ISC StormCast for Friday, July 7th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 July 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, July 7, 2023 edition of the Sands and its Stormsenders Stormcast. |
| 0:08.4 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Jesse today wrote an interesting diary comparing the logs from different IDSs. |
| 0:20.0 | These IDSs were placed in front of Jesse's D-Shield Honeypot |
| 0:25.1 | and interesting to see what attacks are being seen, are not being seen, and most of all, |
| 0:31.7 | how they're being categorized. Some of the IDS, and he compared here mostly Palo Alto and Suricata gave you more detail as to what the potential attack could be versus others. |
| 0:46.5 | Jesse also used full PCAP logs in order to make an ultimate than manual decision for some of these attacks to see essentially which |
| 0:56.3 | IDS is better for more details. |
| 1:00.1 | Well, see Jesse's diary. |
| 1:02.4 | Sort of interesting at the top two attack groups, actually, for Suricata are, well, our |
| 1:10.6 | D-Shield block list which probably is |
| 1:14.3 | researchers they often show up in our block list then of course things like as H scans a little bit |
| 1:21.6 | surprised terminal server scans show up at number four or number two if you remove the two D-Shield block listed issues that are being listed here. |
| 1:34.4 | And Sisa is warning that the latest version of the TrueBot malware is taking advantage of a vulnerability in NetRicks auditor. |
| 1:53.4 | This vulnerability is not new. It has been patched for about a year now. June 6th, 2022 is when the patch was released. |
| 2:04.6 | Bishop Fox has a good write-up on the particular vulnerability. It's a deserilization issue. So exploitation is a relatively straightforward. It does listen on TCP port 9,004. |
| 2:09.6 | So do a quick scan of your network, |
| 2:11.6 | see if anything is listening on port 9,004. |
| 2:14.6 | Not sure how popular this particular application is, but apparently popular enough for |
| 2:20.5 | throughput to sort of deviate from its normal pattern. It's usually just going for phishing emails. |
| 2:27.0 | Well, and now they're actually actively scanning for a network's auditor. |
| 2:34.2 | And then we've got an interesting Linux privilege escalation vulnerability. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

