Redis Cryptocoin Mining Worm; Rowhammer over the Network; DrayTek CSRF Exploit
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/6005.mp3
My Next Class
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Jul 11th - Jul 16th 2022 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | Jul 11th - Jul 16th 2022 |
Redis Cryptocoin Mining Worm
https://isc.sans.edu/forums/diary/Anatomy+of+a+Redis+mining+worm/23673/
Evolving Chrome's Security Indicator
https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html
DrayTek CSRF 0-Day Exploited to Change DNS Servers
https://www.draytek.co.uk/support/security-advisories/kb-advisory-csrf-and-dns-dhcp-web-attacks
Rowhammer Remote Exploit
https://www.cs.vu.nl/~herbertb/download/papers/throwhammer_atc18.pdf
https://arxiv.org/abs/1805.04956
https://isc.sans.edu/forums/diary/Anatomy+of+a+Redis+mining+worm/23673/
Evolving Chrome's Security Indicator
https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html
DrayTek CSRF 0-Day Exploited to Change DNS Servers
https://www.draytek.co.uk/support/security-advisories/kb-advisory-csrf-and-dns-dhcp-web-attacks
Rowhammer Remote Exploit
https://www.cs.vu.nl/~herbertb/download/papers/throwhammer_atc18.pdf
https://arxiv.org/abs/1805.04956
Discussion
There is no mention in the Show Notes of the Spectre attack variation allowing data access inside of the System Management Mode (SMM) area of the CPU. Here is one link: https://www.bleepingcomputer.com/news/security/new-spectre-attack-recovers-data-from-a-cpus-protected-smm-mode/
Posted by SmilingGizmo on Mon May 21 2018, 13:53
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Jul 11th - Jul 16th 2022 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | Jul 11th - Jul 16th 2022 |
Application Security: Securing Web Apps, APIs, and Microservices | Tokyo | Aug 29th - Sep 3rd 2022 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | Japan Standard Time | Aug 29th - Sep 3rd 2022 |
Intrusion Detection In-Depth | Riyadh | Oct 8th - Oct 13th 2022 |
Intrusion Detection In-Depth | Online | Arabian Standard Time | Oct 8th - Oct 13th 2022 |
Application Security: Securing Web Apps, APIs, and Microservices | San Francisco | Dec 5th - Dec 10th 2022 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Pacific | Dec 5th - Dec 10th 2022 |