ISC StormCast for Friday, March 10th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 March 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, March 10th, 2017 edition of the Sands and Storm Centers. |
| 0:07.7 | Stormcast, my name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.7 | The Struts 2 vulnerability I mentioned yesterday is still being exploited. |
| 0:18.6 | If you have web applications relying on struts too, then |
| 0:23.4 | it is critical that you either patch struts to as soon as possible or that you apply |
| 0:30.8 | other countermeasures like a web application firewall. At this point, the exploit I have seen either just tests the system and checks if it's |
| 0:41.8 | vulnerable by echoing back a string or it's running a command like Who Am I? |
| 0:48.1 | In one case I observed the attacker attempting to install a well-known Linux backdoor. |
| 0:55.0 | Of course, these are random attacks against systems that are not vulnerable, |
| 1:00.0 | that are not even running Java. |
| 1:03.0 | If you have a vulnerable system, then you may see more targeted attacks |
| 1:09.0 | in addition to these random ones. |
| 1:11.6 | The exploit sticks pretty close to what was released as a meta-sploid module, varying the user |
| 1:19.9 | agent and the order of the headers. |
| 1:24.1 | And then we got an interesting submission from a reader with an email that was intended to attack the mail server. |
| 1:33.8 | Now typically when we're talking about malicious emails, we're talking about things like attachments that are executable. |
| 1:41.8 | In this case, the attachment was a zip file. Actually, it wasn't the content of the SIP file. It was a problem. Instead, one of the file names inside the SIP file included shell code. |
| 1:55.6 | Heraka is built on top of Node.js, and it is known as a high-performance mail server that's often used |
| 2:03.3 | in front of a regular more full-featured mail server in order to speed up mail delivery. |
| 2:10.5 | Now, this vulnerability was fixed back in September, an exploit was released end of January. It's a very trivial exploit, really all |
| 2:21.5 | you have to do is format that shell command correctly, use it as a file name, and then sip it up. |
| 2:30.1 | The problem here is in how Heraka actually analyzes these attachments. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

