meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 4th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 4 March 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Odd OpenWRT Scan; Alexa Hacks Alexa; Google Cloud Armor Update; Ukraine Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 4th, 2020 edition of the Sansonet Stormers Stormcast.

0:08.2

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.9

We've got a little bit of different type or kind of attack against Lutsi.

0:19.1

Now, Lutsi or Luki is typically coming with OpenWRT.

0:24.7

That's a very popular router software firmware that's often installed on various

0:31.0

routers and alternative to a commercial firmware that may come with those routers.

0:37.4

There are also a handful of commercial routers that come with OpenWRT pre-installed.

0:43.9

What's different about these attacks is that they are looking for a sub-directory called Top Dash

0:49.9

IoT.

0:51.2

This is not a default component as far as I can tell, so we're wondering a little bit what this is not a default component as far as i can tell so we're wondering a little bit

0:56.5

what this is all about a reader on twitter pointed to a chinese maker of seller routers

1:05.1

m to m and apparently they are using this directory and they they're coming with OpenWRT.

1:12.8

Still have to verify this.

1:14.7

Don't have one of their products sitting here.

1:17.0

If anybody does, would like to see a confirmation.

1:21.3

There was also a comment on the post that is maybe related to some Lua scripts possible, but haven't really spotted

1:30.6

like an NMAP Lua script, anything like this, that would look for this particular URL.

1:36.5

So if you have any ideas, let me know, and you would see Lucy dash static slash top dash IoT. And then they're typically looking for a FAF icon file and a specific

1:49.1

image file in that directory. These mobile routers are a common target so wouldn't be a surprise

1:55.9

that someone figured out some kind of vulnerability even if it's just a weak password. And my usual disclaimer here do not expose any admin interface, even if it is OpenWRT,

2:07.2

which has a pretty good reputation to the public.

2:11.0

A couple days ago, I talked about how Google's voice recognition service was used to preach

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.