Ubizen's Security Intelligence Lab (SIL) has sent out an early warning, advising customers about two new high-risk vulnerabilities.
Ubizen has detected a possible buffer overflow scenario in OpenSSH applications, as well as a weak authentication in Solaris sadmind Daemon which allows a remote attacker to gain unauthorized root access to a vulnerable system by sending a sequence of specially crafted RPC requests to the vulnerable system.
Ubizen's Security Intelligence Lab gathers the latest information about threats, system vulnerabilities and possible attacks, through a variety of sources, including the Web, vendor channels and underground resources. Ubizen engineers also conduct ethical hacking, probe for vulnerabilities and evaluate weaknesses in security devices. All this information is centrally stored in a knowledge base and used by the security analysts in Ubizen's Security Operations Centers (SOC). From these SOCs, Ubizen provides managed security services to its global customer base. Ubizen OnlineGuardian® services monitor and manage security devices on a 24x7x365 basis.