meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 19th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 19 January 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Oracle EBS Vulnerable via WebLogic; MSFT Resumes AMD Patches; Infusion Pump Vulnerabilities

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, January 19th, 2018 edition of the Sandton Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida.

0:11.6

On APSIS, a company that deals with the security of enterprise resource planning systems like SAP and Oracle

0:18.8

has taken a closer look at the vulnerability that was exploited to install

0:23.7

these crypto miners. Now, this vulnerability was patched in October and it was a vulnerability

0:30.8

in WebLogic. The issue here is that WebLogic is middleware. So it's really a component of a number of additional

0:38.4

systems and as Onapsus points out, it goes well beyond PeopleSoft. For example, the Oracle

0:45.3

E Business Suite, well, WebLogic is part of it and it could be compromised using this particular

0:52.4

flaw in WebLogic.

0:54.3

Now whenever you have a web application vulnerability like this,

0:58.3

how much you can do with it depends very much on the user

1:01.7

the application is running as.

1:03.8

If this is a low privileged user that doesn't really have access to anything,

1:07.9

then it can be quite limited.

1:09.8

But in this case, actually, WebLogic is running as a privileged user, the application manager,

1:16.6

APPPLMGR.

1:18.6

On AppsS shows how does it can be used to do much more than just install a crypto miner.

1:23.6

For example, they demonstrate how data can be retrieved from the Oracle e-business suite pretty much at well.

1:31.3

So if you find one of these crypto miners running on your system, double check and make sure that there's nothing else going on here.

1:38.3

Yes, the crypto miner is of the big and easy to find exploit for this particular vulnerability, but there

1:46.6

may be more going on in the system that doesn't really stick out as easily. And with all the

1:53.1

fallout about Spectre and Meltdown, Microsoft had run into a problem where some AMD CPUs

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.