meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 9th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 9 March 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apache #Solr Vulnerability and #XMRig; CIRMEB4NK #IRC Bot; #Cisco Patches; Any.Run

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 9th, 2018 edition of the Sansonet Stormers Stormcast.

0:07.2

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:12.4

Remember a few weeks ago we had a crypto coin miner that installed itself on a number of

0:18.8

PeopleSoft servers and the like using an Oracle WebLogic vulnerability.

0:24.6

Well, it looks like this particular group is back, but this time they turn their attention

0:30.6

to Apache Solar.

0:32.6

Apache Solar is, well, what is a database that is often used for full-text searches?

0:40.3

You find it used, for example, for website search and the like.

0:46.3

And as such, a lot of sites may be using Apache Solar without explicitly being aware of it.

0:53.3

And just avoid confusion whenever I mention Apache, this is not the Apache Web Server.

0:59.0

The Apache project has many other software projects that they're covering under their umbrella,

1:05.0

and solar is not something that typically comes with the Apache web server.

1:12.6

The root cause here is actually an XML external entity vulnerability.

1:18.6

These vulnerabilities are quite common when you're parsing XML and you're not being careful

1:25.6

in how you're validating your XML or how you're configuring your parser.

1:31.4

In this particular case, this vulnerability can lead to arbitrary code execution, and that's

1:38.0

exactly what's being exploited here. The vulnerability became known back in October last year. Only a couple days after

1:48.0

the vulnerability was announced and patched, an exploit was released. And just likes of the

1:54.4

Weblogic vulnerability, the exploit is actually relatively simple, reliable and easy to use in various scripts,

2:03.0

which of course helps our attackers here installing the exact same Monero Miner that we have seen

2:09.9

with WebLogic.

2:11.7

Just like with the WebLogic vulnerability, Renato took the lead on this and he actually

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.