Skip to main content

Posts

Configuring NTP Server in HP Procurve Switches

Time is important for you to check logs. This time I'd like to show you how to configure NTP Server in HP Procurve Switches. HP Switches are only support less secure SNTP instead of NTP. OK. Let's Configure! Login to your switch with console/terminal and type following commands for your sntp server configuration. configure terminal timesync sntp sntp unicast (Use this command if you want to use only one NTP server) (or) sntp broadcast (Use this command if you want to use more than one NTP server) sntp server priority 1 218.186.3.36 (or) sntp server  218.186.3.36 (These above two commands are working on different model. Some model work first command and some model work second command. Please take note that you can configure maximum 3 NTP server for your switch. In my example, I use NTP server for Singapore) time timezone +480 (Formula for this command is GMT+Regional Time in Minute. I use Singapore Time and GMT+8. 8 hours in minute is 480. So result is GMT+48...

Resetting admin login password for GMS Application Interface of SonicWall GMS Virtual Appliance on UMA

If you have many SonicWall Firewall, it is not easy to manage without SonicWall GMS. GMS have two logins for System Interface and Application Interface. System Interface is to manage your GMS Hardware Appliance or Virtual Appliance. Application Interface is to manage your SonicWall devices in your network. So, you can contact to SonicWall Technical Support if you forgot the login password of GMS System Interface. But to do so, you need valid support contract/license. (So take note it and do not forget if you didn’t renew support contract/license. :P) For application interface login password, you do not need Tech Support if you know how. As human being, I am sure you will forget your password sometimes and here is how to reset the GMS Application Interface Password. First, you will see like below if you forgot password. You need MySQL Query Browser to access GMS Database in order to reset the password. 1.       Download it from bel...

Angler EK is exploiting Adobe Flash Vulnerability (CVE-2015-5560)

There is an integer overflow vulnerability in Adobe Flash Player 18.0.0.209 and earlier versions. The vulnerability is triggered when Flash Player loads and parses an contrived MP3 file with compressed ID3 data greater than 0x2aaaaaaa bytes. This causes an integer overflow in the buffer that allocates this data. This results in copying a large amount of data in to a small buffer. Not long after the disclosure of the vulnerability, Angler exploit kit has been cited to be using exploits for this vulnerability. The issues only affects 64bit platforms. The vulnerability is referred by CVE as CVE-2015-5560 . If you haven't patch your Security Devices, please patch them. Have a good time. (Be knowledgeable, pass it on then)

How to deploy 2.4GHz Wireless properly?

There are a lot of things to take note before we going to deploy 2.4GHz Wireless Network. If we select channel wrongly, stability and performance of our Wireless Network and it’s client will impact badly. As we know that we can get Channel 1 to 11 (1 to 13 in some devices) for 2.4GHz spectrum. A few channels are only non-overlap among these channel. Channel 1,6 and 11 for range between  1 to 11 are not overlap. Channel 1,5,9 and 13 for range between 1 to 13 are not overlap. Currently, many wireless routers automatically select the channel for you upon initial setup, where depending on your wireless environment, it could lead to slow Wi‑Fi speeds and interference.  It is not always right to configure Automation on channelization on Standlone or Controller Base Wireless devices. The following explanation will describe what interference you're dealing with and takes you through the steps to selecting the right channel, so you can understand why you should c...

OpenSSL X509_cmp_time DoS

After receiving the certificate (either from client to server or server to client) OpenSSL calls X509_cmp_time to perform various checks on the certificate including comparison of notBefore and notAfter validity times against the current time. The function allocates buffer to store bytes in VisibleString. The malformed VisibleString can lead to a read read-access violation, which leads to termination of application Using crafted certificate with malformed UTCTime or GeneralizedTime field Remote attacker can exploit this vulnerability causing denial of service. The vulnerability is referred by CVE as  CVE-2015-1789. If your security devices haven’t patch for this vulnerability, kindly look for update and patch it. If you are using Security Devices from Dell SonicWall, Dell SonicWALL has released an IPS signature to detect and block exploitation attempts targeting this vulnerability. The signature is listed below: 11109 OpenSSL X509 DoS 11110 OpenSSL X509 DoS 1 ...

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft has released an out-of-band security advisory on Aug 18, 2015 to address a critical Memory Corruption Vulnerability. It has been referred as MS15-093 . This vulnerability exists in Internet Explorer when the vulnerable versions of Internet Explorer improperly parse specially crafted webpage. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. It affects all versions of Internet Explorer. The affected users are suggested to install the update immediately, or apply the workarounds from the advisory The vulnerability is referred by CVE as   CVE-2015-2502.   Have a good time. (Be knowledgeable, pass it on then)

Microsoft Security Bulletin Coverage (August 11, 2015)

Microsoft has released security advisories as usual for month of August, 2015. You security devices, OS and Application should able to prevent below CVE ID. Otherwise, please patch first. If you are using Dell SonicWall Security Devices in your premises, then they all are patched. MS15-079  Cumulative Security Update fro Internet Explorer CVE-2015-2423  Unsafe Command Line Parameter Passing Vulnerability This is a local vulnerability. CVE-2015-2441  Memory Corruption Vulnerability There are no known exploits in the wild. CVE-2015-2442  Memory Corruption Vulnerability IPS: 11076  "Internet Explorer Memory Corruption Vulnerability (MS15-079) 1" CVE-2015-2443  Memory Corruption Vulnerability IPS: 11077  "Internet Explorer Memory Corruption Vulnerability (MS15-079) 2" CVE-2015-2444  Memory Corruption Vulnerability IPS: 11078  "Internet Explorer Memory Corruption ...