cat

HP Data Protector Encrypted Communication Remote Command Execution

This Metasploit module exploits a well known remote code execution exploit after establishing encrypted control communications with a Data Protector agent. This allows exploitation of Data Protector agents that have been configured to only use encrypted control communications. This exploit works by executing the payload with Microsoft PowerShell so will only work against Windows Vista or newer. Tested against Data Protector 9.0 installed on Windows Server 2008 R2.




cat

Fortinet FortiSIEM 5.0 / 5.2.1 Improper Certification Validation

A FortiSIEM collector connects to a Supervisor/Worker over HTTPS TLS (443/TCP) to register itself as well as relaying event data such as syslog, netflow, SNMP, etc. When the Collector (the client) connects to the Supervisor/Worker (the server), the client does not validate the server-provided certificate against its root-CA store. Since the client does no server certificate validation, this means any certificate presented to the client will be considered valid and the connection will succeed. If an attacker spoofs a Worker/Supervisor using an ARP or DNS poisoning attack (or any other MITM attack), the Collector will blindly connect to the attacker's HTTPS TLS server. It will disclose the authentication password used along with any data being relayed. Versions 5.0 and 5.2.1 have been tested and are affected.




cat

Hashcat Advanced Password Recovery 4.0.0 Binary Release

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release..




cat

Hashcat Advanced Password Recovery 4.0.0 Source Code

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.




cat

Hashcat Advanced Password Recovery 4.0.1 Binary Release

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release.




cat

Hashcat Advanced Password Recovery 4.0.1 Source Code

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.




cat

Hashcat Advanced Password Recovery 4.1.0 Binary Release

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release.




cat

Hashcat Advanced Password Recovery 4.1.0 Source Code

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.




cat

Hashcat Advanced Password Recovery 4.2.0 Binary Release

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release.




cat

Hashcat Advanced Password Recovery 4.2.0 Source Code

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.




cat

Hashcat Advanced Password Recovery 4.2.1 Binary Release

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release.




cat

Hashcat Advanced Password Recovery 4.2.1 Source Code

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.




cat

Hashcat Advanced Password Recovery 5.0.0 Binary Release

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release.




cat

Hashcat Advanced Password Recovery 5.0.0 Source Code

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.




cat

Hashcat Advanced Password Recovery 5.1.0 Binary Release

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the binary release.




cat

Hashcat Advanced Password Recovery 5.1.0 Source Code

Hashcat is an advanced GPU hash cracking utility that includes the World's fastest md5crypt, phpass, mscash2 and WPA / WPA2 cracker. It also has the first and only GPGPU-based rule engine, focuses on highly iterated modern hashes, single dictionary-based attacks, and more. This is the source code release.







cat

iOS Application (In)Security

This whitepaper details some of the vulnerabilities observed over the past year while performing regular security assessments of iPhone and iPad applications. MDSec documents some of the vulnerabilities identified as well as the methods to exploit them, and recommendations that developers can adopt to protect their iOS applications. It covers not only the security features of the platform, but provides in depth information on how to perform both black box and white box iOS penetration tests, along with suggested methodologies and compliance.




cat

Cacti 1.2.8 Unauthenticated Remote Code Execution

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie if a guest user has the graph real-time privilege.




cat

Centreon Poller Authenticated Remote Command Execution

This Metasploit module exploits a flaw where an authenticated user with sufficient administrative rights to manage pollers can use this functionality to execute arbitrary commands remotely. Usually, the miscellaneous commands are used by the additional modules (to perform certain actions), by the scheduler for data processing, etc. This module uses this functionality to obtain a remote shell on the target.




cat

Fintech Locations of the Future 2019/20: London tops first ranking

London has been named fDi’s inaugural Fintech Location of the Future for 2019/20, followed by Singapore and Belfast. 




cat

Tourism Locations of the Future 2019/20 – FDI Strategy

Australia tops the FDI Strategy category of fDi's Tourism Locations of the Future 2019/20 rankings, followed by Costa Rica and Azerbaijan.




cat

DAWIN - Distributed Audit and Wireless Intrustion Notification

DA-WIN, a wireless IDS, provides an organization a continuous wireless scanning capability that is light touch and simple. It utilizes compact and discreet sensors that can easily be deployed reducing the total cost of protection and simplifying the effort required for absolute, categoric regulatory compliance. This archive includes a dd image to be used on a Raspberry Pi and a user manual.




cat

DAWIN - Distributed Audit and Wireless Intrustion Notification 2.0

DA-WIN, a wireless IDS, provides an organization a continuous wireless scanning capability that is light touch and simple. It utilizes compact and discreet sensors that can easily be deployed reducing the total cost of protection and simplifying the effort required for absolute, categoric regulatory compliance. This archive includes a dd image to be used on a Raspberry Pi and a user manual.




cat

Teltonika RUT9XX Unauthenticated OS Command Injection

Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute arbitrary commands with root privileges.




cat

FLIR Systems FLIR Brickstream 3D+ Unauthenticated Config Download File Disclosure

The FLIR Brickstream 3D+ sensor is vulnerable to unauthenticated config download and file disclosure vulnerability when calling the ExportConfig REST API (getConfigExportFile.cgi). This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation and/or full system access.




cat

Synaccess netBooter NP-02x / NP-08x 6.8 Authentication Bypass

Synaccess netBooter NP-02x and NP-08x version 6.8 suffer from an authentication bypass vulnerability due to a missing control check when calling the webNewAcct.cgi script while creating users. This allows an unauthenticated attacker to create an admin user account and bypass authentication giving her the power to turn off a power supply to a resource.




cat

ABB IDAL HTTP Server Authentication Bypass

The IDAL HTTP server CGI interface contains a URL, which allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. In the IDAL CGI interface, there is a URL (/cgi/loginDefaultUser), which will create a session in an authenticated state and return the session ID along with the username and plaintext password of the user. An attacker can then login with the provided credentials or supply the string 'IDALToken=......' in a cookie which will allow them to perform privileged operations such as restarting the service with /cgi/restart.




cat

D-Link DIR-859 Unauthenticated Remote Command Execution

D-Link DIR-859 Routers are vulnerable to OS command injection via the UPnP interface. The vulnerability exists in /gena.cgi (function genacgi_main() in /htdocs/cgibin), which is accessible without credentials.





cat

Kuwait pins hopes on diversification with Vision 2035

Kuwait's National Vision 2035 has economic diversification at its heart. This move from hydrocarbon reliance to other sectors is attracting investor attention, as Wendy Atkins reports.




cat

Dublin tops European HQ location rankings

The UK is the top country, but Dublin is leading city, for foreign companies setting up headquarters in Europe, according to fDi’s ranking.




cat

Solar industry, advocates hail New York passage of ambitious climate bill

New York’s Climate Leadership and Community Protection Act passed the Assembly early in the morning of June 20 and will now await the governor’s signature. Solar advocates praised the state legislature’s adoption of long anticipated legislation that will require at least 70 percent of electric generation come from renewable sources by 2030 and providing needed funding to low-income and environmental justice communities.




cat

Educating today’s utilities about tomorrow’s innovations

Last week in San Antonio, Texas, about 150 DISTRIBUTECH stakeholders convened to discuss industry trends, best practices for marketing and sales in the utility industry and set the educational agenda for the 2020 event.




cat

Understanding ‘safe harbor’ for extending your 30 percent solar ITC qualification

Just after the midnight hour of New Year’s Eve 2020, more than confetti will be abandoned on America’s sidewalks and parlors. Somewhere around $130 million dollars of Investment Tax Credit (ITC) from that year’s anticipated Commercial & Industrial solar projects will fall out from any hope of reaching the proverbial pocket books of the nation’s infrastructure investors (assuming 2000MW of C&I and Community solar, and a $2/w installation cost). On 1/1/20, the ITC drops to 26 percent, a first step to further decrease the following year.




cat

Get ‘renewable therapy’ during next week’s Solar Education Week

The Redford Center, a California-based non-profit co-founded in 2005 by Robert Redford and his son, James, announced that every morning, from April 15-22, 2019, the organization will post an episode a day of "Renewable Therapy for Climate Anxiety," a conversational mini-series featuring Filmmaker, James Redford, and Matthew Nordan, clean energy investor and managing partner at MNL Partners. In each two-minute installment, the pair explores questions that nag environmentalists when it comes to renewable energy. Watch the first episode below.




cat

Six schools in Minnesota saving money, boosting education with solar

New Energy Equity, Region Five Development Commission (R5DC) and Rural Renewable Energy Alliance (RREAL) last week announced a partnership to develop six solar arrays, totaling 1.5 MW, for Pine River-Backus and Pequot Lakes school districts and Central Lakes College.




cat

Mock REST Backend Server for Angular and React Applications.

As I promised to continue the Angular/Ionic project series, as a developer perspective mock server is the most important to progress the development. We should not depend on the production or development API for front-end development. This post is about creating a simple Node Express server with mock JSON object files. You can import the project to any of the front-end applications like Angular, React, Ionic and VueJS projects.





cat

Ionic 5 and Angular 8: Restful API User Authentication Login and Signup using Guard and Resolver

This is a continuation of my previous article creating an Ionic Angular project with welcome and tabs home page. Today’s post explains how to implement login authentication system for your Ionic Angular application with guards and resolvers. It will show you how to log in with a user and store the user data and protect the routes, so it deals with token-based authentication. Every user details will be stored in an external database and a PHP based API is used in the backend for handling this authentication.





cat

Report: $2.4 Trillion Clean Energy Investment Needed To Avoid Climate Catastrophe

The world must invest $2.4 trillion in clean energy every year through 2035 and cut the use of coal-fired power to almost nothing by 2050 to avoid catastrophic damage from climate change, according to scientists convened by the United Nations.




cat

Global Electrification Goals Are Driving Microgrid Market

According to the Microgrid Market Growth Potential - Industry Size Outlook Report 2024, the microgrid market is expected to reach $19 billion by 2024, nearly five times the original valuation of this business space in 2016.




cat

Educating today’s utilities about tomorrow’s innovations

Last week in San Antonio, Texas, about 150 DISTRIBUTECH stakeholders convened to discuss industry trends, best practices for marketing and sales in the utility industry and set the educational agenda for the 2020 event.




cat

IHA re-elected to steering committee of REN21, advocating for hydropower

The International Hydropower Association has been re-elected to the steering committee of the Renewable Energy Policy Network for the 21st Century (REN21).




cat

Dedication ceremony held for 105-MW Meldahl hydroelectric plant in Kentucky

American Municipal Power and the city of Hamilton held a dedication ceremony for the 105-MW Meldahl hydroelectric plant on June 2.




cat

Developers of 99.9-MW Glyn Rhonwy pumped-storage project withdraw permit applications

Hydroelectric power developer Snowdonia Pumped Hydro has withdrawn its application for environmental permits for the 99.9-MW Glyn Rhonwy pumped-storage plant from Natural Resources Wales.




cat

Indian Cabinet approves US$854.4 million investment for 900-MW Arun 3 hydropower project located in Nepal

India’s Cabinet Committee on Economic Affairs announced today it has approved investment for the generation component of the 900-MW Arun 3 hydropower project on Arun River in Sankhuwasabha district of eastern Nepal, for an estimated Rs. 5723.72 crore (US$854.4 million).
 




cat

Get ‘renewable therapy’ during next week’s Solar Education Week

The Redford Center, a California-based non-profit co-founded in 2005 by Robert Redford and his son, James, announced that every morning, from April 15-22, 2019, the organization will post an episode a day of "Renewable Therapy for Climate Anxiety," a conversational mini-series featuring Filmmaker, James Redford, and Matthew Nordan, clean energy investor and managing partner at MNL Partners. In each two-minute installment, the pair explores questions that nag environmentalists when it comes to renewable energy. Watch the first episode below.




cat

Advocates want next phase of ComEd microgrid powered by renewables

Stakeholders including clean energy and community groups are watching closely as ComEd begins the second phase of a microgrid pilot project in Chicago.