Tag: Cross Site Request Forgery

security advisory

[ICS] Carlo Gavazzi VMUC-EM Energy Meter – Multiple Vulnerabilities

ICS-CERT Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-17-012-03

CVE-IDs
CVE-2017-5144
CVE-2017-5145
CVE-2017-5146

security advisory

[ICS] BINOM3 Electric Power Quality Meters – Multiple Vulnerabilities

Hacking Binom3 Electric Power Quality Meters

ICS-CERT Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-17-031-01A

CVE-IDs
CVE-2017-5164
CVE-2017-5162
CVE-2017-5165
CVE-2017-5166
CVE-2017-5167

Read on.

Attack tool

MonkeyFist v0.4 Released

MonkeyFist is a tool that creates dynamic request forgeries based on cross-domain data leakage. The tool then constructs a payload based on data in the payloads.xml file and sends it to the user’s browser. This may include session data bypassing protection mechanisms for Cross-Site Request Forgery.