SSD Advisory – IBM Informix Dynamic Server and Informix Open Admin Tool Multiple Vulnerabilities

Credit to Author: SSD / Maor Schwartz| Date: Tue, 23 May 2017 06:41:53 +0000

Vulnerabilities Summary The following advisory describes six (6) vulnerabilities found in Informix Dynamic Server and Informix Open Admin Tool. IBM Informix Dynamic Server Exceptional, low maintenance online transaction processing (OLTP) data server for enterprise and workgroup computing. IBM Informix Dynamic Server has many features that cater to a variety of user groups, including developers and … Continue reading SSD Advisory – IBM Informix Dynamic Server and Informix Open Admin Tool Multiple Vulnerabilities

Read more

SSD Advisory – Synology DiskStation Manager Multiple Stored Cross-Site Scripting

Credit to Author: SSD / Maor Schwartz| Date: Sun, 21 May 2017 15:17:30 +0000

Vulnerabilities Summary The following advisory describe two (2) stored Cross-Site Scripting (XSS) found in Synology DiskStation Manager (DSM). Cross-site scripting stored in SWF file Cross-site scripting stored in Video Station application Synology DiskStation Manager (DSM), a Linux based software package that is the operating system for the DiskStation and RackStation products. The Synology DSM is … Continue reading SSD Advisory – Synology DiskStation Manager Multiple Stored Cross-Site Scripting

Read more

SSD Advisory – Bitdefender Code Signing organizationName Buffer Overflow

Credit to Author: SSD / Maor Schwartz| Date: Thu, 18 May 2017 05:34:17 +0000

Vulnerability Summary The following advisory describes a Buffer Overflow vulnerability found in Bitdefender Engine PE. Bitdefender provides the Bitdefender “antimalware” engine for integration with other security vendors products. The engine is used in Bitdefender’s own products, for example in Bitdefender Internet Security 2017 and below. The antimalware engine is the core of the product, among … Continue reading SSD Advisory – Bitdefender Code Signing organizationName Buffer Overflow

Read more

Know your community – Simone Margaritelli (@evilsocket)

Credit to Author: SSD / Maor Schwartz| Date: Tue, 16 May 2017 11:57:33 +0000

The guy that published a first hand account of how an allegedly government-sponsored firm, Dark Matter, tried to hire him to help them spy on civilian in the UAE. A former BlackHat that switch sides Bug Bounty hunter The author of the most known offensive open source software – BetterCAP, dSploit, AndroSwat and more! Please … Continue reading Know your community – Simone Margaritelli (@evilsocket)

Read more

SSD Advisory – AContent Multiple Vulnerabilities

Credit to Author: SSD / Maor Schwartz| Date: Tue, 16 May 2017 05:32:18 +0000

Vulnerabilities Summary The following advisory describes two (2) vulnerabilities types found in AContent version 1.3. AContent is an open source learning content management system (LCMS) used to create interoperable, accessible, adaptive Web-based learning content. It can be used along with learning management systems to develop, share, and archive learning materials. For those familiar with ATutor, … Continue reading SSD Advisory – AContent Multiple Vulnerabilities

Read more

SSD Advisory – Xiaomi Air Purifier 2 Firmware Update Process Vulnerability

Credit to Author: SSD / Maor Schwartz| Date: Sun, 14 May 2017 13:06:52 +0000

Vulnerability Summary The following advisory describes an Firmware Update Process Vulnerability found in Xiaomi Air Purifier 2. Mi Air Purifier is a High performance smart air purifier (IoT) that can be controlled remotely. According to the manufacture (Xiaomi) “Monitor your home air quality in real time from absolutely anywhere when you sync with the Mi … Continue reading SSD Advisory – Xiaomi Air Purifier 2 Firmware Update Process Vulnerability

Read more

SSD Advisory – Cisco DPC3928 Router Arbitrary File Disclosure

Credit to Author: SSD / Maor Schwartz| Date: Wed, 10 May 2017 07:43:17 +0000

Vulnerability Summary The following advisory describes an arbitrary file disclosure vulnerability found in Cisco DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway. The Cisco DPC3928AD DOCSIS is a home wireless router that is currently "Out of support" but is provided by ISPs world wide. Credit An independent security researcher has reported this vulnerability to Beyond Security’s SecuriTeam … Continue reading SSD Advisory – Cisco DPC3928 Router Arbitrary File Disclosure

Read more

SSD Advisory – TerraMaster Operating System (TOS) File Disclosure

Credit to Author: SSD / Maor Schwartz| Date: Sun, 07 May 2017 00:33:00 +0000

Vulnerability Summary The following advisory describes a File Disclosure vulnerability found in TerraMaster Operating System (TOS) version 3. TerraMaster Operating System, TOS is a Linux platform-based operating system developed for TerraMaster cloud storage NAS server. TOS 3 is the third generation operating system newly launched. Credit An independent security researcher has reported this vulnerability to … Continue reading SSD Advisory – TerraMaster Operating System (TOS) File Disclosure

Read more