DNS Reflection Update and Odd Corrupted DNS Requests, (Wed, Sep 25th)

Occasionally, I tend to check in on what reflective DNS denial of service attacks are doing. We usually see steady levels of attacks. Usually, they attempt to use spoofed requests for ANY records to achieve the highest possible amplification. Currently, I am seeing these two records used (among others):

Continue reading DNS Reflection Update and Odd Corrupted DNS Requests, (Wed, Sep 25th)

Posted in Uncategorized

Exploitation of RAISECOM Gateway Devices Vulnerability CVE-2024-7120, (Tue, Sep 24th)

image of SOH/Enterprise Gateway Raisecom MSG2200 series, msg2100E series.Late in July, a researcher using the alias “NETSECFISH” published a blog post revealing a vulnerability in RASIECOM gateway devices [1]. The vulnerability affects the “vpn/list_;base_;Config.php” endpoint and allows for unauthenticated remote code execution. According to Shodan, about 25,000 vulnerable devices are exposed to the internet.

Continue reading Exploitation of RAISECOM Gateway Devices Vulnerability CVE-2024-7120, (Tue, Sep 24th)

Posted in Uncategorized

Phishing links with @ sign and the need for effective security awareness building, (Mon, Sep 23rd)

While going over a batch of phishing e-mails that were delivered to us here at the Internet Storm Center during the first half of September, I noticed one message which was somewhat unusual. Not because it was untypically sophisticated or because it used some completely new technique, but rather because its authors took advantage of one of the less commonly misused aspects of the URI format – the ability to specify information about a user in the URI before its “host” part (domain or IP address).

Continue reading Phishing links with @ sign and the need for effective security awareness building, (Mon, Sep 23rd)

Posted in Uncategorized

Time-to-Live Analysis of DShield Data with Vega-Lite, (Wed, Sep 18th)

Since posting a diary about Vega-Lite [1], I have “played” with other queries that might be interesting and the first one that I wanted to explore since the DShield SIEM [2] capture and parse the iptables logs and store the Time-to-Live (TTL) for analysis.

Continue reading Time-to-Live Analysis of DShield Data with Vega-Lite, (Wed, Sep 18th)

Posted in Uncategorized