ISC StormCast for Friday, December 27th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 December 2019
⏱️ 4 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, December 27th, 2019 edition of the Sansonet Storm Center's |
| 0:06.0 | Stormcast. My name is Johannes Ulrich. And the time recording from Jacksonville, Florida. |
| 0:13.0 | Well, I told you I want to publish at least one more podcast, and we also had a number of great diaries over the holidays, but the couple of |
| 0:24.2 | minutes I have your attention for, I really don't want to waste and focus on one particular |
| 0:29.9 | issue that you definitely should address as quickly as possible. |
| 0:34.5 | And that's a vulnerability in the Citrix application delivery controller and Citrix Gateway. |
| 0:41.3 | Those systems used to be known as NetScaler and NetScaler Gateway before Citrix acquired the product. |
| 0:48.2 | So the problem here is that this is a relatively easy to exploit directory traversal vulnerability that allows arbitrary |
| 0:56.7 | code execution on these products, which of course usually secure your perimeter. Now, with |
| 1:03.9 | this access, an attacker, for example, could get access to your network or, of course, manipulate |
| 1:09.6 | these devices. Citrix did originally publish |
| 1:14.1 | an advisory on the 17th. It hasn't really gotten much attention, but on the 23rd, so on Monday |
| 1:22.9 | this week, positive technologies which originally discovered this vulnerability did publish their |
| 1:29.8 | blog post and that really has gotten more attention. |
| 1:34.1 | So now there is more focus on this vulnerability and also more awareness, of course, likely |
| 1:40.0 | also among the bad guys. |
| 1:42.8 | Good news at this point, I don't see any exploit attempts against |
| 1:47.0 | this vulnerability using our honeypots, but then again our honeypots aren't really good in |
| 1:52.2 | emulating these Cytrics devices. We may fix this. So different really more sort of get |
| 1:58.2 | internet wide scans for the vulnerability and not so much more targeted attempts. |
| 2:03.6 | And of course, most enterprises I would guess have a Syrac's device like this summer in their network. |
| 2:10.6 | So certainly important. So what should you do? Well, read up on the advisory. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

