ISC StormCast for Friday, March 15th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 March 2024
⏱️ 21 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, March 15th, 2024 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:12.6 | We do have a diary today by Jan looking at a couple different options that are increasing in how attackers are storing assets for their |
| 0:23.0 | fishing scams. And these two are IPFS and R2. Both of them have been going around for a while, |
| 0:30.7 | but they keep increasing IPFS. That's short for the interplanetary file system, a distributed Web 3 storage system, and then R2, which is object storage provided by CloudFlare. |
| 0:46.4 | Either of them can be used free or really cheap, so attackers are using it for ephemeral storage. |
| 0:53.7 | Often these URLs are rotating very quickly by the time you noted a particular URL or blocked |
| 1:01.1 | a URL, well, it's already gone and moved to somewhere else. |
| 1:06.2 | IPFS is something that you may want to consider blocking wholesale. |
| 1:10.5 | I don't really see it used much sort of for real stuff. |
| 1:13.5 | Of course, that's much more difficult for Cloudflare. |
| 1:17.7 | R2 is commonly used by a number of valid applications and companies R2. |
| 1:25.2 | D.Dev is the domain associated with it. |
| 1:27.7 | So you may want to keep an eye out for these URLs, but like I said, wouldn't recommend blocking them. |
| 1:36.0 | And we have yet again updates for 40 net users. |
| 1:40.6 | First one is not so good news, and that's new vulnerabilities this time in 40 WLM. |
| 1:48.2 | 40 WLM, that's their wireless land manager. |
| 1:52.5 | Horizon 3 published a blog post with details regarding four different vulnerabilities. |
| 1:58.6 | One is an unauthenticated command injection. We have unauthenticated |
| 2:03.2 | SQL injection, unauthenticated arbitrary file read, and lastly an authenticated command |
| 2:10.0 | injection. Bad news here is that at least two of these vulnerabilities have not yet been patched. Horizon 3 originally reported these |
| 2:20.7 | vulnerabilities to 4-D-NET back in May last year, and now after their 307 days of notification |
| 2:31.3 | expired, they did publish the details regarding these vulnerabilities. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

