Archive for August 24, 2024

Other World Computing (OWC) Announces Labor Day Sales Event

Posted in Commentary with tags on August 24, 2024 by itnerd

 Other World Computing (OWC), a trusted leader in delivering high-performance, secure, and sustainable technology solutions that enhance and extend the life of Macs and PCs, today announced its much-anticipated Labor Day Sale. This year, customers can take advantage of incredible savings on a wide range of OWC products, designed to power their creativity, productivity, and digital workflows.

Exclusive Labor Day Deals Include:

  • OWC Travel Dock E – $10 off, only $49.99 – The best mini-sized dock to connect, charge, display, and import on-the-go via one integrated cable
  • OWC Thunderbolt Go Dock – $30 off, only $269.99 – The first full-featured Thunderbolt dock without a bulky, heavy power adapter, so you can go anywhere easily and connect it all with Thunderbolt and USB-C Macs, PCs, iPads, Chromebooks, and Android devices.
  • OWC Envoy Pro mini – Up to $50 off – Full-sized SSD performance that fits in your pocket.
  • OWC Envoy Pro FX – Up to $100 off – The Fastest Most Compatible Drive Ever Made with Speeds up to 2800MB/s.
  • OWC Gemini – Up to $200 off – Thunderbolt Dock and Dual-Bay RAID external storage enclosure for 2.5-inch and 3.5-inch SATA drives.

In addition, OWC is also offering deep discounts on used Macs and iPads, with some deals reaching up to 72% off. Such as:

  • 69% off the Travel-Friendly 13-inch MacBook Pro – Retina / Touch Bar / Mid 2020-Late 2021 – Combines impressive performance in a sleek design, featuring a powerful processor, an enhanced keyboard for an exceptional user experience, and all day battery life.
  • Perfect-Sized iMac Perfection – from $239.00 – Retina 4K / 21-inch – This iMac is a hit with its compact size, powerful performance, and stunning Retina display.

And, so much more!

This is the perfect opportunity for customers to upgrade their tech at unbeatable prices!

These deals are available now through macsales.com through September 4th, while supplies last.

Traccar 5 Remote Code Execution Vulnerabilities Found By Horizon3.ai

Posted in Commentary with tags on August 24, 2024 by itnerd

Naveen Sunkavally, chief architect at Horizon3.ai, has just published “Traccar 5 Remote Code Execution Vulnerabilities” detailing two related path traversal vulns affecting the popular open source GPS tracking system that could lead to remote code execution: CVE-2024-31214, reported by Horizon3.ai, and CVE-2024-24809, reported by @yiliufeng168. 

The post includes four methods and three proof-of-concept (POC) ways by which these vulnerabilities can be exploited by unauthenticated attackers through RCEs if guest registration is enabled, which is the default configuration for Traccar 5. 

Horizon3.ai reported the vulnerabilities in early April 2024. After the disclosure, the maintainer fixed the path traversal in the Content-Type header and locked down the file extensions to a known set. The maintainer also changed the guest registration setting to be off by default in Traccar 6, per Horizon3.ai’s recommendation, which significantly reduces the attack surface available to unauthenticated attackers and will have a lasting impact on improving the security posture of Traccar for years to come.

Naveen urges that both CVE-2024-31214 and CVE-2024-2809 be treated as critical issues because guest registration is on by default in Traccar 5, effectively allowing unauthenticated access.

Traccar 5 Remote Code Execution Vulnerabilities: https://www.horizon3.ai/attack-research/disclosures/traccar-5-remote-code-execution-vulnerabilities/