meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 19th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 19 January 2024

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Ivanti Updates; Postgres Attacks; Outlook Vuln PoC;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, January 19th, 2020, edition of the Sanchez and at Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.7

I've got yet another update about the Eventi-Connect secure vulnerabilities.

0:20.4

We now have a blog post by Rapid 7 that goes into quite a bit of details of the product,

0:27.7

what the exact nature of the vulnerability is and how to exploit it.

0:33.2

With this, we have fairly straightforward to execute exploits available for everybody willing to give

0:40.3

them a try.

0:41.6

And we certainly do start seeing some specific scans that match the pattern suggested by Rapid

0:48.5

7.

0:49.8

The root cause of the problem is a directory traversal vulnerability.

0:53.8

That part is trivial to exploit, essentially only the first part of the problem is a directory traversal vulnerability. That part is trivial to exploit.

0:55.9

Essentially only the first part of the path is actually being used for access control.

1:00.1

You have to find a path that you have access to. There are a couple that do not require any

1:06.4

kind of access control. And that way you're able to then send you just append the path

1:13.2

that you actually would like to execute.

1:16.1

If you find one that allows code execution, well, then you have your full remote code execution

1:21.5

exploit, and that's what Rapid 7 explains in its blog post.

1:26.3

Now, there's a good news side to the story.

1:28.3

Rapid 7 confirmed that the XML configuration update that Yvante published does prevent the

1:35.5

directory traversal exploit, so that should help you out.

1:40.8

Of course, the denser of remote code execution and such would still work, but you would

1:46.9

need to authenticate to actually execute that. The final patch should become available starting

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.