[KIS-2016-07] SugarCRM <= 6.5.23 (SugarRestSerialize.php) PHP Object Injection Vulnerability

Posted by Egidio Romano on Jun 23

——————————————————————————
SugarCRM <= 6.5.23 (SugarRestSerialize.php) PHP Object Injection Vulnerability
——————————————————————————

[-] Software Link:

http://www.sugarcrm.com/

[-] Affected Versions:

Version 6.5.23 CE and prior versions.

[-] Vulnerability Description:

The vulnerable code is located in the…

[KIS-2016-05] SugarCRM <= 6.5.18 Two PHP Code Injection Vulnerabilities

Posted by Egidio Romano on Jun 23

———————————————————
SugarCRM <= 6.5.18 Two PHP Code Injection Vulnerabilities
———————————————————

[-] Software Link:

http://www.sugarcrm.com/

[-] Affected Versions:

Version 6.5.18 CE and prior versions.

[-] Vulnerabilities Description:

1) The vulnerable code is located in the /include/utils/array_utils.php script:

99. function…

[KIS-2016-06] SugarCRM <= 6.5.18 (MySugar::addDashlet) Insecure fopen() Usage Vulnerability

Posted by Egidio Romano on Jun 23

—————————————————————————–
SugarCRM <= 6.5.18 (MySugar::addDashlet) Insecure fopen() Usage Vulnerability
—————————————————————————–

[-] Software Link:

http://www.sugarcrm.com/

[-] Affected Versions:

Version 6.5.18 CE and other versions.

[-] Vulnerability Description:

The vulnerable code is located within the MySugar::addDashlet() method:…

[KIS-2016-04] SugarCRM <= 6.5.18 Missing Authorization Check Vulnerabilities

Posted by Egidio Romano on Jun 23

————————————————————–
SugarCRM <= 6.5.18 Missing Authorization Check Vulnerabilities
————————————————————–

[-] Software Link:

http://www.sugarcrm.com/

[-] Affected Versions:

Version 6.5.18 CE and prior versions.

[-] Vulnerabilities Description:

The application fails to properly check whether the user has administrator privileges within the following…

[KIS-2016-03] SugarCRM <= 6.5.18 (SAML Authentication) XML External Entity Vulnerability

Posted by Egidio Romano on Jun 23

————————————————————————–
SugarCRM <= 6.5.18 (SAML Authentication) XML External Entity Vulnerability
————————————————————————–

[-] Software Link:

http://www.sugarcrm.com/

[-] Affected Versions:

Version 6.5.18 CE and prior versions.

[-] Vulnerability Description:

The vulnerable code is located in the constructor method of the…

New 2016 AntiVirus and Remote Control Options Available for AVG Managed Workplace

We have seen an incredible excitement in the MSP market surrounding our release of Managed Workplace 10. This month, we have continued this momentum with new security and key enhancements.

Managed Workplace 10 now includes integrated advanced security features from our award-winning AntiVirus 2016 engine, in addition to expanded remote control functions, alerting and customized reporting enhancements.

This is all part of our Managed Workplace Service Pack 1 release, available now.

A few highlights include:

  • Advanced AVG AntiVirus 2016 Engine
    • Advanced heuristics: Through a combination of Artificial Intelligence and advanced algorithms, stops emerging and known threats from ransomware, malware, viruses, spyware, worms, rootkits, and Trojans
    • Cloud-based outbreak detection technology: Helps identify even the newest malware variants in real-time
    • Advanced scanning engine: Scans your systems without impacting the day with boot-time scanning, scheduled and on-demand scans
    • Online shield: Uses cloud-based detection to identify dangerous downloads fast
    • LinkScanner: Assesses web pages in real-time for safe surfing, searching and downloads
    • Identity protection: Shields passwords and credit card numbers from hackers and scammers
    • Email protection: Protects confidential data from latest spam and phishing attacks
    • Firewall protection: Strengthens your perimeter of defense, stops the spread of viruses
  • Enhancements to Premium Remote Control
    • Ad hoc and on-demand sessions: Offers remote support to anyone on the Internet without the need to have Managed Workplace deployed.
    • End-user consent: Respects the privacy of your customers by requesting access to initiate remote control to their devices.

AVG partners are already taking advantage of Service Pack 1.  An AVG channel partner in Ontario, Canada shared his feedback:

  • “Managed Workplace’s integrated AV will allow us to manage threat policies and customize update and scanning schedules while centralizing threat detection into one platform.”
  • “The Enhanced Remote Control feature is a welcome addition to the already fantastic Premium Remote Control client. The ability to prompt users for remote control authorization and provide remote assistance to any user via the on demand feature means we no longer need to purchase and maintain a separate remote control solution for our clients.”

Put the new features to the test today. If you’re new with Managed Workplace, join our Daily Demo by clicking here. As always, please continue to share your feedback.

STOP Rule 41 — FBI should not get Legal Power to Hack Computers Worldwide

We have been hearing a lot about Rule 41 after the US Department of Justice has pushed an update to the rule.

The change to the Rule 41 of the Federal Rules of Criminal Procedure grants the FBI much greater powers to hack legally into any computer across the country, and perhaps anywhere in the world, with just a single search warrant authorized by any US judge.

However, both civil liberties