Building a Security Shield for Your Applications with NGINX & Wallarm

2017-05-03 KENNETH 0

Building a Security Shield for Your Applications with NGINX & Wallarm td { padding-right: 10px; } This post is adapted from a presentation by Stepan Ilyan of Wallarm at nginx.conf in September 2016. You can view a recording of the presentation on YouTube. Table of Contents 0:00 Introduction   Who Am I? 0:34 Some Stats 1:38 Agenda 2:11 Why NGINX? 2:41 Attack Blocking with NGINX 3:05 Chapter 1 – Detect and Block 3:14 Tip #1 – Use ModSecurity WAF   Deployment is Easy   What The Rules Look Like   Core Rule Set (CRS)   More Rules, More Overhead   When ModSecurity Is A Pain   Best Practices   Use Request-Response   ModSecurity Handbook 9:27 Tip #2 – Use NAXSI   NAXSI Security Rules   Scoring-Based Protection   Example for SQLi   Whitelists   Pros and Cons   Kibana and Elasticsearch 12:57 Tip #3 – Try [ more… ]

No Image

USN-3273-1: LibreOffice vulnerabilities

2017-05-03 KENNETH 0

USN-3273-1: LibreOffice vulnerabilities Ubuntu Security Notice USN-3273-1 2nd May, 2017 libreoffice vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary LibreOffice could be made to crash or run programs as your login if it opened a specially crafted EMF file. Software description libreoffice – Office productivity suite Details It was discovered that LibreOffice incorrectly handled EMF image files.If a user were tricked into opening a specially crafted EMF image file, aremote attacker could cause LibreOffice to crash, and possibly executearbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.10: libreoffice-core 1:5.2.2-0ubuntu2.1 Ubuntu 16.04 LTS: libreoffice-core 1:5.1.6~rc2-0ubuntu1~xenial2 Ubuntu 14.04 LTS: libreoffice-core 1:4.2.8-0ubuntu5.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to [ more… ]

No Image

USN-3274-1: ICU vulnerabilities

2017-05-03 KENNETH 0

USN-3274-1: ICU vulnerabilities Ubuntu Security Notice USN-3274-1 2nd May, 2017 icu vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in ICU. Software description icu – International Components for Unicode library Details It was discovered that ICU incorrectly handled certain memory operationswhen processing data. If an application using ICU processed crafted data,a remote attacker could possibly cause it to crash or potentially executearbitrary code with the privileges of the user invoking the program. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: libicu57 57.1-5ubuntu0.1 Ubuntu 16.10: libicu57 57.1-4ubuntu0.2 Ubuntu 16.04 LTS: libicu55 55.1-7ubuntu0.2 Ubuntu 14.04 LTS: libicu52 52.1-3ubuntu0.6 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system [ more… ]

Introducing Surface Laptop, powered by Windows 10 S

2017-05-03 KENNETH 0

Introducing Surface Laptop, powered by Windows 10 S Earlier today, we shared our vision for empowering today’s students and teachers to create the world of tomorrow. This is a vision that resonates deeply with us on the Surface team because it taps directly into why we created Surface – to empower people to bring their ideas to life. To bring hardware and software together to transform the way people learn and create. This is what Surface has always been about. We built Surface Laptop to do two things: refresh the classic laptop form factor that our customers, especially college students, have been asking for; and make a Surface that works seamlessly to showcase the best of Windows 10 S. The result is the most personal and balanced Surface we’ve ever made. This Surface perfectly blends fabric and function, power and [ more… ]