Home / Companies / Detectify / Blog / April 2021

April 2021 Summaries

5 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify's Crowdsource ethical hacker community has been actively providing security updates, including zero-day research, which are rapidly integrated into their Asset Monitoring system within 25 minutes from discovery to scanner deployment. Although not all updates can be disclosed publicly due to confidentiality agreements, they are immediately accessible to all users. Recent vulnerabilities identified by the community include multiple critical flaws such as a reflected XSS vulnerability in Composr CMS, authentication bypass in Dell OpenManage Administrator, information disclosure in Eclipse Jetty, arbitrary file read in Apache Solr, remote code execution in Yii 2, XSS vulnerabilities in Bitrix Site Manager and Tileserver GL, and a directory traversal issue in Rstudio Shiny Server. These vulnerabilities, once exploited, can lead to credential theft, unauthorized access, or execution of malicious JavaScript, highlighting the critical role of ongoing security vigilance and rapid response.
Apr 27, 2021 411 words in the original blog post.
Spencer Pearlman, a Security Researcher at Detectify, emphasizes the importance of adopting a hacker's mindset to identify vulnerabilities in open-source software, highlighting that many hackers target open-source due to its transparency, which can also be an asset in quickly identifying and addressing security flaws. The approach involves a three-step methodology: recon using both dynamic analysis and open-source intelligence (OSINT), followed by static code analysis. Dynamic analysis helps understand how an application is supposed to function, while OSINT involves gathering information from sources like GitHub, GitLab, and forums such as Stackoverflow to uncover potential vulnerabilities. Static analysis, enhanced by tools like Semgrep, focuses on detecting common vulnerabilities and data mishandling. Detectify's strategy involves collaborating with ethical hackers to crowdsource vulnerability information, offering a unique approach that includes per-hit payouts for popular vulnerability modules. This method allows Detectify to rapidly incorporate and test new vulnerabilities, providing enhanced security scanning for users and ensuring they remain protected against emerging threats.
Apr 22, 2021 1,523 words in the original blog post.
Detectify's Crowdsource ethical hacker community has been actively providing security updates, including 0-day research, which are promptly integrated into their scanner for user access, although confidentiality agreements prevent public disclosure of all updates. Recent vulnerabilities reported by the community include open redirect issues in Episerver Find, information disclosure in Gitlab via GraphQL, reflected XSS vulnerabilities in Aryanic HighMail CMS and WSO2 Management Console, and SSRF vulnerability in VMWare vRealize Operations Manager API. Additionally, the PHP "Zerodium" backdoor and RCE vulnerabilities in Adobe ColdFusion and F5 Big-IP iControl REST interface were also identified, enabling attackers to potentially gain full control of affected systems. These findings highlight the critical role of ethical hackers in identifying security flaws and enabling rapid response to protect digital assets.
Apr 12, 2021 381 words in the original blog post.
Detectify is committed to enhancing Internet security by leveraging automation and crowdsourced hacker expertise, offering a modern approach to web application security for SaaS and tech organizations. As code deployment accelerates, the challenge for security teams to manage changes and address new threats grows, necessitating a focus on External Attack Surface Management. With thousands of vulnerabilities being reported, rapid detection and response are crucial, as demonstrated by the swift exploitation of vulnerabilities shortly after their disclosure. Detectify emphasizes the importance of integrating security into the development process through automated, dynamic application security testing (DAST) and regular vulnerability scanning, ensuring that only critical alerts are flagged and addressed promptly. Collaboration between automated tools and human expertise, such as pentesting and bug bounty programs, is essential for robust security, and Detectify offers cloud-based solutions that quickly translate hacker research into actionable insights. The platform aims to align security with development processes, allowing organizations to maintain safety at scale and speed.
Apr 09, 2021 858 words in the original blog post.
Detectify is committed to enhancing Internet security through a blend of automation and insights from ethical hackers, emphasizing the importance of diverse teams in achieving this goal. Conversations with Danwei Tran, a Senior Product Designer, and Marcus Sheridan, a Team Manager in Mid Market Sales, reveal their unique pathways into the IT security space. Danwei's journey began with an early fascination with technology, while Marcus was propelled by a personal experience with hacking. Both have come to appreciate the dynamic and collaborative nature of the security field, contrary to their initial perceptions of it being solely about strict policies. Their work in Internet security has fostered a deep respect for the industry and its critical role in an increasingly digital world. They encourage others to explore the field, highlighting the importance of curiosity and the welcoming nature of the community, as well as the potential to make meaningful contributions to Internet security without needing prior expertise.
Apr 08, 2021 877 words in the original blog post.