Year: 2017

Technical Analysis and Solution of WebLogic Server (WLS) Component Vulnerability

December 25, 2017

Overview Recently, NSFOCUS has received a slew of reports from customers in the finance, telecom, and Internet sectors on similar security events. Through analysis, NSFOCUS believes that these events are all associated with the malware-infected WebLogic Server (WLS) host. Specifically, attackers exploit the WLS component vulnerability (CVE-2017-10271) to attack the WLS middleware host via a […]

Miner Virus Attacked Large Numbers of WebLogic Hosts Recently

December 23, 2017

On the 15th this month, K.Orange twittered a message, saying that unpatched WebLogic has a vulnerability that could be employed by attackers using a “watch-smartd” program. Recently NSFOCUS received requests from customers in many industries (finance, telecom carriers, the Internet companies and so on) asking for emergence response service as they found the “watch-smartd” program […]

IcedID Banking Trojan Sample Technical Analysis and Solution

December 1, 2017

IcedID Banking Trojan Sample Technical Analysis and Solution Date of Release: November 17, 2017 Overview Recently, the IBM X-Force research team discovered a brand new banking Trojan dubbed IcedID. This Trojan was first found spreading in the wild in September 2017, mainly targeting systems used in the financial sectors of US. According to X-Force research, […]

NSFOCUS launches Web Application Firewall for SB Cloud in Japan

November 15, 2017

SB Cloud partners with NSFOCUS to bring the first ICSA and Veracode certified Web Application Firewall powered by NSFOCUS to its customers SINGAPORE, November 15, 2017 – NSFOCUS, the leader in holistic hybrid security solutions, is now offering its comprehensive Web Application Security solution on SB Cloud to provide enterprises with the most comprehensive application-layer […]

BadRabbit Sample Analysis and Recommended Solution

November 2, 2017

Overview A new type of ransomware was detected on October 24, when it had not been even half a year from the extensive breakout of the notorious ransomware Petya and WannaCry. This ransomware dubbed BadRabbit has been distributed in a number of European countries, including Russia, Ukraine, Bulgaria, Turkey, and Germany, and is now found […]

Technical Analysis Report on Rowdy, A New Type of IoT Malware Exploiting STBs

October 19, 2017

In August 2017, NSFOCUS’s DDoS situation awareness platform detected anoma-lous bandwidth usage over a customer’s network, which, upon analysis, was confirmed to be a distributed denial-of-service (DDoS) attack. The attack was characterized by different types of traffic, including TCP flood, HTTP flood, and DNS flood. Tracing source IP addresses, we found that the attack had […]

Past and Present of Underground Network Industry

October 19, 2017

The underground network industry has a long history and extensive coverage. What happened throughout its history? This document presents the definition, category, means, and examples of the underground network industry, as well as protection measures. Overview What is Underground Industry? Underground industry is a general name for a wide variety of behaviors which, using the […]

A Step Further — Demystifying XSS

October 17, 2017

Here is a comprehensive tutorial on cross-site scripting (XSS) attacks, ranging from entry to practice. Overview Note that XSS attacks are classified according to different angles in the preceding figure, but not simply classified into reflective XSS, stored XSS, and DOM-based XSS. In essence, XSS is injection of HTML code and JavaScript code. This kind […]

Analysis and Solution of Spring Data REST Server PATCH Request RCE Vulnerability

October 11, 2017

  Overview Recently, Pivotal released a security advisory to reveal the Spring Data REST server is prone to a remote code execution vulnerability (CVE-2017-8046) when processing PATCH requests. Attackers could exploit this vulnerability by sending a crafted PATCH request to the Spring Data REST server. The submitted JSON data contains a SPEL expression, which could […]

Pacific Internet Joined Forces with NSFOCUS to Deliver Cloud DDoS Defenses for Businesses across SEA

October 10, 2017

Strengthening suite of services to enhance customers’ enterprise security SINGAPORE, October 10, 2017 – Pacific Internet Singapore Pte Ltd, Southeast Asia’s Internet Service Provider, has signed up with NSFOCUS, a global enterprise DDoS (Distributed Denial of Service) mitigation solution provider, to complement its Internet services with best-in-class DDoS defense strategies. According to Deloitte’s Technology, Media […]

Search

Subscribe to the NSFOCUS Blog