4.9 • 696 Ratings
🗓️ 20 December 2024
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, December 20th, |
0:03.1 | 20204 edition of the Sansonet Stormunders Stormcast. |
0:08.4 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:14.5 | Today we've got a quick diary by one of our undercredited interns, |
0:18.3 | Shahil Sheikh. He's writing about an exploit attempt against a |
0:23.2 | PHP unit. This is an old warnability still ranking way up there in the sort of most |
0:29.5 | common exploits that we typically see. Sherill here suspects that this particular attempt, |
0:35.6 | which originates from Bulgaria, and actually that |
0:39.9 | IPI address is quite prolific, is attempting to spread the anthrox ghost malware. That particular |
0:49.1 | malver is known for then installing Python scripts that will essentially |
0:54.4 | infiltrate credentials from the victim's system. |
0:58.9 | They're also known for targeting the dot-env files |
1:03.0 | that we have observed being targeted in the past. |
1:07.9 | I'm talking about a little bit sort of blast from the past style news. |
1:12.1 | Juniper noted that its session smart routers are being attacked by Mirai using, well, what else, default passwords? |
1:22.2 | Not sure what took so long for Mirai to add this particular set of passwords to its list, but yes, |
1:30.1 | you're now being targeted. If you still have a Session Smart router with a default password, |
1:37.7 | you're probably not going to bother to look for any of the indicators of compromise. So just |
1:42.8 | change your password, please, |
1:45.3 | and reboot the device, |
1:46.9 | which probably should get rid of whatever malware was installed, |
1:51.4 | at least by Mirai, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.