JSOC INSIGHT vol.23 English Edition
26 NOV 2019 | JSOC INSIGHT
"JSOC INSIGHT" is an analysis report on the trend of security incidents, such as unauthorized access and malware infection, in Japan, based on daily analysis results by our JSOC security analysts. Since this report analyzes the trends in attacks, based on the data of incidents which JSOC customers actually encountered, the report will help in understanding world trends as well as actual threats that Japanese users are facing.
JSOC INSIGHT vol.23 contains below topics.
- Arbitrary code execution vulnerability in ThinkPHP Framework
- Authentication bypass vulnerability in a WP Portable phpMyAdmin plugin
- WP GDPR Compliance vulnerability
Contents
- Preface
- Executive Summary
- Trends in Severe Incidents at the JSOC
3.1 Trends in severe incidents
3.2 Types of Traffic to Pay Attention to - Topics of This Volume
4.1 Arbitrary code execution vulnerability in ThinkPHP Framework
4.1.1 Vulnerability summary
4.1.2 Example of attacks detected that exploited the vulnerability
4.1.3 Countermeasures against the vulnerability
4.2 Authentication bypass vulnerability in a WP Portable phpMyAdmin plugin
4.2.1 Changes in the number of attacks detected
4.2.2 Sources of attack traffic
4.2.3 Attack traffic contents detected
4.2.4 Countermeasures against the vulnerability
4.3 Reconfigurability vulnerability in a WP GDPR Compliance plugin
4.3.1 Testing the vulnerability
4.3.2 Trends of the detected attack traffic
4.3.3 Countermeasures against the vulnerability - Conclusion
Click here to download PDF file.