meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 22nd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 22 February 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Adobe Reader/Acrobat Patch; MSFT IIS DoS; Drupal Fix; Linux Kernel RCE; MikroTik Open Proxy

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 22nd, 2019 edition of the Santernet Storm Center's Stormcast.

0:07.6

My name is Johannes Ulrich.

0:09.0

And today I'm recording from Jacksonville, Florida.

0:12.9

I think it was about last week that I mentioned that Adobe fixed the leakage flaw in Acrobat and Reader.

0:24.0

This was the issue where you could include Smb links in a PDF document and Adobe would happily try to download the respective files

0:30.6

sending your NtLM hashed credentials out. Well, turns out the patch that you applied a week ago wasn't quite sufficient

0:39.7

to vulnerability still existed, even though in a slightly different version and Adobe today

0:46.5

fixed this flaw again.

0:49.0

Exploitation is pretty trivial in this case. It does affect Adobe Acrobat and Reader on Windows as well as on Mac OS.

0:58.0

And the usual reminder, you probably really for sure want to block outbound port 445

1:05.0

that will block leaks like this at least from leaving your network.

1:12.1

At the end of the month, Microsoft is usually publishing its non-security updates at the

1:18.3

third Tuesday of the month.

1:20.6

Well, looks like this month Microsoft sort of snuck in security fix for IIS. This fixes a denial of service condition that can be

1:31.4

triggered via invalid HTTP2 requests. What the attacker has to do is send a lot of settings frames.

1:40.6

The HTTP2 standard doesn't really limit how many of these settings frames you can send,

1:46.1

so it's technically not actually an invalid request that's being sent, but eventually IS will hang

1:53.9

and will stop responding and needs to be restarted. This update does add a configuration parameter that allows you to limit the number

2:04.3

of settings requests per frame as well as per minute. If a connection exceeds that number,

2:10.5

then it will just be killed. Currently I haven't heard of this being exploited out in the wild,

2:16.5

but this doesn't

2:18.0

sound to be terribly difficult to exploit, so definitely do update your systems.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.