ISC StormCast for Friday, January 19th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 January 2024
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, January 19th, 2020, edition of the Sanchez and at Storm Center's Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.7 | I've got yet another update about the Eventi-Connect secure vulnerabilities. |
| 0:20.4 | We now have a blog post by Rapid 7 that goes into quite a bit of details of the product, |
| 0:27.7 | what the exact nature of the vulnerability is and how to exploit it. |
| 0:33.2 | With this, we have fairly straightforward to execute exploits available for everybody willing to give |
| 0:40.3 | them a try. |
| 0:41.6 | And we certainly do start seeing some specific scans that match the pattern suggested by Rapid |
| 0:48.5 | 7. |
| 0:49.8 | The root cause of the problem is a directory traversal vulnerability. |
| 0:53.8 | That part is trivial to exploit, essentially only the first part of the problem is a directory traversal vulnerability. That part is trivial to exploit. |
| 0:55.9 | Essentially only the first part of the path is actually being used for access control. |
| 1:00.1 | You have to find a path that you have access to. There are a couple that do not require any |
| 1:06.4 | kind of access control. And that way you're able to then send you just append the path |
| 1:13.2 | that you actually would like to execute. |
| 1:16.1 | If you find one that allows code execution, well, then you have your full remote code execution |
| 1:21.5 | exploit, and that's what Rapid 7 explains in its blog post. |
| 1:26.3 | Now, there's a good news side to the story. |
| 1:28.3 | Rapid 7 confirmed that the XML configuration update that Yvante published does prevent the |
| 1:35.5 | directory traversal exploit, so that should help you out. |
| 1:40.8 | Of course, the denser of remote code execution and such would still work, but you would |
| 1:46.9 | need to authenticate to actually execute that. The final patch should become available starting |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

