Should You Send Your Pen Test Report to the MSRC?

2018-11-13 KENNETH 0

Should You Send Your Pen Test Report to the MSRC? Every day, the Microsoft Security Response Center (MSRC) receives vulnerability reports from security researchers, technology/industry partners, and customers. We want those reports, because they help us make our products and services more secure. High-quality reports that include proof of concept, details of an attack or demonstration of a vulnerability, and a detailed writeup of the issue are extremely helpful and actionable. If you send these reports to us, thank you! Customers seeking to evaluate and harden their environments may ask penetration testers to probe their deployment and report on the findings. These reports can help that customer find and correct security risk(s) in their deployment. The catch is that the pen test report findings need to be evaluated in the context of that customer’s group policy objects, mitigations, tools, and [ more… ]

No Image

USN-3816-1: systemd vulnerabilities

2018-11-13 KENNETH 0

USN-3816-1: systemd vulnerabilities systemd vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in systemd. Software Description systemd – system and service manager Details Jann Horn discovered that unit_deserialize incorrectly handled status messages above a certain length. A local attacker could potentially exploit this via NotifyAccess to inject arbitrary state across re-execution and obtain root privileges. (CVE-2018-15686) Jann Horn discovered a race condition in chown_one(). A local attacker could potentially exploit this by setting arbitrary permissions on certain files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-15687) It was discovered that systemd-tmpfiles mishandled symlinks in non-terminal path components. A local attacker could potentially exploit this by gaining ownership of certain files to obtain root privileges. This [ more… ]

[도서] 마인크래프트와 함께 즐겁게 파이썬

2018-11-13 KENNETH 0

[도서] 마인크래프트와 함께 즐겁게 파이썬 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]마인크래프트와 함께 즐겁게 파이썬 최일선 저 | 비제이퍼블릭(BJ퍼블릭) | 2018년 11월 판매가 23,400원 (10%할인) | YES포인트 1,300원(5%지급) 이벤트 : 주목 IT 신간&예약판매 사은품 이벤트 게임으로 재미있게 배우는 코딩과 알고리즘! 『마인크래프트와 함께 즐겁게 파이썬』은 초중급 난이도로, 재미있게 즐기는 게임과 공부를 동시에 하고 싶은 학생들, 학생들에게 실무에서 사용되는 프로그래밍 기 Source: [도서] 마인크래프트와 함께 즐겁게 파이썬

Surface Go with LTE Advanced available now

2018-11-12 KENNETH 0

Surface Go with LTE Advanced available now In July we introduced Surface Go, our lightest, most compact Surface yet. Since then, we have seen strong momentum for Surface Go. Business customers tell us they love Surface Go because it is compact, performant, manageable, affordable, and offers advanced security with Windows 10 Pro. Surface Go is a great device for Firstline Workers who are out in the field, directly interacting with customers. In K-8 classrooms, Surface Go provides a versatile device for sparking creativity and inspiring exploration. Today, we are excited to announce that Surface Go with LTE Advanced is available for pre-order in select markets. Surface Go with LTE Advanced for Business offers organizations the perfect balance of performance, portability and connectivity[1] their Firstline Workers need to get the job done in the field. Imagine: No more dependence on Wi-Fi [ more… ]

No Image

USN-3815-2: gettext vulnerability

2018-11-12 KENNETH 0

USN-3815-2: gettext vulnerability gettext vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 ESM Summary gettext could be made to execute arbitrary code if it received a specially crafted message. Software Description gettext – GNU Internationalization utilities Details USN-3815-1 fixed a vulnerability in gettext. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM gettext – 0.18.1.1-5ubuntu3.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References USN-3815-1 CVE-2018-18751 Source: USN-3815-2: gettext vulnerability