Severity Rating: MEDIUM

Software Affected

ART/Agent  8.1.5
ART/Agent  8.1.5.1
ART/Agent  8.1.5.2
ART/Agent  8.1.5.3
ART/Agent  8.1.5.4
ART/Agent  8.1.5.5
ART/Agent  8.1.5.6
ART/Agent  8.1.6
ART/Agent  8.1.6.1
ART/Agent  8.1.6.2
ART/Agent  8.1.6.3
ART/Agent  8.1.6.4


Overview

A Vulnerability has been reported in IBM WebSphere Application Server which
could allow an attacker to obtain sensitive information leading to further
attacks.

Description
This vulnerability exists in IBM WebSphere Application Server- Liberty
which is used by IBM License Key Server Administration & Reporting Tool
(ART) and Administration Agent due to an error while checking parameters. A
remote attacker could exploit this vulnerability to obtain sensitive
information.

Successful exploitation of this vulnerability could lead to spoofing
attacks on the targeted system.

Solution

Apply appropriate patches as mentioned in the below link:

Vendor Information

IBM

Description

Smart devices are the everyday items that connect into a common network
that can be independently and remotely controlled. This can include both
'hi-tech' items (smart speakers, fitness trackers and security cameras),
and also standard household items (fridges, light bulbs and doorbells).
These devices can be controlled from smart phone or through a mobile touch
screen device.

These devices are usually connected to the internet using Wi-Fi. It gives a
live camera feed, receive alerts and gives record footage. As technology
development continues to expand, home automation helps us to manage all of
home devices from one place, flexibility for new devices and appliances,
maximizing home security, remote control of home functions, increased
energy efficiency etc.

At the same time, appliances and devices that connect to the internet and
to each other on your home network, becomes an increased risk of becoming
the target of cybercriminals. If your home network isn't secure, each new
gadget represents a potential access point for hackers. These hackers can
steal and misuse your personal information and even take control of those
smart cameras or microphones to spy on you.

Existing vulnerabilities, poor configuration, and the use of default
passwords are among the factors that can aid a hacker in compromising at
least one device in a smart home system. Once a single device is
compromised, hackers can take a number of actions depending upon on the
capabilities and functions of the device.

Beginning from the front door, for example, there can be a smart lock. If
compromised, the smart lock can give hackers control over who comes in or
out of the house.

Or a smart speaker, serves as the conduit for voice-initiated home
automation commands. If compromised, it can allow hackers to issue voice
commands of their own.

Devices like smart robot vacuum cleaners, which have some mobility around
the house, can provide hackers information about the home's layout, which
in turn, can be used by the hackers in planning further activities and
movements.

Portable and wearable smart devices add another layer of complexity to IoT
security concerns, as these devices traverse both enterprise and home
environments. Devices, such as smartwatches are typically brought by users
to the office, and then brought back home at the end of the day. A malware
infection picked up in one environment, can spread to the other if the
"bring your own device" (BYOD) policies in place are weak or if
adequate security measures are not taken to prevent such a threat.

Best Practices for Securing Smart Devices

·        Setting up device: Before buying a new device for your home,
consider doing some research on it. Understand what kind of features and
details are included and pick devices that have clearly considered quality
and security as main features. For setting up a specific device, refer to
the manufacturer's documentation.

·        Use a strongest possible encryption method for Wi-Fi.

·        Set up a Separate Wi-Fi Network for IoT Devices: By creating a
separate network dedicated to your IoT devices, you can safeguard your main
network against IoT threats. Visitors, friends and relatives can log into a
separate network that doesn't tie into your IoT devices. As placing IoT
devices on a different network keeps them detached, if hackers do manage to
get through, they can't access any of your more important devices.

·        Change the default username and password: Cybercriminal uses
these well-known passwords to access the camera remotely and view live
video or images of our home. Avoid common words or passwords that are easy
to guess, such as "password" or "123456."  Instead, use unique,
complex passwords made up of letters, numbers, and symbols for Wi-Fi
networks and device accounts. You may also consider a password manager to
up your security game.

·        Disable the unwanted features. Many IoT devices give you the
ability to control them from anywhere on the planet. But if you only use
them on your home's Wi-Fi connection, disable remote access. Smart
speakers often have Bluetooth connectivity in addition to Wi-Fi. Turn it
off, if you are not using it.

·        Setting up Router: Many routers use technologies called UPnP and
port forwarding to allow devices to find other devices within your network.
Cyber criminals can exploit these technologies to potentially access
devices on your network, such as smart cameras. Disable the UPnP and port
forwarding on the router to prevent cyber-criminal access. Don't stick
with your router's default name, which is usually its make and model.

·        Managing account: Two-factor Authentication provides a way of
double checking and makes much harder for criminals to access online
accounts, even if they know the password.

·        Keep your software up to date: Installing software updates help
keep devices secure. Updates to many IoT devices may not happen
automatically. Hence, do a manual check every few months, and if you find
any pending firmware updates, install them right away. If available, enable
the option to install automatic updates.

·        Protect your smartphone: Most home smart technology and security
systems can be controlled by an app on your mobile phone, so protecting
your smartphone is crucial. Be sure you have your smartphone
password-protected so that if your phone is lost or stolen, no one will be
able to access your home smart tech or security system apps.

·        Audit the IoT devices already on your home network.

·        Watch out for outages: Ensure that a hardware outage does not
result in an unsecure state for the device.

·        Perform a factory reset when malicious control/access of a device
in your home.

·        Perform factory reset before selling the device: If you decide to
sell or give away one of your smart electronics, follow the
manufacturer's instructions to remove all of your data. Otherwise, the
next person who gets their hands on it may automatically access all of your
information or communicate with other devices on your network.

References



rt-home-devices/


in-Your-Smart-Home.aspx

Severity rating:  High

Software affected

F5 BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link
Controller, PEM) versions:

·         15.x versions 15.1.0 and 15.0.0

·         14.x versions from 14.1.0 to 14.1.2

·         13.x versions from 13.1.0 to 13.1.3

·         12.x versions from 12.1.0 to 12.1.5

Overview

A vulnerability has been reported in F5 BIG-IP products which could allow
an attacker to perform cross-site scripting attack on a targeted system.

Description

This vulnerability exists in multiple BIG-IP products due to a flaw in
undisclosed pages of Traffic Management User Interface (TMUI), also
referred to as the Configuration utility. 
Successful exploitation of this vulnerability could allow the attacker to
run JavaScript in the context of the currently logged-in user. In case the
user has administrative privileges with access to the Advanced Shell
(bash), the attacker can completely compromise the targeted system.

Solution

Update to the fixed versions as mentioned in the F5 advisory

Vendor Information

F5 Networks


References

Tenable


CVE Name

CVE-2020-5903

Severity Rating: HIGH

Software Affected

·         VMware Fusion 11.x versions prior to 11.5.5

·         VMware Remote Console for Mac versions prior to 11.2.0

·         Horizon Client for Mac versions prior to 5.4.3

Overview

A vulnerability has been reported in multiple VMware products which could
allow an attacker to gain elevated privileges on a targeted system.

Description

This vulnerability exists in affected products due to improper XPC Client
validation.

Successful exploitation of this vulnerability could allow an attacker with
normal user privileges to gain  root privileges on the targeted system.

Solution

Apply appropriate updates as mentioned in VMware Security Advisory:


Vendor Information

VMware


References

Securezoo

rability-cve-2020-3974/

CVE Name

CVE-2020-3974

Severity Rating: Critical

Software Affected
●      Google Android versions 8.0,8.1,9,10

Overview

Multiple vulnerabilities have been reported in Google Android which could
allow a remote attacker to gain elevated privileges, obtain sensitive
information, execute remote code and cause Denial of service condition on
the targeted system.

Description

These vulnerabilities exist in Framework, Media framework, System, Broadcom
components, Kernel Components, Media Tek components, Qualcomm components,
Qualcomm closed-source components of Google Android. A remote attacker
could exploit these vulnerabilities by hosting a specially crafted file
designed to exploit the vulnerabilities.

Successful exploitation of these vulnerabilities could allow an attacker to
gain elevated privileges, disclose sensitive information, execute remote
and cause Denial of Service condition on the targeted system.

Solution

Apply appropriate fix as mentioned in Google Android Security Advisory

Vendor Information
Android

References
Android

CVE Name
CVE-2018-20669
CVE-2019-10580
CVE-2019-14123
CVE-2019-14124
CVE-2019-14130
CVE-2019-18282
CVE-2019-20636
CVE-2019-9501
CVE-2019-9502
CVE-2020-0107
CVE-2020-0122
CVE-2020-0224
CVE-2020-0225
CVE-2020-0226
CVE-2020-0227
CVE-2020-0228
CVE-2020-0230
CVE-2020-0231
CVE-2020-3688
CVE-2020-3698
CVE-2020-3699
CVE-2020-3700
CVE-2020-3701
CVE-2020-9589



Description

Smart devices are the everyday items that connect into a common network
that can be independently and remotely controlled. This can include both
'hi-tech' items (smart speakers, fitness trackers and security cameras),
and also standard household items (fridges, light bulbs and doorbells).
These devices can be controlled from smart phone or through a mobile touch
screen device.

These devices are usually connected to the internet using Wi-Fi. It gives a
live camera feed, receive alerts and gives record footage. As technology
development continues to expand, home automation helps us to manage all of
home devices from one place, flexibility for new devices and appliances,
maximizing home security, remote control of home functions, increased
energy efficiency etc.

At the same time, appliances and devices that connect to the internet and
to each other on your home network, becomes an increased risk of becoming
the target of cybercriminals. If your home network isn't secure, each new
gadget represents a potential access point for hackers. These hackers can
steal and misuse your personal information and even take control of those
smart cameras or microphones to spy on you.

Existing vulnerabilities, poor configuration, and the use of default
passwords are among the factors that can aid a hacker in compromising at
least one device in a smart home system. Once a single device is
compromised, hackers can take a number of actions depending upon on the
capabilities and functions of the device.

Beginning from the front door, for example, there can be a smart lock. If
compromised, the smart lock can give hackers control over who comes in or
out of the house.

Or a smart speaker, serves as the conduit for voice-initiated home
automation commands. If compromised, it can allow hackers to issue voice
commands of their own.

Devices like smart robot vacuum cleaners, which have some mobility around
the house, can provide hackers information about the home's layout, which
in turn, can be used by the hackers in planning further activities and
movements.

Portable and wearable smart devices add another layer of complexity to IoT
security concerns, as these devices traverse both enterprise and home
environments. Devices, such as smartwatches are typically brought by users
to the office, and then brought back home at the end of the day. A malware
infection picked up in one environment, can spread to the other if the
"bring your own device" (BYOD) policies in place are weak or if
adequate security measures are not taken to prevent such a threat.

Best Practices for Securing Smart Devices

·        Setting up device: Before buying a new device for your home,
consider doing some research on it. Understand what kind of features and
details are included and pick devices that have clearly considered quality
and security as main features. For setting up a specific device, refer to
the manufacturer's documentation.

·        Use a strongest possible encryption method for Wi-Fi.

·        Set up a Separate Wi-Fi Network for IoT Devices: By creating a
separate network dedicated to your IoT devices, you can safeguard your main
network against IoT threats. Visitors, friends and relatives can log into a
separate network that doesn't tie into your IoT devices. As placing IoT
devices on a different network keeps them detached, if hackers do manage to
get through, they can't access any of your more important devices.

·        Change the default username and password: Cybercriminal uses
these well-known passwords to access the camera remotely and view live
video or images of our home. Avoid common words or passwords that are easy
to guess, such as "password" or "123456."  Instead, use unique,
complex passwords made up of letters, numbers, and symbols for Wi-Fi
networks and device accounts. You may also consider a password manager to
up your security game.

·        Disable the unwanted features. Many IoT devices give you the
ability to control them from anywhere on the planet. But if you only use
them on your home's Wi-Fi connection, disable remote access. Smart
speakers often have Bluetooth connectivity in addition to Wi-Fi. Turn it
off, if you are not using it.

·        Setting up Router: Many routers use technologies called UPnP and
port forwarding to allow devices to find other devices within your network.
Cyber criminals can exploit these technologies to potentially access
devices on your network, such as smart cameras. Disable the UPnP and port
forwarding on the router to prevent cyber-criminal access. Don't stick
with your router's default name, which is usually its make and model.

·        Managing account: Two-factor Authentication provides a way of
double checking and makes much harder for criminals to access online
accounts, even if they know the password.

·        Keep your software up to date: Installing software updates help
keep devices secure. Updates to many IoT devices may not happen
automatically. Hence, do a manual check every few months, and if you find
any pending firmware updates, install them right away. If available, enable
the option to install automatic updates.

·        Protect your smartphone: Most home smart technology and security
systems can be controlled by an app on your mobile phone, so protecting
your smartphone is crucial. Be sure you have your smartphone
password-protected so that if your phone is lost or stolen, no one will be
able to access your home smart tech or security system apps.

·        Audit the IoT devices already on your home network.

·        Watch out for outages: Ensure that a hardware outage does not
result in an unsecure state for the device.

·        Perform a factory reset when malicious control/access of a device
in your home.

·        Perform factory reset before selling the device: If you decide to
sell or give away one of your smart electronics, follow the
manufacturer's instructions to remove all of your data. Otherwise, the
next person who gets their hands on it may automatically access all of your
information or communicate with other devices on your network.

References



rt-home-devices/


in-Your-Smart-Home.aspx

Virus Type: crypto-jacking Malware

It has been reported that a new self-propagating malware, dubbed "Lucifer",
targeting Windows systems with crypto-jacking and DDoS attacks is
spreading. The latest variant of this malware was discovered recently
related to exploitation of vulnerability in Laravel Framework
(CVE-2019-9081) that can be leveraged for remote code execution (RCE)
attacks. Reports indicate that this malware utilizes an exhaustive list of
unpatched critical vulnerabilities. While the patches of all critical and
highly severe vulnerabilities are available but the systems affected by
Lucifer malware have not been applied upon with those patches.

The vulnerabilities exploited by Lucifer includes affect Rejetto HTTP File
Server (CVE-2014-6287), Oracle Weblogic (CVE-2017-10271), ThinkPHP RCE
(CVE-2018-20062), Apache Struts (CVE-2017-9791), Laravel framework
CVE-2019-9081), and Microsoft Windows (CVE-2017-0144, CVE-2017-0145, and
CVE-2017-8464) and some others depending on which version of the malware is
in role.

After exploiting the flaws, connection to C2 server is established for
arbitrary command execution including performing DDoS attack, transferring
stolen data etc. Another command allows the malware to drop XMRig miner, a
program used to secretly mine Monero (XMR) cryptocurrency. Lucifer also
receives command from C2 server to keep the operator informed about the
status of Monero crypto currency miner.


The malware scans open TCP ports 135(RPC) and 1433(MSSQL) and if found
open, it launches brute-force attack to obtain access. In addition to this,
the malware leverages exploitation for self- propagation. If SMB protocol
is open, Lucifer executes several backdoors including the EternalBlue,
EternalRomance, and DoublePulsar exploits to establish persistence. It also
tampers registry to schedule itself as a task at startup.


The malware utilizes "certutil utility" in the payload for self-
propagation and targets Windows hosts on both the internet and intranet.
With its updated features, Lucifer also checks for the presence of
sandboxes or VMs to escape from detection and if anyone of those is found
it enters "infinite loop" which stops operations.

Lucifer can be summarized as a new hybrid of crypto-jacking and DDoS
malware variant exploiting unpatched critical vulnerabilities for malicious
activity on Windows hosts.

Till date, two different versions of Lucifer malware are observed which
indicates that malware is evolving in threat potential and sophistication.

IOC:
Lucifer version 1:
Malware Hosting Site:

180[.]126[.]161[.]27
210[.]112[.]41[.]71

C2:
122[.]112[.]179[.]189:15888 (version 1)
Created Files:

C:\\ProgramData\\spread.txt
C:\\ProgramData\\index.html
C:\\ProgramData\\spreadXfghij.exe
C:\\ProgramData\\SMB.exe
C:\\ProgramData\\svchostlong.exe
C:\\ProgramData\\X86.dll
C:\\ProgramData\\X64.dll
%TEMP%\\<4-random-lower-case-characters>.exe
Lucifer version 2:

Malware Hosting Site

121[.]206[.]143[.]140
C2:

qf2020[.]top:19370
Note: For complete set of IOCs please refer the URL:

id-malware/
Countermeasures and Best practices for prevention:

Keep software and OS up-to-date so that attackers may not take advantages
of or exploit known vulnerabilities.
Keep updated Antivirus/Antimalware software to detect any threat before it
infects the system/network. Always scan the external drives/removable
devices before use. Leverage anti-phishing solutions that help protect
credentials and against malicious file downloads.
It is also important to keep web filtering tools updated.
Change default login credentials as they are readily available with
attackers.
Use limited privilege user on the computer or allow administrative access
to systems with special administrative accounts for administrators.
Avoid downloading files from untrusted websites.
Network administrators should continuously monitor systems and guide their
employees to recognize any above-normal sustained CPU loading activity on
computer workstations, mobile devices, and network servers. Network
activity should continuously be monitored for any unusual activity.
Maintain appropriate Firewall policies to block malicious traffic entering
the system/network. Enable a personal firewall on workstation.
Block the IP addresses of known malicious sites to prevent devices from
being able to access them. Activate intelligent website blacklisting to
block known bad websites.
Block websites hosting JavaScript miners both at the gateway and the
endpoints.
Maintain browser extensions as some attackers are using malicious browser
extensions or poisoning legitimate extensions to execute cryptomining
scripts.
Go beyond intrusion detection to protect servers with runtime memory
protection
for critical applications and server workloads, ensuring a defense against
actors who already have a grip on your server.
Disable Autorun and Autoplay policies.
Consider using application whitelists to prevent unknown executables from
launching autonomously.
Delete the system changes made by the malware such as files created/
registry entries /services etc.
Monitor traffic generated from client machines to the domains and IP
address mentioned in Installation section.
Disable unnecessary services on agency workstations and servers.
References

id-malware/
tems/156883/
- -vulnerabilities-on-your-windows-pc/

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top