October 2024 Activity with Username chenzilong, (Thu, Oct 31st)

After reviewing the Top 10 Not So Common SSH Usernames and Passwords &#;x26;#;x5b;1&#;x26;#;x5d; published by Johannes 2 weeks ago, I noticed activity by one in his list that we don&#;x26;#;39;t really know what it is. Beginning 12 October 2024, my DShield sensor started storing one of the usernames mentioned in his diary that I had never seen before (I have over a year of data). The username chenzilong has been used with 5 different passwords including, some combination with the same username. So far, this account activity has been used with 302 different IPs.

Continue reading October 2024 Activity with Username chenzilong, (Thu, Oct 31st)

Posted in Uncategorized

Apple Updates Everything, (Mon, Oct 28th)

Today, Apple released updates for all of its operating systems. These updates include new AI features. For iOS 18 users, the only upgrade path is iOS 18.1, which includes the AI features. Same for users of macOS 15 Sequoia. For older operating systems versions (iOS 17, macOS 13, and 14), patches are made available, addressing only the security issues.

Continue reading Apple Updates Everything, (Mon, Oct 28th)

Posted in Uncategorized

Self-contained HTML phishing attachment using Telegram to exfiltrate stolen credentials, (Mon, Oct 28th)

Phishing authors have long ago discovered that adding HTML attachments to the messages they send out can have significant benefits for them – especially since an HTML file can contain an entire credential-stealing web page and does not need to reach out to the internet for any other reason than to send the credentials a victim puts in a login form to an attacker-controlled server[1]. Since this approach can be significantly more effective than just pointing recipients to a URL somewhere on the internet, the technique of sending out entire credential-stealing pages as attachments has become quite commonplace.

Continue reading Self-contained HTML phishing attachment using Telegram to exfiltrate stolen credentials, (Mon, Oct 28th)

Posted in Uncategorized

Two currently (old) exploited Ivanti vulnerabilities, (Sun, Oct 27th)

Ivanti products have given us a rich corpus of vulnerabilities in recent months (years). Of course, we do see occasional scans attempting to exploit them. Just today, I spotted two of them. None of them is particularly new, but a reminder to keep patching (or disabling):

Continue reading Two currently (old) exploited Ivanti vulnerabilities, (Sun, Oct 27th)

Posted in Uncategorized

Development Features Enabled in Prodcution, (Thu, Oct 24th)

We do keep seeing attackers “poking around” looking for enabled development features. Developers often use these features and plugins to aid in debugging web applications. But if left behind, they may provide an attacker with inside to the application. In their simplest form, these features provide detailed configuration information. More severe cases may leak credentials or even provide full remote code execution access.

Continue reading Development Features Enabled in Prodcution, (Thu, Oct 24th)

Posted in Uncategorized