Friday, August 17, 2018
Universal Declaration of Human Rights
Whereas recognition of the inherent dignity and of the equal and inalienable rights of all members of the human family is the foundation of freedom, justice and peace in the world,
Whereas disregard and contempt for human rights have resulted in barbarous acts which have outraged the conscience of mankind, and the advent of a world in which human beings shall enjoy freedom of speech and belief and freedom from fear and want has been proclaimed as the highest aspiration of the common people,
Whereas it is essential, if man is not to be compelled to have recourse, as a last resort, to rebellion against tyranny and oppression, that human rights should be protected by the rule of law,
Whereas it is essential to promote the development of friendly relations between nations,
Whereas the peoples of the United Nations have in the Charter reaffirmed their faith in fundamental human rights, in the dignity and worth of the human person and in the equal rights of men and women and have determined to promote social progress and better standards of life in larger freedom,
Whereas Member States have pledged themselves to achieve, in co-operation with the United Nations, the promotion of universal respect for and observance of human rights and fundamental freedoms,
Whereas a common understanding of these rights and freedoms is of the greatest importance for the full realization of this pledge,
Now, Therefore THE GENERAL ASSEMBLY proclaims THIS UNIVERSAL DECLARATION OF HUMAN RIGHTS as a common standard of achievement for all peoples and all nations, to the end that every individual and every organ of society, keeping this Declaration constantly in mind, shall strive by teaching and education to promote respect for these rights and freedoms and by progressive measures, national and international, to secure their universal and effective recognition and observance, both among the peoples of Member States themselves and among the peoples of territories under their jurisdiction.
Article 1.
All human beings are born free and equal in dignity and rights. They are endowed with reason and conscience and should act towards one another in a spirit of brotherhood.
Article 2.
Everyone is entitled to all the rights and freedoms set forth in this Declaration, without distinction of any kind, such as race, color, sex, language, religion, political or other opinion, national or social origin, property, birth or other status. Furthermore, no distinction shall be made on the basis of the political, jurisdictional or international status of the country or territory to which a person belongs, whether it be independent, trust, non-self-governing or under any other limitation of sovereignty.
Article 3.
Everyone has the right to life, liberty and security of person.
Article 4.
No one shall be held in slavery or servitude; slavery and the slave trade shall be prohibited in all their forms.
Article 5.
No one shall be subjected to torture or to cruel, inhuman or degrading treatment or punishment.
Article 6.
Everyone has the right to recognition everywhere as a person before the law.
Article 7.
All are equal before the law and are entitled without any discrimination to equal protection of the law. All are entitled to equal protection against any discrimination in violation of this Declaration and against any incitement to such discrimination.
Article 8.
Everyone has the right to an effective remedy by the competent national tribunals for acts violating the fundamental rights granted him by the constitution or by law.
Article 9.
No one shall be subjected to arbitrary arrest, detention or exile.
Article 10.
Everyone is entitled in full equality to a fair and public hearing by an independent and impartial tribunal, in the determination of his rights and obligations and of any criminal charge against him.
Article 11.
(1) Everyone charged with a penal offence has the right to be presumed innocent until proved guilty according to law in a public trial at which he has had all the guarantees necessary for his defence.
(2) No one shall be held guilty of any penal offence on account of any act or omission which did not constitute a penal offence, under national or international law, at the time when it was committed. Nor shall a heavier penalty be imposed than the one that was applicable at the time the penal offence was committed.
Article 12.
No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honor and reputation. Everyone has the right to the protection of the law against such interference or attacks.
Article 13.
(1) Everyone has the right to freedom of movement and residence within the borders of each state.
(2) Everyone has the right to leave any country, including his own, and to return to his country.
Article 14.
(1) Everyone has the right to seek and to enjoy in other countries asylum from persecution.
(2) This right may not be invoked in the case of prosecutions genuinely arising from non-political crimes or from acts contrary to the purposes and principles of the United Nations.
Article 15.
(1) Everyone has the right to a nationality.
(2) No one shall be arbitrarily deprived of his nationality nor denied the right to change his nationality.
Article 16.
(1) Men and women of full age, without any limitation due to race, nationality or religion, have the right to marry and to found a family. They are entitled to equal rights as to marriage, during marriage and at its dissolution.
(2) Marriage shall be entered into only with the free and full consent of the intending spouses.
(3) The family is the natural and fundamental group unit of society and is entitled to protection by society and the State.
Article 17.
(1) Everyone has the right to own property alone as well as in association with others.
(2) No one shall be arbitrarily deprived of his property.
Article 18.
Everyone has the right to freedom of thought, conscience and religion; this right includes freedom to change his religion or belief, and freedom, either alone or in community with others and in public or private, to manifest his religion or belief in teaching, practice, worship and observance.
Article 19.
Everyone has the right to freedom of opinion and expression; this right includes freedom to hold opinions without interference and to seek, receive and impart information and ideas through any media and regardless of frontiers.
Article 20.
(1) Everyone has the right to freedom of peaceful assembly and association.
(2) No one may be compelled to belong to an association.
Article 21.
(1) Everyone has the right to take part in the government of his country, directly or through freely chosen representatives.
(2) Everyone has the right of equal access to public service in his country.
(3) The will of the people shall be the basis of the authority of government; this will shall be expressed in periodic and genuine elections which shall be by universal and equal suffrage and shall be held by secret vote or by equivalent free voting procedures.
Article 22.
Everyone, as a member of society, has the right to social security and is entitled to realization, through national effort and international co-operation and in accordance with the organization and resources of each State, of the economic, social and cultural rights indispensable for his dignity and the free development of his personality.
Article 23.
(1) Everyone has the right to work, to free choice of employment, to just and favorable conditions of work and to protection against unemployment.
(2) Everyone, without any discrimination, has the right to equal pay for equal work.
(3) Everyone who works has the right to just and favorable remuneration ensuring for himself and his family an existence worthy of human dignity, and supplemented, if necessary, by other means of social protection.
(4) Everyone has the right to form and to join trade unions for the protection of his interests.
Article 24.
Everyone has the right to rest and leisure, including reasonable limitation of working hours and periodic holidays with pay.
Article 25.
(1) Everyone has the right to a standard of living adequate for the health and well-being of himself and of his family, including food, clothing, housing and medical care and necessary social services, and the right to security in the event of unemployment, sickness, disability, widowhood, old age or other lack of livelihood in circumstances beyond his control.
(2) Motherhood and childhood are entitled to special care and assistance. All children, whether born in or out of wedlock, shall enjoy the same social protection.
Article 26.
(1) Everyone has the right to education. Education shall be free, at least in the elementary and fundamental stages. Elementary education shall be compulsory. Technical and professional education shall be made generally available and higher education shall be equally accessible to all on the basis of merit.
(2) Education shall be directed to the full development of the human personality and to the strengthening of respect for human rights and fundamental freedoms. It shall promote understanding, tolerance and friendship among all nations, racial or religious groups, and shall further the activities of the United Nations for the maintenance of peace.
(3) Parents have a prior right to choose the kind of education that shall be given to their children.
Article 27.
(1) Everyone has the right freely to participate in the cultural life of the community, to enjoy the arts and to share in scientific advancement and its benefits.
(2) Everyone has the right to the protection of the moral and material interests resulting from any scientific, literary or artistic production of which he is the author.
Article 28.
Everyone is entitled to a social and international order in which the rights and freedoms set forth in this Declaration can be fully realized.
Article 29.
(1) Everyone has duties to the community in which alone the free and full development of his personality is possible.
(2) In the exercise of his rights and freedoms, everyone shall be subject only to such limitations as are determined by law solely for the purpose of securing due recognition and respect for the rights and freedoms of others and of meeting the just requirements of morality, public order and the general welfare in a democratic society.
(3) These rights and freedoms may in no case be exercised contrary to the purposes and principles of the United Nations.
Article 30.
Nothing in this Declaration may be interpreted as implying for any State, group or person any right to engage in any activity or to perform any act aimed at the destruction of any of the rights and freedoms set forth herein.
Source: United Nations
Sunday, January 7, 2018
Shakespeare and the Hiring Process
It was a great gig, but the working conditions kinda sucked. My desk was more-or-less in a hallway between the operations office and their sales office with the door leading to the elevator behind me. And it wasn't really a desk, it was one of those small reading tables you might find in a library. If I was going to use a reference book or read some of the Blackboard documentation I had to put my keyboard on top of the monitor.
The location was a perfect place to learn about 'The Big Apple'. It was on the 500 block of Broadway, NY which is between Houston (pronounced 'how-ston') and Canal Streets which put me right in the middle SOHO near the neighborhoods of China Town and Little Italy. It is this area of the city where at 5 p.m. the sidewalks are packed shoulder to shoulder with people trying to get to their train or bus so they can go home.
Regardless of the working conditions I had to stick-it-out, I rented a house on Staten Island having made the move from Taylorsville, NC.
At the end of 2000 the "dot.com" bubble was about to burst and NYU decided to take the endeavor in-house, reducing the funding. When they had released half of their sales and operational staff I saw the writing on the wall and went to Monster.com to find another ColdFusion position in New York City.
I had two job offers fairly quickly. ColdFusion programmers who can also do database work (now called "full-stack" developers) were a rare breed back then. It was only a couple of days before I had two interviews both of which turned into job offers.
The first was MarthaStewart.com. This was the time when Martha was at the top of her game and a full three years before she reported for a five-month term in federal prison for lying to federal investigators. They had a large staff working on her web presence, the offices were nice and fully decorated as an homage to Martha with pictures of her and food too pretty to eat.
The other was LAWTRAC.com. Their offices were on the eleventh floor of an office building on Montague Street in Brooklyn. Here I would be the only programmer taking an older application and converting it to a web-based offering.
With both offers being exactly the same dollar wise the choice was easy. I went to work for LAWTRAC where I would be 'the guy' with, more-or-less, a free hand to simply develop.
For the next fourteen years I was 'the guy'. Not only did I do all the application programming, but I designed the database, made the hosting and delivery decisions, added modules and functionality that no one in our industry of matter management software for corporate legal departments had or were even close to having.
I was in Hog's Heaven, working most of the time from my house on Staten Island, then moving to Brooklyn after a stabbing incident (another story) and finally to a neighborhood on Long Island called Carle Place.
I was fully engulfed in ColdFusion and database programming and the world of corporate legal needs and using the programming to meet those needs. I traveled the country doing product demos, working with customers, tradeshows and had speaking engagements on both corporate legal data management and ColdFusion programming techniques.
By 2009 we had hired two additional programmers. One had a focus on creating custom reports for clients and the other's forte was writing the data exchange packages so the legal and financial data could talk to other programs.
Life was great - I was THE big fish in a little pond, making great money and had earned five-percent ownership in the company, a reward for sticking around during the lean times when the company was struggling.
By the time we received our buy-out offer from Mitratech and Vista Equity Partners the software industry had completely recovered from the 'Dot.com' downturn. This recovery period ushered in more structure to the methodologies software companies were using to produce their products. The older method called "Waterfall" turned to piece-meal structure called "Agile". The industry incorporated things called Product Managers who worked with the clients to identify needed changes to continue to meet client needs. The Agile methodology also used positions called Scrum Masters who took the needed changes and broke the requirements down so the changes could be done in a structured, more modular method.
A far cry from what we at Lawtrac were doing. After all, with a programming staff of three we didn't need all that additional overhead because I was doing all the things Product Managers, Project Managers, and Scrum Masters were doing. And we were doing fine, we had clients like Oprah, United Technologies, all the major oil companies, health care equipment providers, Federal Express, even the American Bar Association used our software to track their legal matters.
The American Bar Association, getting them as a client was like getting the contract to provide the candles to the Vatican. To this day I don't understand why the new owners haven't leveraged that to boost their sales.
Mitratech is a 'best practices' company using the Agile method to produce software. So quickly I had to adapt; I took classes on Lynda.com, bought books from Amazon and by February of 2014 I was up to speed and had brought the Lawtrac development and support staff up to speed as well.
I realize now that during the time I was the 'big fish' writing the software I did so in a bubble. My world consisted of writing code, caring for customer needs, speaking at conferences, doing trade shows, generally helping to enrich my meager five-percent ownership. The industry of software production had introduced business processes I was unaware of and the handing-over of Lawtrac source code to Mitratech felt like landing on the moon.
But I had helped to build a software company. I fought the good fight and afterwards walked away with enough money to buy and furnish a house in Austin, TX. I moved there thinking that I would fit in at Mitratech and could continue working on what was more-or-less my baby and help it grow even more.
I eventually had to resign because the person at Mitratech (VP of Product Development) removed me from the role of being a programmer who worked with clients to continue to build a better product had placed me in a role of doing nothing more than support ticket changes and handed the day-to-day programming tasks to complete strangers.
Three years have gone buy, I'm still trying to fit in where I can use the ColdFusion and database programming skills I have to earn a living.
But I'm finding that software companies don't want learned programmers. The conventional hiring practice follows the acronym "HIPLE" which stands for 'High Potential, Low Experience'. Recently I interviewed with a company which does corporate patent and trademark software (which would be right up my ally) called iRunWay and they actually said during the interview that they were concerned how I would fit in with a staff made up of all younger people. Two months ago, I meet with a company called CoStar; I had gone through four interviews before they meet me in person and I guarantee you that the only reason they rejected me was my greying hair. I'm still getting calls from recruiters about that position, CoStar had no other reason to reject me.
Since leaving Mitratech I've worked to bring my skills up-to-date taking courses for my Project Manager Professional certificate and Amazon Web Services Architect certification.
Getting past the young recruiter staff software companies employ too has been a challenge. If I remove much of my work experience and the dates from my resume so my age is not as apparent I get calls, but once they begin to since I'm over thirty those calls go downhill very quickly.
The whole experience reminds me of Shakespeare's St. Crispin's Day Speech, the ending….
Shall think themselves accurs'd they were not here,
And hold their manhoods cheap whiles any speaks
Of all the start-up companies in Austin, TX you would think that one would like to have a seasoned programmer who would bring a 'been there, done that' attitude. One that has experienced programming pit-falls many on their HIPLE staffs will make.
But I really think Shakespeare was onto something. A recruiter or young hiring manager looks over my resume they experience their own feelings of having missed out on something, like the birth of the Internet and that history that has lead up to what the industry is today.
@TheCoStarGroup
@iRunwayInc
Wednesday, August 9, 2017
Whole Foods CEO John Mackey Announced as Keynote Speaker at Mitratech’s Interact 2017 Conference
The real story should be that Mitratech is paying John Mackey $75,000 to speak, he has little knowledge of what software his legal department needs or is using.
https://speaking.com/speakers/john-mackey/
Whole Foods CEO John Mackey Announced as Keynote Speaker at Mitratech’s Interact 2017 Conference
Friday, April 1, 2016
Armor Welcomes New Chief Marketing Officer Diana Massaro
The leader in active cyber defense, Armor offers customer-centric security outcomes for retail and eCommerce enterprises, healthcare organizations, payment leaders and financial institutions. Armor protects highly sensitive data for the most security-conscious companies in the world. With its proven cybersecurity approach and proprietary cloud infrastructure built specifically for security, compliance and performance, responsible businesses choose Armor to reduce their risk.
Armor Welcomes New Chief Marketing Officer Diana Massaro
Wednesday, March 2, 2016
IRS and US-CERT Caution Users: Prepare for Heightened Phishing Risk This Tax Season
Overview
Throughout the year, scam artists pose as legitimate entities—such as the Internal Revenue Service (IRS), other government agencies, and financial institutions—in an attempt to defraud taxpayers. They employ sophisticated phishing campaigns to lure users to malicious sites or entice them to activate malware in infected email attachments. To protect sensitive data, credentials, and payment information, US-CERT and the IRS recommend taxpayers prepare for heightened risk this tax season and remain vigilant year-round.Remain alert
Phishing attacks use email or malicious websites to solicit personal information by posing as a trustworthy organization. In many successful incidents, recipients are fooled into believing the phishing communication is from someone they trust. An actor may take advantage of knowledge gained from research and earlier attempts to masquerade as a legitimate source, including the look and feel of authentic communications. These targeted messages can trick any user into taking action that may compromise enterprise security.Spot common elements of the phishing lifecycle
- A Lure: enticing email content.
- A Hook: an email-based exploit.
- Email with embedded malicious content that is executed as a side effect of opening the email
- Email with malicious attachments that are activated as a side effect of opening an attachment
- Email with “clickable” URLs: the body of the email includes a link, which displays as a recognized, legitimate website, though the actual URL redirects the user to malicious content
- A Catch: a transaction conducted by an actor following a successful attempt.
- Unexplainable charges
- Unexplainable password changes
Understand how the IRS communicates electronically with taxpayers
- The IRS does not initiate contact with taxpayers by email, text messages or social media channels to request personal or financial information.
- This includes requests for PIN numbers, passwords or similar access information for credit cards, banks or other financial accounts.
- The official website of the IRS is www.irs.gov.
Take action to avoid becoming a victim
If you believe you might have revealed sensitive information about your organization or access credentials, report it to the appropriate contacts within the organization, including network administrators. They can be alert for any suspicious or unusual activity.Watch for any unexplainable charges to your financial accounts. If you believe your accounts may be compromised, contact your financial institution immediately and close those accounts.
If you believe you might have revealed sensitive account information, immediately change the passwords you might have revealed. If you used the same password for multiple accounts, make sure to change the password for each account and do not use that password in the future.
Report suspicious phishing communications
- Email: If you read an email claiming to be from the IRS, do not reply or click on attachments and/or links. Forward the email as-is to phishing@irs.gov (link sends e-mail), then delete the original email.
- Website: If you find a website that claims to be the IRS and suspect it is fraudulent, send the URL of the suspicious site to phishing@irs.gov (link sends e-mail) with subject line, “Suspicious website”.
- Text Message: If you receive a suspicious text message, do not reply or click on attachments and/or links. Forward the text as-is to 202-552-1226 (standard text rates apply), and then delete the original message (if you clicked on links in SMS and entered confidential information, visit the IRS’ identity protection page).
Additional Resources
For more information on phishing, other suspicious IRS-related communications including phone or fax scams, or additional guidance released by Treasury/IRS and DHS/US-CERT, visit:- Avoiding Social Engineering and Phishing Attacks
- Recognizing and Avoiding Email Scams
- Phishing and Other Schemes Using the IRS Name
- IRS Repeats Warning about Phone Scams
- Report Phishing and Online Scams
- Tips for Taxpayers, Victims about Identity Theft and Tax Returns
Tuesday, March 1, 2016
OpenSSL Security Advisory
OpenSSL has released updates to address vulnerabilities in prior versions. Exploitation of some of these vulnerabilities may allow a remote attacker to obtain sensitive information. Updates available include:
- OpenSSL 1.0.2g for 1.0.2 users
- OpenSSL 1.0.1s for 1.0.1 users
=========================================
NOTE: With this update, OpenSSL is disabling the SSLv2 protocol by default, as
well as removing SSLv2 EXPORT ciphers. We strongly advise against the use of
SSLv2 due not only to the issues described below, but to the other known
deficiencies in the protocol as described at
https://tools.ietf.org/html/rfc6176
Cross-protocol attack on TLS using SSLv2 (DROWN) (CVE-2016-0800)
================================================================
Severity: High
A cross-protocol attack was discovered that could lead to decryption of TLS
sessions by using a server supporting SSLv2 and EXPORT cipher suites as a
Bleichenbacher RSA padding oracle. Note that traffic between clients and
non-vulnerable servers can be decrypted provided another server supporting
SSLv2 and EXPORT ciphers (even with a different protocol such as SMTP, IMAP or
POP) shares the RSA keys of the non-vulnerable server. This vulnerability is
known as DROWN (CVE-2016-0800).
Recovering one session key requires the attacker to perform approximately 2^50
computation, as well as thousands of connections to the affected server. A more
efficient variant of the DROWN attack exists against unpatched OpenSSL servers
using versions that predate 1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf released on
19/Mar/2015 (see CVE-2016-0703 below).
Users can avoid this issue by disabling the SSLv2 protocol in all their SSL/TLS
servers, if they've not done so already. Disabling all SSLv2 ciphers is also
sufficient, provided the patches for CVE-2015-3197 (fixed in OpenSSL 1.0.1r and
1.0.2f) have been deployed. Servers that have not disabled the SSLv2 protocol,
and are not patched for CVE-2015-3197 are vulnerable to DROWN even if all SSLv2
ciphers are nominally disabled, because malicious clients can force the use of
SSLv2 with EXPORT ciphers.
OpenSSL 1.0.2g and 1.0.1s deploy the following mitigation against DROWN:
SSLv2 is now by default disabled at build-time. Builds that are not configured
with "enable-ssl2" will not support SSLv2. Even if "enable-ssl2" is used,
users who want to negotiate SSLv2 via the version-flexible SSLv23_method() will
need to explicitly call either of:
SSL_CTX_clear_options(ctx, SSL_OP_NO_SSLv2);
or
SSL_clear_options(ssl, SSL_OP_NO_SSLv2);
as appropriate. Even if either of those is used, or the application explicitly
uses the version-specific SSLv2_method() or its client or server variants,
SSLv2 ciphers vulnerable to exhaustive search key recovery have been removed.
Specifically, the SSLv2 40-bit EXPORT ciphers, and SSLv2 56-bit DES are no
longer available.
In addition, weak ciphers in SSLv3 and up are now disabled in default builds of
OpenSSL. Builds that are not configured with "enable-weak-ssl-ciphers" will
not provide any "EXPORT" or "LOW" strength ciphers.
OpenSSL 1.0.2 users should upgrade to 1.0.2g
OpenSSL 1.0.1 users should upgrade to 1.0.1s
More At: https://www.openssl.org/news/secadv/20160301.txt
Thursday, February 25, 2016
Drupal Critical Vulnerabilities
Drupal Core - Critical - Multiple Vulnerabilities - SA-CORE-2016-001
- Advisory ID: SA-CORE-2016-001
- Project: Drupal core
- Version: 6.x, 7.x, 8.x
- Date: 2016-February-24
- Security risk: 15/25 ( Critical) AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:All
- Vulnerability: Multiple vulnerabilities
Description
File upload access bypass and denial of service (File module - Drupal 7 and 8 - Moderately Critical)
A vulnerability exists in the File module that allows a malicious user to view, delete or substitute a link to a file that the victim has uploaded to a form while the form has not yet been submitted and processed. If an attacker carries out this attack continuously, all file uploads to a site could be blocked by deleting all temporary files before they can be saved.This vulnerability is mitigated by the fact that the attacker must have permission to create content or comment and upload files as part of that process.
Brute force amplification attacks via XML-RPC (XML-RPC server - Drupal 6 and 7 - Moderately Critical)
The XML-RPC system allows a large number of calls to the same method to be made at once, which can be used as an enabling factor in brute force attacks (for example, attempting to determine user passwords by submitting a large number of password variations at once).This vulnerability is mitigated by the fact that you must have enabled a module that provides an XML-RPC method that is vulnerable to brute-forcing. There are no such modules in Drupal 7 core, but Drupal 6 core is vulnerable via the Blog API module. It is additionally mitigated if flood control protection is in place for the method in question.
Open redirect via path manipulation (Base system - Drupal 6, 7 and 8 - Moderately Critical)
In Drupal 6 and 7, the current path can be populated with an external URL. This can lead to Open Redirect vulnerabilities.This vulnerability is mitigated by the fact that it would only occur in combination with custom code, or in certain cases if a user submits a form shown on a 404 page with a specially crafted URL.
For Drupal 8 this is a hardening against possible browser flaws handling certain redirect paths.
Form API ignores access restrictions on submit buttons (Form API - Drupal 6 - Critical)
An access bypass vulnerability was found that allows input to be submitted, for example using JavaScript, for form button elements that a user is not supposed to have access to because the button was blocked by setting #access to FALSE in the server-side form definition.This vulnerability is mitigated by the fact that the attacker must have access to submit a form that has such buttons defined for it (for example, a form that both administrators and non-administrators can access, but where administrators have additional buttons available to them).
HTTP header injection using line breaks (Base system - Drupal 6 - Moderately Critical)
A vulnerability in the drupal_set_header() function allows an HTTP header injection attack to be performed if user-generated content is passed as a header value on sites running PHP versions older than 5.1.2. If the content contains line breaks the user may be able to set arbitrary headers of their own choosing.This vulnerability is mitigated by the fact that most hosts have newer versions of PHP installed, and that it requires a module to be installed on the site that allows user-submitted data to appear in HTTP headers.
Open redirect via double-encoded 'destination' parameter (Base system - Drupal 6 - Moderately Critical)
The drupal_goto() function in Drupal 6 improperly decodes the contents of $_REQUEST['destination'] before using it, which allows the function's open redirect protection to be bypassed and allows an attacker to initiate a redirect to an arbitrary external URL.This vulnerability is mitigated by that fact that the attack is not possible for sites running on PHP 5.4.7 or greater.
Reflected file download vulnerability (System module - Drupal 6 and 7 - Moderately Critical)
Drupal core has a reflected file download vulnerability that could allow an attacker to trick a user into downloading and running a file with arbitrary JSON-encoded content.This vulnerability is mitigated by the fact that the victim must be a site administrator and that the full version of the attack only works with certain web browsers.
Saving user accounts can sometimes grant the user all roles (User module - Drupal 6 and 7 - Less Critical)
Some specific contributed or custom code may call Drupal's user_save() API in a manner different than Drupal core. Depending on the data that has been added to a form or the array prior to saving, this can lead to a user gaining all roles on a site.This issue is mitigated by the fact that it requires contributed or custom code that calls user_save() with an explicit category and code that loads all roles into the array.
Email address can be matched to an account (User module - Drupal 7 and 8 - Less Critical)
In certain configurations where a user's email addresses could be used to log in instead of their username, links to "have you forgotten your password" could reveal the username associated with a particular email address, leading to an information disclosure vulnerability.This issue is mitigated by the fact that it requires a contributed module to be installed that permits logging in with an email address, and that it is only relevant on sites where usernames are typically chosen to hide the users' real-life identities.
Session data truncation can lead to unserialization of user provided data (Base system - Drupal 6 - Less Critical)
On certain older versions of PHP, user-provided data stored in a Drupal session may be unserialized leading to possible remote code execution.This issue is mitigated by the fact that it requires an unusual set of circumstances to exploit and depends on the particular Drupal code that is running on the site. It is also believed to be mitigated by upgrading to PHP 5.4.45, 5.5.29, 5.6.13, or any higher version.
CVE identifier(s) issued (#)
- CVE identifiers will be requested, and added upon issuance, in accordance with Drupal Security Team processes.
Versions affected
- Drupal core 6.x versions prior to 6.38
- Drupal core 7.x versions prior to 7.43
- Drupal core 8.0.x versions prior to 8.0.4
Solution
Install the latest version:- If you use Drupal 6.x, upgrade to Drupal core 6.38
- If you use Drupal 7.x, upgrade to Drupal core 7.43
- If you use Drupal 8.0.x, upgrade to Drupal core 8.0.4
Reported by
File upload access bypass and denial of service:Brute force amplification attacks via XML-RPC:
- Stéphane Corlosquet of the Drupal Security Team
- Francesco Placella
- Heine Deelstra of the Drupal Security Team
- Pere Orga of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Gábor Hojtsy of the Drupal Security Team
- Damien Tournoud of the Drupal Security Team
- Daniel Kudwien
Open redirect via double-encoded 'destination' parameter:
- Tarpinder Grewal
- Harry Taheem
- David Rothstein of the Drupal Security Team
Saving user accounts can sometimes grant the user all roles:
Email address can be matched to an account:
Session data truncation can lead to unserialization of user provided data:
- David Jardin of the Joomla Security Team
- Damien Tournoud of the Drupal Security Team
- Heine Deelstra of the Drupal Security Team
Fixed by
File upload access bypass and denial of service:- fnqgpc
- Nathaniel Catchpole of the Drupal Security Team
- Ben Dougherty of the Drupal Security Team
- Lee Rowlands of the Drupal Security Team
- Sascha Grossenbacher
- Gábor Hojtsy of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team
- Klaus Purer of the Drupal Security Team
- David Rothstein of the Drupal Security Team
- Stefan Ruijsenaars, provisional member of the Drupal Security Team
- Cathy Theys, provisional member of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Frédéric G. Marand, provisional member of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Nathaniel Catchpole of the Drupal Security Team
- Ben Dougherty of the Drupal Security Team
- Alan Evans
- Nate Haug
- Gábor Hojtsy of the Drupal Security Team
- Heine Deelstra of the Drupal Security Team
- David Stoline of the Drupal Security Team
- Damien McKenna, Provisional member of the Drupal Security Team
- Pere Orga of the Drupal Security Team
- Francesco Placella
- Dave Reid of the Drupal Security Team
- David Rothstein of the Drupal Security Team
- Lee Rowlands of the Drupal Security Team
- David Snopek of the Drupal Security Team
- Cathy Theys, provisional member of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- chx
- Daniel Kudwien
- Alex Bronstein of the Drupal Security Team
- Heine Deelstra of the Drupal Security Team
- Dmitri Gaskin
- Nate Haug
- John Morahan
- David Rothstein of the Drupal Security Team
- Damien Tournoud of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Dave Hansen-Lange
- David Rothstein of the Drupal Security Team
- Nathaniel Catchpole of the Drupal Security Team
- Klaus Purer of the Drupal Security Team
- David Rothstein of the Drupal Security Team
- Alex Bronstein of the Drupal Security Team
- Juho Nurminen
- David Rothstein of the Drupal Security Team
- Damien Tournoud of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Nate Haug
- Dave Cohen
- Greg Knaddison of the Drupal Security Team
- Rick Manelius of the Drupal Security Team
- Balazs Nagykekesi
- David Rothstein of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Klaus Purer of the Drupal Security Team
- David Rothstein of the Drupal Security Team
- Heine Deelstra of the Drupal Security Team
- Damien Tournoud of the Drupal Security Team
- David Rothstein of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
Coordinated by
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.
Follow the Drupal Security Team on Twitter at https://twitter.com/drupalsecurity
Monday, March 9, 2015
23andMe Appoints Kate Black as Privacy Officer and Corporate Counsel
This is just another example of the current growing pains corporations are experiencing as we move further into the ‘Internet of Things’.
A lot of corporations have introduced the additional “C” level position for “Technology”. The “Chief Technology Officer” is responsible not only for the electronic tools the company uses to produce goods and services but interact with its customers and partners.
As local, state and federal governments begin to apply additional regulations reflective of current technologies it is becoming more-and-more the responsibility of the legal department to maintain a constant watch on the governance and compliance pulse of the company. If you haven’t bumped into the acronym of “GRC” (Governance, Regulation and Compliance) you soon will.
This is where the two (dare I use the phrase) ‘silos’ of the company begin to converge; and not for the better, something will fall through the cracks.
My view from the cheep seats….
Companies who trade directly in the world of finance have in their offices individuals who report to their government oversight organizations. These individuals monitor the company’s activities and provide on-the-spot oversight. Same too do companies who provide food sold to and consumed by the citizens of the US. These USDA officials report to a government oversight body, but provide (again) on-the-spot correction directives.
Corporate boards need to set-up the same idea in their corporations. Someone who is going to perform government compliance (at all oversight levels) activities and provide on-the-spot corrective directions in real time. This person reports to the corporate board; because he / she needs to be able to interact with the CTO and Legal departments without fear of reprisals.
Important: Either the corporate boards begin to do this or we may find ourselves in the very near future having a government representative sitting in product development, account processing, and all aspects of our companies including human resources, etc., etc., etc.
So congratulations to Ms. Black on her new appointment. Taking on the Legal department and trying to make sure you are in compliance with every state in the country, and every country you do business is going to be a very daunting endeavor.
Wednesday, February 25, 2015
US offers highest-ever cybercrime reward for arrest of Russian hacker | US news | The Guardian
The United States is offering a $3M reward for the arrest or conviction of a Russian national.
According to the story, he has stole more than $100M form online bank accounts.
The article is an interesting read.
US offers highest-ever cybercrime reward for arrest of Russian hacker | US news | The Guardian
Thursday, May 24, 2012
Legal Considerations - Social Media
Monday, October 31, 2011
Wisconsin Senate Passes Bill to Regulate Attorney Fees » Controlling Legal Costs
This is an interesting article.
The fees have to be limited based on the ‘factors’ listed below. I don’t see how this is really limited legal fees unless it was to spend some money on legislation that really doesn’t do anything.
- Time and labor required by the attorney
- Novelty and difficulty of the questions involved in the action
- Skill requisite to perform the legal service properly
- Likelihood that the acceptance of the particular case precluded other employment by the attorney
- Fee customarily charged in the locality for similar legal services
- Amount of damages involved in the action
- Results obtained in the action
- Time limitations imposed by the client or by the circumstances of the action
- Nature and length of the attorney’s professional relationship with his or her client
- Experience, reputation and ability of the attorney
- Whether the fee is fixed or contingent
- Complexity of the case
- Awards of costs and fees in similar cases
- Legitimacy or strength of any defenses or affirmative defenses asserted in the action
- Other factors
Wisconsin Senate Passes Bill to Regulate Attorney Fees » Controlling Legal Costs
Thursday, June 2, 2011
LAWTRAC 2011 User Conference
The Corporate Legal Department maintains the most sensitive information a corporation can have.
Just to give you an idea on some of the things they may work on:
- Employment agreements
- Civil matters of senior officers
- R&D Work (patent and trademarks)
- Litigation
If a person can get to the data and documents maintained by the legal department they can ascertain trade secrets and more.
For example:
A national retail chain store will experience mishaps by shoppers who will in-turn file a lawsuit. Nine times out of ten the parties will settle out of court. The store wants to insure the person recovers from any injuries while preserving their reputation as a safe place to shop.
If a person were to obtain a copy of the last 50 or so settlements, they can then make a determination as to what the company will automatically settle for. A person goes into the store, fakes a mishap and asks for just less than what the store will fight over.
If your company has a legal department, you need to attend this conference.
LAWTRAC 2011 User Conference | Agenda | powered by RegOnline
Friday, May 20, 2011
Symantec spends $390M for Clearwell, discovery - Storage Soup
I realize that not a lot of people who read this blog know what eDiscovery is, but I thought some of you might find it interesting why all the big data companies are buying software that does something called “eDiscovery”.
Those of you who work in large corporations will hear this term more and more.
“eDiscovery” uses technologies that are constantly crawling all the computers on your company network and indexing all the documents, emails, databases, everything.
Think of it as Google for your company.
This gives those who manage your company the ability to search for anything.
- Who worked on that project three years ago?
- Did that person work for a particular supervisor during a certain time frame?
- What were the details of the contract negotiations and final agreement?
The ability to index all this stuff is a result of lawsuits (believe it or not). During these court procedures the person or persons suing your company has the ability to do what is called “discovery”.
So let’s say it is a '”wrongful termination” suite.
The lawyers representing the person suing has the right to ask for their employment agreement, all the employee reviews, emails between the person, their supervisor(s) and co-workers.
The ability to use the technologies used to pull all that information together quickly is called “eDiscovery”.
So all these large data companies are buying the technologies so they can sell the services of not only the software to do the searching, but the data storage stuff to. Or to reverse that, companies who use their data storage services will want to buy the eDiscovery software as an add-on product.
I’ve seen this consolidation first had.
Two years ago the number of eDiscovery vendors at the New York LegalTech were too numerous to count. Last year the consolidation of this space alone was a part of the reason the amount of space for all the vendor booths went from three floors to two.
Anyway, a link about one of the big software companies buying an eDiscovery company is below.
Symantec spends $390M for Clearwell, discovery - Storage Soup
Legal Directions
Just an introduction to a bit of programming some might find interesting, at least those of you in the legal industry.
A while back the owners of my company were approached and were offered a ‘service’ to have live news headlines appear on the LAWTRAC.com website and inside the LAWTRAC application.
I thought the cost was something that was really out of this world, so I threw this together over a weekend to show them that the technologies that were being offered for something that was over $200 a month could be done for free.
This site brings in news targeting the legal industry from many sources around the internet and taps into government news and regulations information releases.
Check it out… perhaps you can suggest an improvement or two.
