Telekom Security Updates
-
T-Pot Version 19.03 released
In Mach 2019 we released T-Pot 19.03. Read more Details here.
Continue Reading -
WeBid Directory Traversal, Blind SQL Injection and XSS
Multiple vulnerabilities were identified in version 1.2.2 of the popular “WeBid” open source auction system. Patches for all three vulnerabilities are available in their GitHub, and will be included in the next release.
Continue Reading -
ServiceNow Glide Scripting injection leading to privilege escalation
ServiceNow, an enterprise IT service management solution, is vulnerable to an templateinjection vulnerability, leading to a full privilege escalation.
Continue Reading -
Variant of Satori/Mirai detected attacking public available ADB shells
On the 10th of July at 23:30 UTC we noticed an increased traffic on our blackhole monitoring on TCP port 5555. Upon further analysis, we saw a big chunk of this traffic coming from China, USA and the Dominican Republic. In total we gathe...
Continue Reading -
Trovebox - Authentication Bypass, SQLi, SSRF
Trovebox, a photo sharing and management application, is prone to several criticalvulnerabilities. Exploiting is trivial and it is recommended to updateto the fixed version from Github.
Continue Reading -
Potherder: a Honeypot Story
It’s been seven years now that I started to contribute to the setup of Deutsche Telekom’s Early Warning System which is running multiple honeypots all over the globe and I would like to share my personal view on the history of the projec...
Continue Reading -
Opensourcing our Honeypot Backend (well, parts of it)
The last years we have consistently supported the community by releasing new versions of our multi honeypot platform called T-Pot. This November we areproud to release a new version of T-Pot with exciting new features and …something more.
Continue Reading