Click here to Skip to main content
15,892,005 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
GeneralRe: These are the top ten software flaws used by crooks: Make sure you've applied the patches Pin
Rick York4-Feb-20 9:44
mveRick York4-Feb-20 9:44 
GeneralRe: These are the top ten software flaws used by crooks: Make sure you've applied the patches Pin
Mark_Wallace4-Feb-20 22:06
Mark_Wallace4-Feb-20 22:06 
GeneralRe: These are the top ten software flaws used by crooks: Make sure you've applied the patches Pin
Rick York5-Feb-20 4:50
mveRick York5-Feb-20 4:50 
GeneralRe: These are the top ten software flaws used by crooks: Make sure you've applied the patches Pin
Joe Woodbury4-Feb-20 9:54
professionalJoe Woodbury4-Feb-20 9:54 
GeneralRe: These are the top ten software flaws used by crooks: Make sure you've applied the patches Pin
Mark_Wallace4-Feb-20 22:05
Mark_Wallace4-Feb-20 22:05 
NewsReport: Alphabet working on software to make quantum computing more accessible Pin
Kent Sharkey4-Feb-20 8:16
staffKent Sharkey4-Feb-20 8:16 
NewsSome Google Photos videos in ‘Takeout’ backups were sent to strangers last November Pin
Kent Sharkey4-Feb-20 8:01
staffKent Sharkey4-Feb-20 8:01 
NewsTeam viewer stores encrypted passwords using the same key for all users (which has been publicly disclosed) and provides a path for privilege escalation to running as admin Pin
Dan Neely4-Feb-20 5:08
Dan Neely4-Feb-20 5:08 
TL;DR: TeamViewer stored user passwords encrypted with AES-128-CBC ... in the Windows registry. If the password is reused anywhere, privilege escalation is possible. If you do not have RDP rights to machine but TeamViewer is installed, you can use TeamViewer to remote in. TeamViewer also lets you copy data or schedule tasks to run through their Service, which runs as NT AUTHORITY\SYSTEM, so a low privilege user can immediately go to SYSTEM with a .bat file. This was assigned CVE-2019-18988.


The developers of Teamviewer went communication silent after the issue was reported in November, and so after being unable to get any followup the researcher who found the flaw has published in full.

Altogether now...

🤦🤦🏻🤦🏼🤦🏽🤦🏾🤦🏿🤦‍♂️🤦🏻‍♂️🤦🏼‍♂️🤦🏽‍♂️🤦🏾‍♂️🤦🏿‍♂️🤦‍♀️🤦🏻‍♀️🤦🏼‍♀️🤦🏽‍♀️🤦🏾‍♀️🤦🏿‍♀️
Did you ever see history portrayed as an old man with a wise brow and pulseless heart, weighing all things in the balance of reason?
Is not rather the genius of history like an eternal, imploring maiden, full of fire, with a burning heart and flaming soul, humanly warm and humanly beautiful?
--Zachris Topelius

Training a telescope on one’s own belly button will only reveal lint. You like that? You go right on staring at it. I prefer looking at galaxies.
-- Sarah Hoyt


modified 4-Feb-20 13:16pm.

GeneralRe: Team viewer stores encrypted passwords using the same key for all users (which has been publicly disclosed) and provides a path for privilege escalation to running as admin Pin
Marc Clifton4-Feb-20 5:52
mvaMarc Clifton4-Feb-20 5:52 
GeneralRe: Team viewer stores encrypted passwords using the same key for all users (which has been publicly disclosed) and provides a path for privilege escalation to running as admin Pin
Dan Neely4-Feb-20 5:59
Dan Neely4-Feb-20 5:59 
GeneralRe: Team viewer stores encrypted passwords using the same key for all users (which has been publicly disclosed) and provides a path for privilege escalation to running as admin Pin
Dave Kreskowiak4-Feb-20 6:23
mveDave Kreskowiak4-Feb-20 6:23 
GeneralRe: Team viewer stores encrypted passwords using the same key for all users (which has been publicly disclosed) and provides a path for privilege escalation to running as admin Pin
Rick York4-Feb-20 6:59
mveRick York4-Feb-20 6:59 
GeneralRe: Team viewer stores encrypted passwords using the same key for all users (which has been publicly disclosed) and provides a path for privilege escalation to running as admin Pin
phil.o4-Feb-20 7:24
professionalphil.o4-Feb-20 7:24 
NewsNext month Yahoo!’s time capsule will reveal the distant past… of 2006 Pin
Kent Sharkey3-Feb-20 11:46
staffKent Sharkey3-Feb-20 11:46 
GeneralRe: Next month Yahoo!’s time capsule will reveal the distant past… of 2006 Pin
Mark_Wallace3-Feb-20 20:08
Mark_Wallace3-Feb-20 20:08 
GeneralRe: Next month Yahoo!’s time capsule will reveal the distant past… of 2006 Pin
Kornfeld Eliyahu Peter3-Feb-20 21:24
professionalKornfeld Eliyahu Peter3-Feb-20 21:24 
GeneralRe: Next month Yahoo!’s time capsule will reveal the distant past… of 2006 Pin
Rick York4-Feb-20 9:44
mveRick York4-Feb-20 9:44 
NewsThe three types of code Pin
Kent Sharkey3-Feb-20 11:01
staffKent Sharkey3-Feb-20 11:01 
GeneralRe: The three types of code Pin
virang_213-Feb-20 11:23
virang_213-Feb-20 11:23 
GeneralRe: The three types of code Pin
Eddy Vluggen3-Feb-20 12:04
professionalEddy Vluggen3-Feb-20 12:04 
GeneralRe: The three types of code Pin
Mark_Wallace3-Feb-20 11:42
Mark_Wallace3-Feb-20 11:42 
GeneralRe: The three types of code Pin
Marc Clifton4-Feb-20 5:54
mvaMarc Clifton4-Feb-20 5:54 
NewsAgile software development is dead. Deal with it Pin
Kent Sharkey3-Feb-20 11:01
staffKent Sharkey3-Feb-20 11:01 
GeneralRe: Agile software development is dead. Deal with it Pin
Mark_Wallace3-Feb-20 11:48
Mark_Wallace3-Feb-20 11:48 
GeneralRe: Agile software development is dead. Deal with it PinPopular
Tasadit3-Feb-20 22:20
Tasadit3-Feb-20 22:20 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.