November 2018 Summaries
5 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
Detectify releases bi-weekly security updates to ensure their tool remains current with the latest security findings, features, and improvements contributed by both their security researchers and the Detectify Crowdsource ethical hacker community. Although confidentiality agreements prevent the public release of all security updates, they are immediately integrated into the Detectify scanner for user access. Recent updates include addressing vulnerabilities in popular software such as WordPress plugins, specifically wp-backup-plus which can expose entire backups, and jQuery-File-Upload, which is frequently targeted for remote code execution exploits. Additionally, the update highlights the common issue of inadvertently uploading Thumbs.db and .DS_Store files, which store directory information and thumbnails, potentially exposing sensitive data. The release also notes ongoing work by Detectify researchers on existing vulnerabilities in Apache Struts, ensuring comprehensive and effective testing.
Nov 29, 2018
315 words in the original blog post.
Detectify provides bi-weekly security updates to its scanning tool, incorporating new findings and improvements from its security researchers and the Crowdsource ethical hacker community. Due to confidentiality agreements, not all updates can be disclosed publicly, but they are implemented immediately for users. Recent updates include addressing vulnerabilities in WordPress plugins, specifically the limit-login-attempts plugin's XSS issue, and enhancing checks for the Expect-CT header. Additionally, Detectify has added tests for path traversal vulnerabilities in Spring Boot and Ruby on Rails, based on submissions from their community. The latest updates also involve expanding tests for exposed endpoints in Spring Boot, reflecting the team's continuous engagement with the security community's evolving interests and discoveries. Users are encouraged to scan their assets for these vulnerabilities and can start a free trial or log in to access the latest security features.
Nov 15, 2018
403 words in the original blog post.
A recently identified vulnerability in Oracle WebLogic Server allows for unauthenticated remote code execution (RCE) through its Web Services (WLS) subcomponent, particularly affecting the path /ws_utc/config.do on port 7001, which is accessible without authentication in development mode. To exploit the vulnerability, an attacker must set a writable Work Home Dir and upload Java Server Pages (JSP) files via the Security tab, enabling them to execute code remotely. Although the vulnerability requires the server to be in development mode, which limits its exposure, WebLogic servers are easily identifiable and numerous instances are accessible online, posing a significant risk. It is crucial for administrators to ensure their servers are not running in development mode and to monitor for potential vulnerabilities using tools like Detectify. For comprehensive guidance and updates, Oracle's Critical Patch Update Advisory should be consulted.
Nov 14, 2018
355 words in the original blog post.
Cloud security is essential for maintaining the scalability benefits of cloud computing, requiring organizations to manage their own security configurations despite cloud service providers ensuring physical security. Common issues like data breaches often arise from misconfigurations in cloud storage services such as Amazon S3, Azure, or Google Cloud, which organizations must address to protect sensitive information. Key security practices include using strong identity, credential, and access management; checking for forgotten subdomains; ensuring proper logging and monitoring; and regularly updating technologies to mitigate vulnerabilities like SQL injections. Tools like Detectify offer continuous monitoring and automated scanning to identify vulnerabilities, helping organizations maintain robust cloud security by keeping up with rapid changes in web vulnerabilities and offering asset monitoring for potential DNS misconfigurations.
Nov 12, 2018
1,227 words in the original blog post.
Detectify's bi-weekly security updates integrate new findings and improvements from its security researchers and Crowdsource ethical hacker community, although not all updates can be publicized due to confidentiality agreements. Recent updates to the Detectify scanner tool, as of October 31, include tests for vulnerabilities such as the NGINX Remote Integer Overflow, which can leak sensitive web server memory, and the F5 BIG-IP Cookie Information Exposure that may reveal internal IP addresses, aiding potential attacks. Additionally, the jQuery-File-Upload vulnerability allows arbitrary file uploads, and Spring Boot misconfigurations can expose sensitive heap dumps. NGINX Alias Directory Listing and deprecated PHP versions are also addressed, with alerts for unsupported PHP versions being introduced, and improvements in detecting the persistent XSS vulnerability in older Laravel setups are noted. Users are encouraged to scan for these vulnerabilities and can try the tool with a free trial.
Nov 01, 2018
531 words in the original blog post.