meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 20th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 January 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Open Hadoop At Risk;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, January 20th, 2017 edition of the Sandton and Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and today I'm recording from Brussels, Belgium.

0:12.6

I've talked in the past a couple times about Elasticsearch and MongoDB and how it is being attacked.

0:19.3

Most recently, there was a big rash of compromised MongoDB systems

0:25.0

where attackers held the data for ransom or at least claimed to have it,

0:30.7

even though they already had it deleted.

0:33.1

The latest big data database that's being attacked like this is Hadoop. According to one of our

0:40.6

handers actually, John Bamanick, who wrote this for Fidelis, they have seen databases being deleted

0:48.4

that were not adequately secured. And just like the other NoSQL databases, Hadoop also is often installed without credentials.

1:01.0

I guess it was just a matter of time and of course, like anything that you make accessible to the Internet and don't adequately secure,

1:10.0

it will get stolen or will get wiped just a matter of time.

1:14.9

And of course, this year will mean the end of Shah 1 based certificates.

1:21.0

And starting next week, you may actually see some of the effects.

1:26.3

Mozilla is supposed to release Firefox 51 on Tuesday,

1:31.3

and with that, Shah 1-based certificates will be marked unsafe. A week later on January 31st,

1:39.3

we'll get the same from Google with Chrome 56, and mid-February with the February patch Tuesday,

1:47.0

Microsoft will also cut off support for Shaw 1 in Edge

1:52.0

and Internet Explorer.

1:55.0

Earlier this year, actually on January 1st,

1:58.0

Windows already stopped accepting Shaw 1 based certificates. certificates. So with that, you really,

2:04.7

really need to get going quickly and make sure that you no longer have any SL web servers

2:11.3

that use SHA-1-based certificates. Most existing browsers already allow you to disable them or present

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.