meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, July 10th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 10 July 2020

⏱️ 14 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Citrix Scanning; Juniper Patches; Google Releases Tsunami Scanner; @sans_edu student Billy Wilson: Securing Super Computers

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, July 10th, 2020 edition of the Sands and the Storm Center's Stormcast.

0:08.6

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.5

Yesterday I mentioned how the Citrix vulnerabilities became somewhat more important because Donny Maslund did publish

0:24.2

a blog post with additional details about how to exploit these vulnerabilities. Well,

0:30.5

it turns out that this morning our honeypots did see a scan from actually only a very small number of sources, but they were scanning

0:40.4

for two of the vulnerabilities, one that can be used to read arbitrary files, and a second one that

0:48.5

does retrieve a PCI-DSS compliance document without authentication.

0:55.0

Now, the file that these exploit attempts retrieved with Etsy password,

1:00.0

Etsy password, of course, does not contain any passwords, but usernames.

1:05.0

I really rank this more sort of as a reconnaissance scan

1:08.0

where someone is just checking whether or not these systems are vulnerable.

1:13.2

Our honeypots actually were still configured to act as F5 Big IP devices, so they just responded

1:21.4

with 404 errors to these requests.

1:25.0

And talking about F5 Big IP, one configuration change I made to our Honeypots

1:30.1

this morning was to configure them to be essentially patched systems with the workaround applied,

1:37.2

so they also returned 404 errors to these exploit attempts for the F5 vulnerabilities.

1:45.0

I didn't see any query that would try to bypass the workaround,

1:51.3

so that may still be fairly rare and not something the internet is sort of scanned for at large.

1:59.4

Now, in an added development to the Crix vulnerability, Donnie Maslin also now published

2:06.0

a YouTube video showing how the cross-site scripting vulnerability that had been patched by

2:12.5

Citrix can be leveraged to get full remote code execution.

2:23.3

Now, there isn't a lot of detail, it's really just a video demo without showing any of the underlying code other than sort of a couple of hints as to, for example, what error messages

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.