Latest YouTube Video

Monday, April 9, 2018

Here's how hackers are targeting Cisco Network Switches in Russia and Iran

Since last week, a new hacking group, calling itself 'JHT,' hijacked a significant number of Cisco devices belonging to organizations in Russia and Iran, and left a message that reads—"Do not mess with our elections" with an American flag (in ASCII art). MJ Azari Jahromi, Iranian Communication and Information Technology Minister, said the campaign impacted approximately 3,500 network switches


from The Hacker News https://ift.tt/2GMAMiT
via IFTTT

[FD] [RT-SA-2017-015] CyberArk Password Vault Memory Disclosure

Advisory: CyberArk Password Vault Memory Disclosure Data in the CyberArk Password Vault may be accessed through a proprietary network protocol. While answering to a client's logon request, the vault discloses around 50 bytes of its memory to the client. Details ======= Product: CyberArk Password Vault Affected Versions: < 9.7, < 10 Fixed Versions: 9.7, 10 Vulnerability Type: Information Disclosure Security Risk: high Vendor URL: https://www.cyberark.com/ Vendor Status: fixed version released Advisory URL: https://www.redteam-pentesting.de/advisories/rt-sa-2017-015 Advisory Status: published CVE: CVE-2018-9842 CVE URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9842 Introduction ============ "CyberArk Enterprise Password Vault is designed to secure, rotate and control access to privileged account credentials based on organizational policies. A flexible architecture allows organizations to start small and scale to the largest, most complex IT environments. The solution protects privileged account credentials used to access the vast majority of systems." (from the Enterprise Password Vault Data Sheet [1]) More Details ============ The CyberArk Password Vault serves as a database to securely store credentials. Furthermore, the vault enforces access controls and logs access to its records. Data stored in the vault may be accessed through a proprietary network protocol which is usually transmitted over TCP port 1858. Various clients, such as web applications or command line tools, are provided by CyberArk to interface with a vault. The first message a client sends to the vault is a "Logon" command. Using a network sniffer, such a message was captured: $ xxd logon.bin 00000000: ffff ffff f700 0000 ffff ffff 3d01 0000 ............=... 00000010: 5061 636c 6953 6372 6970 7455 7365 7200 PacliScriptUser. 00000020: 0000 0000 0000 0000 0000 0000 0000 0000 ................ 00000030: 0000 0000 0000 0000 0000 0000 0000 0000 ................ 00000040: 0000 0000 0000 0000 0000 0000 0000 0000 ................ 00000050: 0000 0000 0000 0000 0000 0000 0000 0000 ................ 00000060: 0000 0000 0000 0000 0000 0000 0020 2020 ............. 00000070: 20ff ffff ff00 0000 0000 0000 0000 0073 ..............s 00000080: 0000 00ce cece ce00 0000 0000 0000 0000 ................ 00000090: 0000 0000 0000 0030 3d4c 6f67 6f6e fd31 .......0=Logon.1 000000a0: 3135 3d37 2e32 302e 3930 2e32 38fd 3639 15=7.20.90.28.69 000000b0: 3d50 fd31 3136 3d30 fd31 3030 3dfd 3231 =P.116=0.100=.21 000000c0: 373d 59fd 3231 383d 5041 434c 49fd 3231 7=Y.218=PACLI.21 000000d0: 393d fd33 3137 3d30 fd33 3537 3d30 fd32 9=.317=0.357=0.2 000000e0: 323d 5061 636c 6953 6372 6970 7455 7365 2=PacliScriptUse 000000f0: 72fd 3336 373d 3330 fd00 00 r.367=30... Starting at offset 0x97, a type of remote procedure call can be identified. In this case, "Logon" is invoked for the user "PacliScriptUser". This message does not contain any random, unpredictable data. Therefore, it may be replayed at will once captured. This can be accomplished using netcat:

Source: Gmail -> IFTTT-> Blogger

[FD] [RT-SA-2017-014] CyberArk Password Vault Web Access Remote Code Execution

Advisory: CyberArk Password Vault Web Access Remote Code Execution The CyberArk Password Vault Web Access application uses authentication tokens which consist of serialized .NET objects. By crafting manipulated tokens, attackers are able to gain unauthenticated remote code execution on the web server. Details ======= Product: CyberArk Password Vault Web Access Affected Versions: < 9.9.5, < 9.10, 10.1 Fixed Versions: 9.9.5, 9.10, 10.2 Vulnerability Type: Remote Code Execution Security Risk: high Vendor URL: https://www.cyberark.com/ Vendor Status: fixed version released Advisory URL: https://www.redteam-pentesting.de/advisories/rt-sa-2017-014 Advisory Status: published CVE: CVE-2018-9843 CVE URL: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9843 Introduction ============ "CyberArk Enterprise Password Vault is designed to secure, rotate and control access to privileged account credentials based on organizational policies. A flexible architecture allows organizations to start small and scale to the largest, most complex IT environments. The solution protects privileged account credentials used to access the vast majority of systems." (from the Enterprise Password Vault Data Sheet [1]) More Details ============ The CyberArk Password Vault provides secure storage for credentials. It may be accessed through various clients which are also provided by CyberArk. One such client is the CyberArk Password Vault Web Access, a .NET web application. After logging into the web application with their credentials, users may access credentials kept in the vault. Additionally, CyberArk Password Vault Web Access provides a REST API for programmatic access to the vault. This API is available at an URL similar to the following: https://10.0.0.6/PasswordVault/WebServices/ The API provides multiple endpoints with different methods. Most methods provided by the API require prior authentication. Consequently, a user's API call must include an authentication token in an HTTP authorization header. Tokens may be generated by calling a dedicated "Logon" API method. Analysis of this token by RedTeam Pentesting revealed, that it consists of a base64 encoded, serialized .NET object of the type "CyberArk.Services.Web.SessionIdentifiers". This class consists of four string attributes which hold information about a user's session. The integrity of the serialized data is not protected. Therefore, attackers may send arbitrary .NET objects to the API in the authorization header. By leveraging certain gadgets, such as the ones provided by ysoserial.net [2], attackers may execute arbitrary code in the context of the web application. Proof of Concept ================ First, a malicious serialized .NET object is created. Here the "TypeConfuseDelegate" gadget of ysoserial.net is used to execute the "ping" command:

Source: Gmail -> IFTTT-> Blogger

The Sun Unleashed: Monster Filament in Ultraviolet


One of the most spectacular solar sights is an explosive flare. In 2011 June, the Sun unleashed somewhat impressive, medium-sized solar flare as rotation carried active regions of sunpots toward the solar limb. That flare, though, was followed by an astounding gush of magnetized plasma -- a monster filament seen erupting at the Sun's edge in this extreme ultraviolet image from NASA's Solar Dynamics Observatory. Featured here is a time-lapse video of that hours-long event showing darker, cooler plasma raining down across a broad area of the Sun's surface, arcing along otherwise invisible magnetic field lines. An associated coronal mass ejection, a massive cloud of high energy particles, was blasted in the general direction of the Earth,and made a glancing blow to Earth's magnetosphere. via NASA https://ift.tt/2qiokjX

Sunday, April 8, 2018

NGC 6960: The Witchs Broom Nebula


Ten thousand years ago, before the dawn of recorded human history, a new light would have suddenly have appeared in the night sky and faded after a few weeks. Today we know this light was from a supernova, or exploding star, and record the expanding debris cloud as the Veil Nebula, a supernova remnant. This sharp telescopic view is centered on a western segment of the Veil Nebula cataloged as NGC 6960 but less formally known as the Witch's Broom Nebula. Blasted out in the cataclysmic explosion, the interstellar shock wave plows through space sweeping up and exciting interstellar material. Imaged with narrow band filters, the glowing filaments are like long ripples in a sheet seen almost edge on, remarkably well separated into atomic hydrogen (red) and oxygen (blue-green) gas. The complete supernova remnant lies about 1400 light-years away towards the constellation Cygnus. This Witch's Broom actually spans about 35 light-years. The bright star in the frame is 52 Cygni, visible with the unaided eye from a dark location but unrelated to the ancient supernova remnant. via NASA https://ift.tt/2HgwHV1