Do you like this site? Remember to share it to all your friends on Facebook and Twitter!

Wednesday, January 29, 2014

Thursday, January 16, 2014

Fw: NTP Amplification Attacks Using CVE-2013-5211 | US-CERT

Screen capture of this alert page.

If you are running NTP Daemon, remember to upgrade to Version 4.2.7, or just disable “monlist” functionality.

Monday, January 13, 2014

What I have learned from this vulnerability: Undocumented Test Interface in Cisco Small Business Devices

"Two adult Guinea Pigs"
Photo taken by Sandos on Wikipedia.

Recently Eloi Vanderbecken discovered a security hole on his home Internet gateway. An undocumented TCP port 32764 is listened on this gateway. Intruders can use this hole to reset administrator’s password and then gain control of that Internet gateway. There is a post about how Eloi discovered this security hole and possible way for an intruder to gain control.

The brand of that Internet gateway is Linksys, which was once part of Cisco System but now is part of Belkin. That is why I look more carefully about this case. Cisco published this report about the discovered security hole.

I have learned many things about this case.

Popular Posts