meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 3rd 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 3 February 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. SMB 3 0-Day DoS Exploit; WordPress Update; Webroot BSOD

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 3rd, 2017 edition of the Sandsenet Storm Center's Stormcast.

0:07.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:11.5

We got our TCPDump update today from tcdump.org, so if you're relying on that, you can now download TCPDump 4.9 and be no longer vulnerable against these various

0:23.5

heap buffer overflows that were released earlier this week. But to make up for it, we got a new

0:30.4

Saturday and that one hits Windows users. Windows 2012 and later on the server side and Windows 8 and later on the client

0:40.6

side started implementing SMB version 3.

0:44.1

And there is a relatively straightforward buffer overflow in SMB version 3 on these Windows

0:50.5

systems that can be exploited now thanks to a proof of concept exploit.

0:55.0

Now this is at this point just a denial of service vulnerability.

1:00.0

It's not clear if it's also executable.

1:03.0

In order to be vulnerable or to be exploited, a client needs to connect to a malicious

1:09.0

Smb version 3 server.

1:11.8

So the way this could potentially be executed is that you visit a website that includes a link

1:19.2

that links, for example, an image to an SMP version 3 server.

1:23.7

I tested this particular scenario with a static HTML file on the client and yes, the client

1:30.9

rebooted immediately after opening the file. If you get hit by it, you'll see a blue screen of

1:37.9

death. I have a screenshot of the blue screen in the diary so you can compare in case you see one pop up on your system.

1:48.1

But there's also a very experimental preliminary snort signature that I came up with for it.

1:53.6

Not sure how good it is, but you could also try that out if you would like to detect exploit attempts.

2:00.2

At this point, I haven't seen a statement

2:02.0

from Microsoft about this exploit yet, so in case you run across something, let me know.

2:09.2

And if you didn't update to WordPress 472, which was released end of January, because you

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.