본문 바로가기

1Day 1News

New PHP Flaw Could Let Attackers Hack Sites Running On Nginx Servers Source for https://thehackernews.com/2019/10/nginx-php-fpm-hacking.html New PHP Flaw Could Let Attackers Hack Sites Running On Nginx Servers A new security vulnerability in php-fpm could allow attackers to hack PHP websites running on Nginx servers. thehackernews.com If you're running any PHP based website on NGINX server and have PHP-FPM feature enabled for better performance, then beware of a .. 더보기
42 Adware Apps with 8 Million Downloads Traced Back to Vietnamese Student Source for https://thehackernews.com/2019/10/42-adware-apps-with-8-million-downloads.html 42 Adware Apps with 8 Million Downloads Traced Back to Vietnamese Student 42 Android Adware Apps on Google Play Store with 8 Million Downloads Traced Back to Vietnamese Student. thehackernews.com First of all, if you have any of the below-listed apps installed on your Android device, you are advised to unin.. 더보기
New Cache Poisoning Attack Lets Attackers Target CDN Protected Sites Source for https://thehackernews.com/2019/10/cdn-cache-poisoning-dos-attack.html New Cache Poisoning Attack Lets Attackers Target CDN Protected Sites CPDoS, a new web-cache poisoning attack could allow attackers to target Content Distribution Network (CDN) protected websites with DoS attacks. thehackernews.com A team of German cybersecurity researchers has discovered a new cache poisoning attack.. 더보기
안드로이드OS, 리눅스 블루투스 취약점 보안 업데이트 권고 Source for https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=35178 KISA 인터넷 보호나라&KrCERT KISA 인터넷 보호나라&KrCERT www.boho.or.kr □ 개요 o 블루투스 프로토콜에서 발생하는 취약점을 해결한 보안 업데이트 발표[1] o 낮은 버전을 사용 중인 OS 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고 □ 설명 o 블루투스 프로토콜(BR/EDR)에서 암호화 수준이 낮은 키 길이를 허용하여 공격자가 트래픽을 도청하고 변조할 수 있는 정보노출 취약점(CVE-2019-9506) [1] □ 영향을 받는 제품 및 최신 버전 OS 명 영향 받는 버전 최신 버전 안드로이드 2019년 8월.. 더보기
Adobe 제품군 보안 업데이트 권고 Source for https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=35172 KISA 인터넷 보호나라&KrCERT KISA 인터넷 보호나라&KrCERT www.boho.or.kr □ 개요 o Adobe社는 자사 제품군의 취약점을 해결한 보안 업데이트 발표 [1] o 낮은 버전을 사용중인 시스템 사용자는 해결 방안에 따라 최신버전으로 업데이트 권고 □ 설명 o Adobe Download Manager에서 발생하는 권한상승 취약점(CVE-2019-8071) [2] o Adobe Experience Manager Forms에서 XSS로 인해 발생하는 정보노출 취약점(CVE-2019-8089) [3] o Adobe Acrobat.. 더보기
Firefox Blocks Inline and Eval JavaScript on Internal Pages to Prevent Injection Attacks Source for https://thehackernews.com/2019/10/firefox-javascript-injection.html Firefox Blocks Inline and Eval JavaScript on Internal Pages to Prevent Injection Attacks Firefox Blocks Inline and Eval JavaScript From Internal Pages to Prevent Code Injection Attacks thehackernews.com In an effort to mitigate a large class of potential cross-site scripting issues in Firefox, Mozilla has blocked exec.. 더보기
Adobe Releases Out-of-Band Security Patches for 82 Flaws in Various Products Source for https://thehackernews.com/2019/10/adobe-software-patches.html Adobe Releases Out-of-Band Security Patches for 82 Flaws in Various Products Adobe Releases Out-of-Band Security Patches for 82 Flaws Affecting Various Products, including Adobe Acrobat and Reader, Adobe Experience Manager, Adobe Experience Manager Forms, Adobe Download Manager thehackernews.com No, it's not a patch Tuesday.. 더보기
Sudo Flaw Lets Linux Users Run Commands As Root Even When They're Restricted Source for https://thehackernews.com/2019/10/linux-sudo-run-as-root-flaw.html Sudo Flaw Lets Linux Users Run Commands As Root Even When They're Restricted A vulnerability in Sudo, tracked as CVE-2019-14287, could allow Linux users to run commands as root user even when they're restricted. thehackernews.com Attention Linux Users! A vulnerability has been discovered in Sudo—one of the most importa.. 더보기