from ESPN http://ift.tt/17lH5T2
via IFTTT
Latest YouTube Video
Monday, August 15, 2016
ISS Daily Summary Report – 08/12/2016
Synchronized Position Hold, Engage, Reorient, Experimental Satellites (SPHERES) Zero Robotics (ZR) Competition: A USOS and Russian crewmember set up the SPHERES hardware and executed the SPHERES Zero Robotics tests with participation from students on the ground. The investigation provides an opportunity for high school students to design research for the ISS. As part of a competition, students write algorithms for the SPHERES satellites to accomplish tasks relevant to future space missions. The algorithms are tested by the SPHERES team and the best designs are selected for the competition to operate the SPHERES satellites on board the ISS. Thermolab Deinstrumentation for Circadian Rhythms: The crew removed the double sensors and the Thermolab Unit before cleaning and stowing the equipment following completion of the European Space Agency’s (ESA’s) Circadian Rhythm experiment measurement process which took 36 hours over a three day period to complete. The objective of the experiment is to get a better basic understanding of alterations in circadian rhythms in humans during long-term space flights. Mouse Epigenetics Cage Unit Maintenance: The crew performed standard maintenance activities for the Mouse Epigenetics experiment by exchanging the food cartridge of the Mouse Habitat Cage Unit and checking the fan and LED light of the Transportation Cage Unit). The Mouse Epigenetics investigation studies altered gene expression patterns in the organs of male mice that spend one month in space, and also examines changes in the deoxyribonucleic acid (DNA) of their offspring. Results from the investigation identify genetic alterations that happen after exposure to the microgravity environment of space. NeuroMapping Operations: The crew set up the NeuroMapping hardware before performing the experiment including testing in both a “strapped in” and ”free floating” body configuration. The investigation studies whether long-duration spaceflight causes changes to the brain including brain structure and function, motor control, and multi-tasking abilities. It also measures how long it would take for the brain and body to recover from possible changes. Previous research and anecdotal evidence from astronauts suggests movement control and cognition can be affected in microgravity. The NeuroMapping investigation performs structural and functional magnetic resonance brain imaging (MRI and fMRI) to assess any changes that occur after spending months on the ISS. Heart Cells Media Change: The crew changed the media in the Multiwell BioCell for Heart Cells in the Microgravity Science Glovebox (MSG) to provide nutrients to the cells and encourage continued cell health. Later in the day, atmospheric conditions inside SABL2 exceeded the acceptable levels and the cells were moved to SABL1 in an effort to save the science. The investigation studies the human heart, specifically how heart muscle tissue contracts, grows and changes (gene expression) in microgravity and how those changes vary among subjects. Understanding how heart muscle cells, or cardiomyocytes, change in space improves efforts for studying disease, screening drugs and conducting cell replacement therapy for future space missions. NanoRacks Module 9: The NanoRacks Module 9 experiment session 3 of 5 was completed today. The crew activated, deactivated, and shook the mixture tubes to facilitate the experiment. Module-9 is a collection of student research projects utilizing the NanoRacks Mixsticks. Student teams from across the United States design their own experiments using flight approved fluids and materials. The investigation consists of several science experiments flown in a NanoRacks Module on board the ISS. Space Headaches: The crew completed the European Space Agency (ESA) Space Headaches questionnaire to provide information that may help in the development of methods to alleviate associated symptoms and improvement in the well-being and performance of crew members in space. Headaches during space flight can negatively affect mental and physical capacities of crew members which can influence performance during a space mission. Fine Motor Skills: A series of interactive tasks on a touchscreen tablet were completed for the Fine Motor Skills investigation. This investigation is critical during long-duration space missions, particularly those skills needed to interact with technologies required in next-generation space vehicles, spacesuits, and habitats. The crewmember’s fine motor skills are also necessary for performing tasks in transit or on a planetary surface, such as information access, just-in-time training, subsystem maintenance, and medical treatment. Waste Storage Tank Assembly (WSTA) Sample – Last week, the contents of the WSTA was emptied into a ЕДВ for the purpose of obtaining a sample for return on SpaceX 9. Today, the crew successfully obtained a sample from the ЕДВ. This sample is part of an overall plan for troubleshooting the elevated conductivity of the Urine Processing Assembly (UPA) water. Lab Carbon Dioxide Removal Assembly (CDRA) Activation – The Lab CDRA was activated to provide supplemental CO2 removal during a Synchronized Position Hold, Engage, Reorient, Experimental Satellites (SPHERES) session today. The SPHEREs payload uses CO2 for propulsion and in order to maintain desired 24hour ppCO2 average, the Lab CDRA can be activated as necessary. Today’s activation is also being used as the periodic activation of Lab CDRA (required every 30 days). The Node3 CDRA has been brought to standby and the Lab CDRA will be run for 24 hours. Today’s Planned Activities All activities were completed unless otherwise noted. Ocular Ultrasound Scan (Ultrasound 2) Rack 1 Power Up CASKAD. Manual Mixing in Bioreactor / r/g 2888 Fine Motor Skills (FINEMOTR) Experiment Ops HRTCEL Hardware Removal ISS crew and ГОГУ (RSA Flight Control Management Team) weekly conference (S-band) / r/g 3030 Ocular Ultrasound Scan (Ultrasound 2) Preparation IMS Tagup (S-band) CIRCADIAN RHYTHMS Hardware Removal Ocular Ultrasound Scan (Ultrasound 2) Scan (Operator) Ocular Ultrasound Scan (Ultrasound 2) Scan (Subject) Fine Motor Skills (FINEMOTR) Experiment Ops NANO Sample Mixing Ultrasound 2 Ground Guided Data Export POLAR4 Replacement of consumables СОЖ Maintenance XF305 Camcorder Settings Adjustment MOUSE Mouse Habitat Cage Unit Maintenance ELC4 Relocation IDENTIFICATION. Copy ИМУ-Ц micro-accelerometer data to laptop / r/g 1589 Ocular Ultrasound Scan (Ultrasound 2) Scan (Subject) IMS Delta File Prep Ocular Ultrasound Scan (Ultrasound 2) Scan (Operator) Ultrasound 2 Ground Guided Data Export HRTCEL Hardware Setup Ocular Ultrasound Scan (Ultrasound 2) Scan (Subject) Ocular Ultrasound Scan (Ultrasound 2) Scanning (Operator) Ocular Ultrasound Scan (Ultrasound 2) Data Export […]
from ISS On-Orbit Status Report http://ift.tt/2bxPKhR
via IFTTT
from ISS On-Orbit Status Report http://ift.tt/2bxPKhR
via IFTTT
[FD] PayPal Inc BB #127 - 2FA Bypass Vulnerability
Document Title: =============== PayPal Inc BB #127 - 2FA Bypass Vulnerability References (Source): ==================== http://ift.tt/2aPSAcB Release Date: ============= 2016-08-12 Vulnerability Laboratory ID (VL-ID): ==================================== 1903 Common Vulnerability Scoring System: ==================================== 6.2 Product & Service Introduction: =============================== PayPal is a global e-commerce business allowing payments and money transfers to be made through the Internet. Online money transfers serve as electronic alternatives to paying with traditional paper methods, such as checks and money orders. (Copy of the Homepage: www.paypal.com ) Abstract Advisory Information: ============================== The independent vulnerability laboratory researcher (shawar khan) discovered a vulnerability in the official PayPal website (api) web-application). The issue allows an attacker to bypass the 2-factor authentication and mobile confirmation which could lead to unauthorized access. Vulnerability Disclosure Timeline: ================================== 2016-05-13: Researcher Notification & Coordination (Shawar Khan) 2016-05-14: Vendor Notification (PayPal Inc Bug Bounty Program - Security Team) 2016-05-24: Vendor Response/Feedback (PayPal Inc Bug Bounty Program - Security Team) 2016-07-10: Vendor Fix/Patch (PayPal Inc Developer Team) 2016-07-18: Acknowledgements (PayPal Inc Bug Bounty Program - Security Team) 2016-08-12: Public Disclosure (Vulnerability Laboratory) Discovery Status: ================= Published Affected Product(s): ==================== PayPal Inc Product: PayPal - Online Service Web Application 2016 Q3 Exploitation Technique: ======================= Remote Severity Level: =============== High Technical Details & Description: ================================ A 2 Factor Authentication Bypass Vulnerability was discovered in the official PayPal website (api) web-application). This vulnerability allows an attacker to bypass the 2FA mechanism for access to accounts of paypal without verifying in the basic procedure the identity with confirmation. The security vulnerability is located in the paypal login portals of uk and the paypal preview. Each Portal is having an issue which can lead to a full bypass once used in a combined way. If the user have 2FA activated in his account. Whenever an user logs into his account, paypal will ask the user to verify the identity. Verification can be made via phone number or by confirming the login request via paypal mobile app (api). The mechanism mainly prevents unauthorized acccess to the account and provides an extra layer of security. The login portal of paypal preview is missing verification mechanism in it. When an user is logged in via paypal preview's login portal, the user is logged in without any verification and the login is successful but there is no settings or anything of interest. When logged in via paypal uk login portal, it checks if the user account is already signed in from any other portal or not. Once it checks the user is already logged in via paypal preview (without verification) it allows us access to the account without any kind of verification. This is the way how 2FA was bypassed in paypal due to lack of 2FA protection. Proof of Concept (PoC): ======================= PayPal uses an additional layer of security known as 2-Factor Authentication which is used to verify the user's identity so no unauthorized access would be allowed. The mechanism verifies the user's identity by calling or messaging a code to phone number or by confirming the login via Mobile App. Without these, the account will not be accessed. By following the procedure below the 2FA protection can be bypassed: Site: PayPal ( www.paypal.com ) PayPal UK Login Portal: http://ift.tt/2baQrbU PayPal Preview Login Portal: http://ift.tt/2btLTkN Steps to reproduce: 1. Open PayPal UK Login Portal in a new tab(keep it open) 2. On the other tab, open PayPal Preview Login Portal 3. Login to your account in the URL which is opened in step 2 4. Enter credentials in the new window which appears 5. Refresh the page which was opened in step 1 6. Now you will be logged, Click on view account button which will lead you to your account and the 2 step verification will be bypassed Solution - Fix & Patch: ======================= In every login portals, verification checks must be deployed even if the user is already logged in. This will prevent unauthorized access to the account. Security Risk: ============== This vulnerability allows an attacker to bypass the 2-factor authentication and mobile confirmation which could lead to unauthorized access. Credits & Authors: ================== Shawar Khan - (https://shawarkhan.com) [http://ift.tt/2baRAA4] Disclaimer & Information: ========================= The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. We do not approve or encourage anybody to break any licenses, policies, deface websites, hack into databases or trade with stolen data. Domains: http://ift.tt/1jnqRwA - www.vuln-lab.com - http://ift.tt/1kouTut Section: magazine.vulnerability-lab.com - http://ift.tt/1zNuo47 - http://ift.tt/1wo6y8x Social: twitter.com/vuln_lab - http://ift.tt/1kouSqa - http://youtube.com/user/vulnerability0lab Feeds: http://ift.tt/1iS1DH0 - http://ift.tt/1kouSqh - http://ift.tt/1kouTKS Programs: http://ift.tt/1iS1GCs - http://ift.tt/1iS1FyF - http://ift.tt/1oSBx0A Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, source code, videos and other information on this website is trademark of vulnerability-lab team & the specific authors or managers. To record, list, modify, use or edit our material contact (admin@ or research@vulnerability-lab.com) to get a ask permission. Copyright © 2016 | Vulnerability Laboratory - [Evolution Security GmbH]™
Source: Gmail -> IFTTT-> Blogger
Source: Gmail -> IFTTT-> Blogger
[FD] Stash v1.0.3 CMS - SQL Injection Vulnerability
Document Title: =============== Stash v1.0.3 CMS - SQL Injection Vulnerability References (Source): ==================== http://ift.tt/2aF50ns Release Date: ============= 2016-08-10 Vulnerability Laboratory ID (VL-ID): ==================================== 1899 Common Vulnerability Scoring System: ==================================== 6 Product & Service Introduction: =============================== Stash is a free content management system (CMS). Was written on PHP and uses MySQL. Distributed under The Creative Commons License. Abstract Advisory Information: ============================== The vulnerability laboratory core research team discovered a remote sql-injection web vulnerability in the official Stash v1.0.3 content management system. Vulnerability Disclosure Timeline: ================================== 2016-08-10: Public Disclosure (Vulnerability Laboratory) Discovery Status: ================= Published Affected Product(s): ==================== Stash Product: Stash - Content Management System (Web-Application) 1.0.3 Exploitation Technique: ======================= Remote Severity Level: =============== High Technical Details & Description: ================================ A remote sql-injection web vulnerability has been discovered in the official phpCollab v2.5 content management system. The vulnerability allows remote attackers to execute own malicious sql commands to compromise the application or dbms. The sql-injection vulnerability is located in the `id` parameter of the `./stash/admin/` module GET method request. Remote attackers are able to execute own sql commands by usage of the insecure `usersedit.php` file GET method request. The attack vector of the vulnerability is application-side and the request method to inject is GET. The vulnerability is a classic select remote sql-injection. The security risk of the vulnerability is estimated as high with a cvss (common vulnerability scoring system) count of 6.0. Exploitation of the remote sql injection vulnerability requires no user interaction and a low privileged web-application user account. Successful exploitation of the remote sql injection results in database management system, web-server and web-application compromise. Request Method(s): [+] GET Vulnerable Module(s): [+] ./stash/admin/ Vulnerable File(s): [+] usersedit.php Vulnerable Parameter(s): [+] id Proof of Concept (PoC): ======================= The remote sql-injection web vulnerability can be exploited by remote attackers without privileged web-application user account and without user interaction. For security demonstration or to reproduce the sql-injection web vulnerability follow the provided information and steps below to continue. PoC: Exploitation http://ift.tt/2aNyNyJ'[SQL-INJECTION VULNERABILITY!
Source: Gmail -> IFTTT-> Blogger
Source: Gmail -> IFTTT-> Blogger
I have a new follower on Twitter
Corporate Tech
Leveraging the power of information #technology to meet our clients’ strategic business goals—reducing cost, increasing revenue, and mitigating risk.
Burlington, MA
http://t.co/IvJVCLxNfL
Following: 6252 - Followers: 8535
August 15, 2016 at 03:57AM via Twitter http://twitter.com/Corp_Tech
Subscribe to:
Posts (Atom)