ISC StormCast for Friday, December 22nd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 December 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, December 22nd, 2017 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.8 | Remember how many issues we had with S&B version 1 this year? |
| 0:18.0 | Well, and prior years, there is one more bug that you probably need to fix |
| 0:24.5 | rather quickly if you're running Dell EMC storage gear. |
| 0:28.9 | Turns out the data domain deduplication and data protection software suffers from a critical |
| 0:35.5 | memory overflow vulnerability that can lead possibly to remote code |
| 0:40.9 | execution, but almost certainly to a denial of service against affected devices. |
| 0:48.5 | Effected are pretty much all current versions of Data Domain DDOS. |
| 0:53.6 | This includes the 5.76061 families of this software. |
| 1:00.0 | Also, if you're running the Data Domain Virtual Edition, then 203031 are all affected. |
| 1:09.0 | So at the very least, before you head home for the holidays |
| 1:12.4 | double-check that you have firewall rules preventing access via SMB to these |
| 1:18.4 | devices from the outside. This particular flaw does not require authentication. No |
| 1:25.9 | exploit has been released up to this point, but who knows, people |
| 1:30.7 | are probably working on it already. And ever received an email from Facebook and you weren't |
| 1:36.1 | quite sure if this is an authentic email from Facebook or not. Well, Facebook now introduced a new feature that helps you make that decision. |
| 1:47.0 | If you go to settings in Facebook and then select security and login at the very bottom of the page, |
| 1:53.0 | you'll find a new item that lists all recent emails sent by Facebook. |
| 2:00.0 | So here you can review whether or not that password reset or whatever you received was an actual |
| 2:06.6 | Facebook message or not. |
| 2:08.6 | There are two categories here. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

