banner Expire 1 July 2024
Ad Ends 13 July 2024
banner Expire 15 July 2024
banner Expire 18 October 2024
ad End 18 October 2024
Ad Ends 13 July 2023
banner Expire 20 May 2024
What's new
Ad expire at 5 May 2024
UniCvv
CrdCrew.cc Carding forum
Western union transfer
Carding.pw carding forum
adv exp at 23 may

Anonymous

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 21, 2020
Messages
5,630
Reaction score
1,363
Points
1,012
Awards
4
  • Rich User
  • trusted user
  • Somebody Likes you
  • First post
CISA and the FBI are calling for urgent measures to protect the code.

CISA and the FBI called on software developers to more actively identify and eliminate path traversal vulnerabilities before releasing products to the market. Such flaws allow an attacker to create or overwrite critical files, which violates authentication mechanisms and leads to remote code execution.

Agencies emphasize that such actions become possible due to insufficient protection on the part of technology manufacturers, who do not consider the data provided by users as potentially malicious. These vulnerabilities can give hackers access to confidential information, including credentials, which can then be used for brute-force attacks.

The problem is compounded by the fact that such vulnerabilities have been known as "unforgivable" for many years, but despite this, they are still widespread, as confirmed by studies of the CWE-22 and CWE-23 vulnerability classes.

The FBI and CISA recommended that developers take proven precautions, including:

  • generate a random ID for each file and store the associated metadata separately from the file name;
  • limiting the types of characters that can be used in file names;
  • ensuring that uploaded files do not have execution rights.

The reason for this warning was recent attacks on critical infrastructure, including in the health and public health sectors, where attackers used directory navigation vulnerabilities to implement their campaigns. For example, in attacks using the ScreenConnect vulnerability CVE-2024-1708.

Directory traversal vulnerabilities ranked 8th in the MITRE ranking of the 25 most dangerous software vulnerabilities, behind threats such as out-of-bounds, cross - site scripting (XSS), and SQL injection.
 
Ad End 1 July 2024
Top