meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, June 28th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 27 June 2019

⏱️ 17 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. New Brickerbot; Telco Service Provider Attachs; Malwaretising; Automating Phish Reporting Response @sans_edu

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, June 28th, 2019 edition of the Sands and it storms and its

0:06.0

Stormcast. My name is Johannes. All right. I'm recording from Riyadh, Saudi Arabia.

0:13.1

We have yet another Pricker bot making the rounds. Prickerbot usually refers to malware

0:19.3

that's trying to actually disable IOT devices.

0:23.8

The way they often do this is by just using the DD utility that's used to dump disk images

0:32.0

and overriding various partitions on the device.

0:36.3

Now in many cases in Internet of Things devices, these

0:39.5

partitions are actually not writable. So even if this particular bot runs as rude, it

0:47.2

typically doesn't do as much damage as it appears to do. In many cases, a simple reboot of

0:53.8

the device will restore them to their prior

0:56.8

state. Every couple of years or so, these kind of breaker bots make the news again. So,

1:03.1

this is yet another iteration of this basic idea. No new vulnerability involved here. It's still

1:10.7

mostly going after simple usames and

1:13.8

passwords via telnet or s pho. Of course given that the entire of miri family of melvair

1:20.8

has been adding more exploits like against popular web applications and such means that these exploits will likely

1:29.5

migrate to these precker bots as well and earlier yesterday in our Slack

1:35.8

channel Bruce pointed to a nice write-up by Cyber Reason about an attack that

1:41.7

they have been following that compromised a number of telecommunication providers.

1:47.0

I think what's sort of interesting about this attack is that when we talk about supply chain attacks,

1:53.0

these last couple of years it often was very focused on hardware and software vendors,

2:00.0

but suppliers of services are certainly part of this larger

2:05.4

threat. And of course, unlike with software and hardware, you can actually obtain a copy and

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.