meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, April 29th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 29 April 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SMB/RPC Honeypot Results; Azure PostgreSQL Priv Esc; GitHub Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, April 29, 2020 edition of the Sands and it's Storms

0:06.9

on a stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.6

I had some time today, so I summarized some of the traffic that we have been seeing for our

0:20.5

SMB and RPC Windows Honeypot.

0:23.9

What we did here was that some of the honeypots that we have deployed around the internet,

0:30.1

we basically just redirected Port 445 traffic to this system.

0:36.3

This gives us only one system that we really have to maintain here,

0:39.6

and that's actually fully vulnerable to the RPC vulnerability that Microsoft patched a couple

0:47.8

weeks ago. And it does give us a pretty good cross-section. so we get basic data from a lot of IP addresses

0:55.5

by only having to maintain one individual vulnerable system. Well, first, what do we not see,

1:02.2

and that's an exploit for CVE 2022-26809, that's the RPC vulnerability that Microsoft patched in April.

1:13.2

Instead, we did see an awful lot of brute forcing, of course, and then also quite a bit of

1:19.0

eternal plume.

1:20.9

That vulnerability, going back to 2017 now is still quite popular and apparently there are still some vulnerable systems out there.

1:33.8

I would be surprised if they aren't already compromised, but well, maybe the attackers here

1:40.3

are hoping for new systems to come online or to be able to recompemise some already compromised

1:47.6

systems. When you're running a database on premise, then privilege escalation is a problem,

1:54.8

but usually not sort of at the top of the things that you worry about. However, things change if this database is running in the cloud,

2:04.1

and that's what happened to Azure.

2:07.0

Microsoft is offering an Azure database for Postgres flexible server,

2:13.2

and the WIS security team, I think I should call them,

2:17.1

the Azure security team,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.