Belkin N750 router has Zero-day exploit

This router has a big security hole:   Integrity Labs says there is a guest wifi Zero-day exploit, this means that an unportected (without a password) wifi zone can be attacked and the machine can be taken over by the hacker.   If you have a Belkin N750 you should consider replacing it ASAP. Believe … Read more

Malicious malware in BIOS again?

I say “again” because we have had BIOS malware before  the famous CIH (Chernobyl) virus from 1998. Sophos recount And the last time the Chernobyl virus activated (April 26th) it caused $250mil dollars of damage in 1999 for South Korea alone. Even Mac’s can have BIOS infections as from Trendmicro Blog post Intel and MITRE … Read more

Drupal vulnerability has new POC

New Proof of Concept for the 2 week old Drupal vulnerability The Drupal Security team says that you should assume every Drupal website not patched on October 15th was infected. A SQL injection attack went around the Internet in an automated fashion. And the details are: In this code we see, that Drupal gives the … Read more

Bash Shellcode test site made

this is interesting: https://shellshocker.net/ Is an interesting site…  You can enter your domain name and they will tell you if you have the Bash Shellcode vulnerability. At this time they found 1767 vulnerable hosts: 107760 Total tests to date. 1767 Total vulnerable hosts found. It is also called the Shellshock vulnerability. As I mentioned in previous posts: … Read more

Wget vulnerability – does it affect you?

So there is a wget vulnerability … big deal? Metasploit developer – Rapid7 has a page discussing the exploit Specifically: GNU Wget is a command-line utility designed to download files via HTTP, HTTPS, and FTP.  Wget versions prior to 1.16 are vulnerable a symlink attack (CVE-2014-4877) when running in recursive mode with a FTP target. … Read more