ISC StormCast for Friday, December 23rd, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 December 2022
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, December 23rd, 22 edition of the Sands and its Storm Center's Stormcast. |
| 0:08.2 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.6 | Well, just a quick follow-up on a story I mentioned yesterday. |
| 0:17.9 | A Rapid 7 and Crowdstrike did observe a workaround for some of |
| 0:24.0 | the Outlook Web Access server site request forgery, a vulnerability or the proxy not shell |
| 0:31.2 | vulnerability workarounds that Microsoft recommended. Well, Guy thinks that he saw some of these requests also in his honeypots. |
| 0:41.2 | Definitely something that you should be aware of. |
| 0:42.9 | And again, it does not affect you if you're fully patched on your exchange servers. |
| 0:47.7 | This is something that you should be worried about if you're relying on any of the published |
| 0:51.9 | workarounds to protect yourself and not using the patch. |
| 0:57.4 | And we got today an early Christmas gift from the Serday Initiative. An advisory published today |
| 1:04.5 | by the Serday initiative makes public kernel KSMBD use after free remote code execution vulnerability in Linux. |
| 1:14.2 | It scores a perfect CVSS score of 10. |
| 1:18.2 | Now, this is certainly something important. |
| 1:21.9 | Why is it not sort of a huge deal? |
| 1:24.0 | Well, the vulnerability was originally reported to Linux in July, according to |
| 1:30.9 | a link in the advisory. Update was actually made public in August that should fix this particular |
| 1:40.5 | vulnerability, but it wasn't really sort of acknowledged as a vulnerability back then. |
| 1:46.2 | Also, KSMBD, it's an implementation of the SMB version 3 protocol. |
| 1:53.1 | It's sort of a replacement for Samba, but it's relatively new. |
| 1:57.7 | Again, it's a kernel module, so basically moved the user space Samba code sort of into |
| 2:04.3 | the kernel, of course, with a complete rewrite. Most systems still use Samba instead of KSMBD. KSMBD. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

