Posted by malvuln on Feb 16
Discovery / credits: Malvuln – malvuln.com (c) 2022
Original source:
https://malvuln.com/advisory/65a53a37843db2b86a67a9e23277c1bf.txt
Contact: malvuln13 () gmail com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Prorat.lkt
Vulnerability: Weak Hardcoded Password
Description: The malware listens on TCP port 2121. Authentication is
required, however the password “special” is weak and hardcoded in cleartext
at offset 0040267C.
Type:…
More Stories
golang-github-cncf-xds-0-0.10.20230912gite9ce688.fc39 golang-github-envoyproxy-control-plane-0.11.1-1.fc39 golang-github-nats-io-1.30.1-1.fc39 golang-github-nats-io-jwt-2-2.5.2-1.fc39 golang-github-nats-io-nkeys-0.4.5-2.fc39 golang-github-protobuf-1.5.3-3.fc39 golang-google-protobuf-1.31.0-4.fc39 nats-server-2.10.1-3.fc39
FEDORA-2023-6b89bc0305 Packages in this update: golang-github-cncf-xds-0-0.10.20230912gite9ce688.fc39 golang-github-envoyproxy-control-plane-0.11.1-1.fc39 golang-github-nats-io-1.30.1-1.fc39 golang-github-nats-io-jwt-2-2.5.2-1.fc39 golang-github-nats-io-nkeys-0.4.5-2.fc39 golang-github-protobuf-1.5.3-3.fc39 golang-google-protobuf-1.31.0-4.fc39 nats-server-2.10.1-3.fc39 Update description: Contains updates to address CVE-2022-{28357,41717}...
bind-9.18.19-1.fc39 bind-dyndb-ldap-11.10-21.fc39
FEDORA-2023-b4acb0f7c6 Packages in this update: bind-9.18.19-1.fc39 bind-dyndb-ldap-11.10-21.fc39 Update description: BIND 9.18.19 Security Fixes Previously, sending a specially crafted message over...
golang-github-nats-io-1.30.1-1.fc40 golang-github-protobuf-1.5.3-3.fc40 nats-server-2.10.1-3.fc40
FEDORA-2023-5f904f4dd4 Packages in this update: golang-github-nats-io-1.30.1-1.fc40 golang-github-protobuf-1.5.3-3.fc40 nats-server-2.10.1-3.fc40 Update description: Contains updates to address CVE-2022-{28357,41717} Read More
[tool] WatchGuard Firebox Web Update Unpacker
Posted by retset on Sep 25 A small utility for extracting file system images from "sysa-dl" update files. https://github.com/ret5et/Watchguard_WebUI_Unpacker Read...
CVE-2022-4244
A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and...
CVE-2022-4245
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that...