When you’re analyzing web applications as a pentester or reading pentest reports
about web applications, you will often see findings regarding cookies missing
certain security flags. The Set-Cookie HTTP header and the JavaScript
document.cookie API allow to use, for example, the
flags Secure, Path, and Domain.
Common audit and pentest tools will tell you when your web application does not
or just insecurely implements these cookie flags.
However, they do not provide optimal security even when using these flags
correctly. However, there are mitigations available that partly solve the
issues.
We recently conducted a security assessment of VMware Carbon Black Cloud, a
unified SaaS solution that integrates endpoint detection and response (EDR),
anti-virus, and vulnerability management capabilities. As part of our
evaluation, we tested the solution’s ability to detect and prevent malicious
activity on Windows and Linux systems. Our analysis focused on the Carbon Black
agents for these platforms, and although we did not identify any critical
vulnerabilities, we want to share some of the findings in this blog post.
As part of our research into
the Auracast feature set in Bluetooth, we also started looking into vendor
implementations. At the time we started with our research, there weren’t a lot
of products on the market yet. But new products are coming out pretty frequently
now.
One of the vendors that had Auracast implemented pretty early was Samsung. At
the time the Samsung Galaxy S23 and S24 phones were able to broadcast Audio,
while the Galaxy Buds were able to join these broadcasts.
Recently, one of our customers contacted us to investigate the extent of some
unwanted and unexpected behavior regarding browsing data of employees.
Employees started contacting IT support because private browser bookmarks,
private login credentials etc. showed up on their work machines. All affected
employees stated that they never created these bookmarks on work systems. And
interestingly, the data seemed to have been collected over quite some time.
Our customer wanted to understand how private data ended up in their
environment. Obviously, private employee data in the enterprise landscape could
cause some data privacy trouble (GDPR).
In a recent incident response project, we had the chance to virtually look over
the attackers’ shoulder and observe their activities. The attackers used the
Remote Desktop Protocol (RDP) for lateral movement within the compromized
environment and beyond (MITRE techniques
T1570,
T1021). As a matter of fact,
RDP creates cache files that contain tiles of the transferred screen recording
data. While this fact is well-known and there are existing tools, we found it
worth reporting because of two different aspects:
Auracast, the new Bluetooth LE Broadcast Audio feature has gained some publicity
in the past months. The Bluetooth SIG has introduced the LE Audio feature-set to
the Bluetooth 5.2 Specification in 2019 and vendors are only now starting to
implement it. Auracast facilitates broadcasting audio over Bluetooth LE to a
potentially unlimited number of devices. It does not require pairing or
interaction between the sender and the receivers.
We also presented this topic
at 38c3.
This blog post will contain similar contents albeit with some more details.
While conducting security research, I identified a critical vulnerability in
Kemp’s LoadMaster Load Balancer. This vulnerability is a
Command Injection
and allows full system compromise. It requires no authentication and can be
exploited remotely by having access to the Web User Interface (WUI). Kemp found
that all LoadMaster versions up to and including version 7.2.60.0 and also the
multi-tenant hypervisors up to and including version 7.1.35.11 are affected.
Kemp LoadMaster is a widely used Load Balancing Application that can commonly be
seen in customer engagements. Therefore, we decided to take a closer look as
part of our regular research projects.
During a penetration test for a customer, we briefly assessed
Vaultwarden, an open-source online
password safe. In June 2024, the German Federal Office for Information Security
(BSI) published results1 of a static and dynamic test of the Vaultwarden
server component. Therefore, only a partial source code audit was performed
during our assessment. However, a quick look was needed to find some glaring
issues with the authentication.
Vaultwarden
Vaultwarden is an alternative
online password safe server to Bitwarden and exposes the same API so that
Bitwarden clients can connect to the Vaultwarden server. Since Bitwarden has a
Browser client and Mobile clients, they can all connect to Vaultwarden, too.
during a recent Red Teaming engagement Marius Walter from
ERNW found a command injection issue in Progress (Kemp)
LoadMaster. It was registered as
CVE-2024-7591 and scores a
CVSS of 10.0.
The vendor already has patches out, make sure to apply them as this is a high
severe issue. You can find the official announcement and the patch references on
the
official support page.
Marius will follow up with a technical blog post on this issue once we think
everybody had a realistic chance of applying the patches.
Apple Automated Device Enrollment (ADE) is presented as a way to automate and
simplify the enrollment process of Apple devices within Mobile Device Management
(MDE) solutions. This blog post is aimed at organizations currently planning or
even already using this feature and making you, the reader, aware of potential
limitations of this process that might otherwise not be clearly addressed in
your companies’ device management process.
How Apple ADE Is Presented
Looking at the Apple Support pages today, Automated Device Enrollment is
described as a process that