meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, December 6th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 December 2019

⏱️ 14 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. OpenBSD Vuln; Linux/BSD VPN Connection Hijack; STI Paper: RASP vs. WAF

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, December 6th, 2019 edition of the Santernet Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich and I'm recording from San Francisco, California.

0:12.0

OpenBST has always had a reputation for very good security controls and thorough reviews of its features, often foregoing some

0:24.4

more advanced features for enhanced security. It's therefore somewhat surprising to find a

0:32.0

fairly easy authentication bypass in OpenBSD. The problem here is how users and passwords or authentication

0:42.4

credentials more generically are being validated. This is done using login underscore style and the

0:51.3

username is passed as a command line argument, but not properly escape,

0:56.8

meaning that if a username starts with dash s challenge, this is actually interpreted as a

1:04.9

command line parameter for login underscore style and can be used to bypass the login username and password check.

1:15.3

This can be trivially exploited against a number of different demons on OpenPSD, SMTPD, LDAB, the RadiusD, as well as S-S-H-D, which is probably the most critical here.

1:33.0

Also, SU, which then can lead to approach escalation, can be exploited using this trick.

1:40.5

This vulnerability was made public by Qualis and well since it's so trivial

1:47.5

really to exploit, proof-of-concept exploits have been made available by Qualis.

1:54.4

Qualis also found three other privilege escalation vulnerabilities in OpenBSD that have also been made public.

2:04.9

Qualis has reported these vulnerabilities to the OpenBSD team and within 40 hours of reporting

2:12.3

the vulnerability, OpenBSD has released an update addressing these issues.

2:21.4

And we also got an interesting vulnerability affecting several Linux and BSD distributions

2:29.1

that would allow a net hacker to learn some information about a VPN connection terminated

2:37.0

at that particular system.

2:40.0

Now, in order to exploit this vulnerability, the attacker has to be located within the same

2:45.0

network as the victim.

2:47.0

So, for example, I'm here at a hotel connected to the hotel's Wi-Fi network,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.