Home / Companies / Detectify / Blog / January 2021

January 2021 Summaries

5 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify, a SaaS-based web application security company, pursued ISO 27001 certification to enhance its market position, reduce cybersecurity risks, and meet the demands of existing and prospective partners. The certification process highlighted the importance of implementing a comprehensive Information Security Management System (ISMS) and required company-wide commitment, including training and the adoption of new security tools tailored to their tech-agnostic environment. Despite the challenges, the certification provided a competitive advantage by establishing Detectify as a trustworthy vendor with robust security practices. Detectify emphasizes that while compliance is not the same as security, achieving ISO 27001 serves as both a valuable marketing asset and a catalyst for improving overall security measures, encouraging organizations to look beyond compliance towards genuine security enhancements.
Jan 26, 2021 1,503 words in the original blog post.
Detectify's Crowdsource ethical hacker community has been actively contributing to security updates by identifying vulnerabilities such as zero-day threats, which are rapidly integrated into the Detectify scanner within 25 minutes for asset monitoring purposes. Various security vulnerabilities reported between January 11 and January 22 include critical issues like Remote Code Execution in Apache Solr, Local File Inclusion in SolarWinds Orion, Blind SQL Injection in Fortinet FortiWeb, and Path Traversal in Apache Flink. Additional vulnerabilities include cross-site scripting in mdBook, authentication bypass in ColdFusion Lucee, and Local File Inclusion in Oracle Business Intelligence, among others. These vulnerabilities allow attackers to execute malicious actions such as code execution, file reading, and unauthorized data access, highlighting the importance of timely security updates and monitoring.
Jan 25, 2021 530 words in the original blog post.
In January, Detectify's security team identified that the .cd top-level domain (TLD) was set to expire and managed to secure it to prevent potential malicious exploitation. The expiration of a TLD can lead to DNS hijacking, where attackers could control traffic and intercept sensitive information. Fredrik Nordberg Almroth, a co-founder of Detectify, preemptively claimed the .cd domain, which belongs to the Democratic Republic of Congo, to prevent such risks. DNS hijacking involves redirecting user traffic by manipulating domain name servers, and it poses significant threats, including phishing and data theft. A similar vulnerability exists at the subdomain level, known as Hostile Subdomain Takeover, which occurs when abandoned subdomains are claimed by others for malicious purposes. Detectify emphasizes the importance of monitoring domain licenses and subdomain inventories to prevent these threats, offering tools like Surface Monitoring to help organizations track DNS configurations and mitigate vulnerabilities.
Jan 19, 2021 1,168 words in the original blog post.
In December, cybersecurity researcher Fredrik Nordberg Almroth, co-founder of Detectify, discovered a significant vulnerability within the Democratic Republic of Congo's top-level domain, .cd, which exposed it to potential malicious exploitation. By purchasing a crucial, expired domain name server linked to .cd, Almroth thwarted possible nefarious activities, such as traffic redirection, credential theft, and malware dissemination. This vulnerability, once reported, was swiftly patched, but it highlighted the severe risks of domain hijacking, which can impact millions of users and major institutions. Almroth emphasized the importance of proactive monitoring and quick vulnerability detection to prevent such hostile takeovers, citing past incidents with other country code top-level domains. A detailed technical report on this incident is available through Detectify Labs.
Jan 15, 2021 436 words in the original blog post.
Detectify's Crowdsource ethical hacker community has been actively contributing security updates, including zero-day vulnerabilities, which are quickly integrated into their Asset Monitoring system, allowing for rapid testing within 25 minutes from discovery to scanner deployment. Although confidentiality agreements limit the public disclosure of these updates, they are immediately made available to users. Recent security vulnerabilities identified by the community include notable issues such as an authentication bypass in Solar Winds Orion API, a path traversal vulnerability in Apache Flink, a blind SQL injection in FortiWeb, an open redirect issue in Ruby on Rails, a server-side request forgery (SSRF) vulnerability in Oracle JD Edwards EnterpriseOne Application Interface Services, and a prototype pollution leading to cross-site scripting (XSS) in Atlassian Jira. These vulnerabilities, reported between December 28 and January 8, have been added to the Detectify scanner to enhance security measures for its users.
Jan 11, 2021 244 words in the original blog post.