IPFS phishing and the need for correctly set HTTP security headers, (Wed, Mar 15th)

In the last couple of weeks, I’ve noticed a small spike in the number of phishing messages that carried links to fake HTML login pages hosted on the InterPlanetary File System (IPFS) – an interesting web-based decentralized/peer-to-peer data storage system. Unfortunately, pretty much any type of internet-connected data storage solution is used to host malicious content by threat actors these days, and the IPFS is no exception. In fact, it seems to have been used to host phishing pages since at least the beginning of 2022[1].

Continue reading IPFS phishing and the need for correctly set HTTP security headers, (Wed, Mar 15th)→

Posted in Uncategorized

Microsoft March 2023 Patch Tuesday, (Tue, Mar 14th)

This month we got patches for 76 vulnerabilities. Of these, 9 are critical and 2 are already being exploited, according to Microsoft.
&#;x26;#;xd;
&#;x26;#;xd; One of the exploited vulnerabilities is an elevation of privilege affecting Microsoft Outlook (CVE-2023-23397). According to the advisory, an attacker who successfully exploited this vulnerability could access a user&#;x26;#;39;s Net-NTLMv2 hash which could be used as a basis of an NTLM Relay attack against another service to authenticate as the user. The attacker could exploit this vulnerability by sending a specially crafted email that triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane. The CVSS for this vulnerability is 9.8.
&#;x26;#;xd;
&#;x26;#;xd; The second exploit vulnerability is a security feature bypass affecting Windows SmartScreen (CVE-2023-24880). According to the advisory, an attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. The CVSS for this vulnerability is 5.4.
&#;x26;#;xd;
&#;x26;#;xd; There is another critical vulnerability worth mentioning which is Remote Code Execution (RCE) affecting HTTP Protocol Stack (CVE-2023-23392). A prerequisite for a server to be vulnerable is that the binding has HTTP/3 enabled and the server uses buffered I/O. HTTP/3 support for services is a new feature of Windows Server 2022. This vulnerability requires no user interaction, no privileges, and the attack complexity is low. The CVSS for this vulnerability is 9.8.
&#;x26;#;xd;
&#;x26;#;xd; See my dashboard for a more detailed breakout: https://patchtuesdaydashboard.com/

&#;x26;#;xd; Continue reading Microsoft March 2023 Patch Tuesday, (Tue, Mar 14th)→

Posted in Uncategorized

AsynRAT Trojan – Bill Payment (Pago de la factura), (Sun, Mar 12th)

This week the mail server quarantined this file FautraPago392023.gz. I did find it a bit strange after I extracted (gunzip) the file, there was no .exe extension associated with this file. The source and destination addresses are both blank without an actual email address.

Continue reading AsynRAT Trojan – Bill Payment (Pago de la factura), (Sun, Mar 12th)→

Posted in Uncategorized