17-Year-Old Weakness in Firefox's Same Origin Policy for File URI Scheme Let HTML File Steal Other Files On the Device

 Google has started rolling out this month's security updates for its mobile operating system platform to address a tota...
03/07/2019



Google has started rolling out this month's security updates for its mobile operating system platform to address a total of 33 new security vulnerabilities affecting Android devices, 9 of which have been rated critical in severity.
The vulnerabilities affect various Android components, including the Android operating system, framework, library, media framework, as well as Qualcomm components, including closed-source components.
Three of the critical vulnerabilities patched this month reside in Android's Media framework, the most severe of which could allow a remote attacker to execute arbitrary code on a targeted device, within the context of a privileged process, by convincing users into opening a specially crafted malicious file.
"The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed," the company says.
Out of the remaining seven critical vulnerabilities, one affects Android Library, one affects the System, two resides in Qualcomm components (one in DSP_Services and one in Kernel), and three resides in Qualcomm closed-source components.
Besides this, a high-severity flaw (CVE-2019-2104) in the Android Framework could allow an installed malicious app to bypass user interaction requirements in an attempt to gain access to additional permissions.
Six high-severity vulnerabilities addressed in Qualcomm components resides in WLAN Host (CVE-2019-2276, CVE-2019-2307), WLAN Driver (CVE-2019-2305), HLOS (CVE-2019-2278), and Audio (CVE-2019-2326, CVE-2019-2328).
According to the Android security advisory, none of the flaws addressed this month were publicly disclosed or found being exploited in the wild.


Apart from releasing patches for security vulnerabilities, the Android Security Patch for July 2019 also includes fixes for various issues in some of the supported version of Pixel devices.
Pixel smartphone users will get the July updates shortly, while others will have to wait for their Android device manufacturers or service providers to roll out the security patches for their devices.
Users are strongly recommended to download the most recent Android security updates as soon as they are available in order to keep their Android devices protected against any potential attack.

Google Releases July 2019 Android Security Updates to Patch 33 New Vulnerabilities

PoC Released for Outlook Flaw that Microsoft Patched 6 Month After Discovery
25/06/2019

PoC Released for Outlook Flaw that Microsoft Patched 6 Month After Discovery

Researcher releases proof-of-concept for vulnerability in Outlook app for Android that Microsoft patched 6 month after discovery

    In recent years, several groups of cybersecurity researchers have disclosed dozens of memory side-channel vulnerabil...
23/06/2019






In recent years, several groups of cybersecurity researchers have disclosed dozens of memory side-channel vulnerabilities in modern processors and DRAMs, like Rowhammer, RAMBleed, Spectre, and Meltdown.
Have you ever noticed they all had at least one thing in common?
That's OpenSSH.
As a proof-of-concept, many researchers demonstrated their side-channel attacks against OpenSSH application installed on a targeted computer, where an unprivileged attacker-owned process exploits memory read vulnerabilities to steal secret SSH private keys from the restricted memory regions of the system.
That's possible because OpenSSH has an agent that keeps a copy of your SSH key in the memory so that you don't have to type your passphrase every time you want to connect to the same remote server.
However, modern operating systems by default store sensitive data, including encryption keys and passwords, in the kernel memory which can not be accessed by user-level privileged processes.
But since these SSH keys live on the RAM or CPU memory in plaintext format, the feature is susceptible to hacking attempts when the attacks involve memory read vulnerabilities.
OpenSSH Now Stores Only Encrypted Keys in the Memory
Here's good news — it's not the case anymore.
The latest update from the OpenSSH developers resolves this issue by introducing a new security feature that encrypts private keys before storing them into the system memory, protecting it against almost all types of side-channel attacks.


According to OpenSSH developer Damien Miller, a new patch to OpenSSH now "encrypts private keys when they are not in use with a symmetric key that is derived from a relatively large "prekey" consisting of random data (currently 16KB)."
"Attackers must recover the entire prekey with high accuracy before they can attempt to decrypt the shielded private key, but the current generation of attacks have bit error rates that, when applied cumulatively to the entire prekey, make this unlikely," Miller explains.
"Implementation-wise, keys are encrypted 'shielded' when loaded and then automatically and transparently unshielded when used for signatures or when being saved/serialized."
It should be noted that this patch just mitigates the threat and is not a permanent solution. Miller says OpenSSH will remove this protection against side-channel attacks in a few years when computer architecture becomes less unsafe.

OpenSSH Now Keeps Encrypted Keys in Memory to Protect Them Against Side-Channel Attacks

  —  Oracle has released an out-of-band emergency software update to patch a newly discovered critical vulnerability in ...
20/06/2019



Oracle has released an out-of-band emergency software update to patch a newly discovered critical vulnerability in the WebLogic Server.
According to Oracle, the vulnerability—which can be identified as CVE-2019-2729 and has a CVSS score of 9.8 out of 10—is already being exploited in the wild by an unnamed group of attackers.
Oracle WebLogic is a Java-based multi-tier enterprise application server that allows businesses to quickly deploy new products and services on the cloud, which is popular across both, cloud environment and conventional environments.
The reported vulnerability is a deserialization issue via XMLDecoder in Oracle WebLogic Server Web Services that could allow unauthorized remote attackers to execute arbitrary code on the targeted servers and take control over them.
"This remote code ex*****on vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password," the advisory said.
In a separate note, the company also revealed that the flaw is related to a previously known deserialization vulnerability (CVE-2019-2725) in Oracle WebLogic Server that it patched in April this year.
The previously patched RCE flaw in Oracle WebLogic was also exploited by attackers as a zero-day i.e., to distribute Sodinokibi ransomware and cryptocurrency mining malware.
Reported independently by a separate group of individuals and organizations, the new vulnerability affects Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0


Due to the severity of this vulnerability, the company has recommended affected users and companies to install available security updates as soon as possible.
Other Important Security Updates from Oracle
Besides this, Cisco today also released several other software updates for various of its products that to addresses some critical and high severity vulnerabilities.
Cisco TelePresence — a video conferencing system by Cisco, the software contains a high severity vulnerability that could allow remote attackers to execute arbitrary shell commands or scripts on the targeted device just by sending crafted CDP packets to an affected device.
Cisco SD-WAN Solution — The vManage web-based interface of the software-defined WAN solutions by Cisco contains three flaws, two of which have been rated high in severity, and one is critical. Two of these allow an attacker to elevate his privileges to the root user, whereas one flaw could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.
Cisco Router Management Interface — Cisco's RV110W, RV130W, and RV215W Routers contains a denial-of-service vulnerability that could allow an unauthenticated attacker to cause a reload of an affected device. Another flaw in this product affected by a medium severity issue that could expose the list of devices that are connected to the guest network to remote attackers.

Oracle has released security update to patch a critical deserialization vulnerability (CVE-2019-2729) in WebLogic servers

 If you use the Firefox web browser, you need to update it right now.Mozilla earlier today released Firefox 67.0.3 and F...
19/06/2019



If you use the Firefox web browser, you need to update it right now.
Mozilla earlier today released Firefox 67.0.3 and Firefox ESR 60.7.1 versions to patch a critical zero-day vulnerability in the browsing software that hackers have been found exploiting in the wild.
Discovered and reported by Samuel Groß, a cybersecurity researcher at Google Project Zero, the vulnerability could allow attackers to remotely execute arbitrary code on machines running vulnerable Firefox versions and take full control of them.


The vulnerability, identified as CVE-2019-11707, affects anyone who uses Firefox on desktop (Windows, macOS, and Linux) — whereas, Firefox for Android, iOS, and Amazon Fire TV are not affected.
According to an advisory, the flaw has been labelled as a type confusion vulnerability in Firefox that can result in an exploitable crash due to issues in Array.pop which can occur when manipulating JavaScript objects.
At the time of writing, neither the researcher nor Mozilla has yet released any further technical details or proof-of-concept for this flaw.
Through Firefox automatically installs latest updates and activate new version after a restart, users are still advised to ensure they are running the latest Firefox 67.0.3 and Firefox (Extended Support Release) 60.7.1 or later.

Firefox Releases Patch Update to Fix a Critical Flaw (CVE-2019-11707) and Stop Ongoing Zero-Day Attacks

Free Ethical Hacking workshop from 11AM to 1PM on 8th & 9th of this month. Call us for more details @ +917625096935 (Ava...
07/06/2019

Free Ethical Hacking workshop from 11AM to 1PM on 8th & 9th of this month. Call us for more details @ +917625096935 (Available in WhatsApp) or Send Message

07/06/2019
Microsoft Warned Second Time to Update Windows for Bluekeep RDP Flaw – Exploits Already Available in Hackers HandIts a s...
01/06/2019

Microsoft Warned Second Time to Update Windows for Bluekeep RDP Flaw – Exploits Already Available in Hackers Hand

Its a second time Microsoft urged users to update the recently patched Warmable BlueKeep Remote desktop protocol vulnerability due to the seriousness of this flaw let the hackers perform WannaCry level Attack.

Microsoft already warned first on May 14 when they released a patch for a critical Remote Code Ex*****on vulnerability, CVE-2019-0708.

We have reported about “Bluekeep vulnerability” earlier this week. Successful exploitation of this vulnerability, allows an attacker to execute arbitrary code on the windows machine and to install programs on the machine with elevated privileges.

Since the vulnerability is ‘wormable,’ that means, any future malware that exploits this vulnerability could propagate from vulnerable computer to another vulnerable computer.

“This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could then install programs; view, change, or delete data; or create new accounts with full user rights. ”

Microsoft strongly believes that the attackers already prepared an exploit for this RDP flaw, and soon they will start similarly attacking the vulnerable systems as the WannaCry malware spread across the globe in 2017.

A recent analysis revealed that more than one million PCs on the public internet are still vulnerable to wormable, BlueKeep RDP flaw.

Robert Graham conducted an RDP scan looking for port 3389 used by Remote Desktop to find the possible vulnerable machines. He discovered that 923,671 machines are still vulnerable.

McAfee, Kaspersky, Check Point, and MalwareTech created a Proof-of-Concept (PoC) that would use the CVE-2019-0708 vulnerability that could remotely execute the code on the victim’s machine.

Many Corporate networks are vulnerable
Microsoft also believes many of the corporate networks are still vulnerable, and they are more vulnerable than individual users since there are many systems connected in a single network.

By compromise the single system in a corporate network, an attacker could use it as a potential gateway and compromise the vulnerable computers in the entire network that connected with the internet across the enterprise.

Microsoft released a statement that says, This scenario could be even worse for those who have not kept their internal systems updated with the latest fixes, as any future malware may also attempt further exploitation of vulnerabilities that have already been fixed.

To keep this all the facts in mind, Microsoft strongly advise that all affected systems should be updated as soon as possible.

Mitigations
Block Remote Desktop Services if they are not in use.
Block TCP port 3389 at the Enterprise Perimeter Firewall.
Apply the patch to the vulnerable Machines that have RDP Enabled

Its a second time Microsoft urged users to update the recently patched Warmable BlueKeep Remote desktop protocol vulnerability

Address

#44, 2nd And 3rd Floor, 9th 'A' Main, Off 100 Ft. Road Indira Nagar First Stage
Bangalore
560038

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

+918088778600

Alerts

Be the first to know and let us send you an email when Triad Square Infosec Pvt.Ltd posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Triad Square Infosec Pvt.Ltd:

Share