ISC StormCast for Friday, June 14th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 June 2019
⏱️ 15 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, June 14th, 2019 edition of the Santernet Storm Service Stormcast. |
| 0:07.9 | My name is Johannes Ulrich, and the time recording from Neptune, New Jersey. |
| 0:14.0 | About a week ago, we had this critical remote code execution vulnerability in the XM mail server that was being |
| 0:23.6 | patched. |
| 0:24.6 | Well, it looks like the bad guys wasted no time and there are now a couple of different bot |
| 0:30.6 | nets that are exploiting this vulnerability. |
| 0:34.6 | One of these bots is described by cyber reason in a blog post and what they're seeing is XM servers that haven't been patched being exploited and backdoored. |
| 0:47.3 | The attacker in this case will modify the authorized keys file for ZH in order to be able to log in to that server. Later, it also |
| 0:59.4 | installs crypto miners on vulnerable servers. So before you're leaving for the weekend, it may be a good |
| 1:06.6 | idea to run a quick scan on your network, making sure you don't have any XM servers running and |
| 1:13.5 | if you do that these servers are patched. If they're not patched at this point, you definitely |
| 1:19.6 | should assume that the server has been compromised. And Ubiki is recalling several of its FIPS certified Ubikis. |
| 1:32.3 | The problem apparently here is that after you power up one of these affected UB keys, |
| 1:40.3 | the initial cryptographic keys being used for the first few operations are using up to 80 |
| 1:48.0 | predictable bits, which may not be a big issue for, for example, an RZE key, which has a total |
| 1:54.6 | of 2048 bits, but for some of the elliptic curve keys, of course, that are shorter, this may be more of a problem. |
| 2:03.6 | So in order to check if your particular UB keys affected, you should see the four letters FIPS. |
| 2:11.6 | So FIPS printed on the UB key if your UB key is affected. |
| 2:16.6 | Also only UB keys shipped before April 30th are affected. |
| 2:21.9 | These Ubikis are running fervors prior to 445, which would be either 442 or 444. |
| 2:31.0 | So if you're using Ubikis, take a look at the Ubico advisory regarding this issue. They also |
| 2:38.6 | have pictures of affected UBKs in order to make it easier to identify if your particular key is |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

