meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 17th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 17 May 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Vulnerability Scanner NTLM Relay; ARIN Revokes Malicious IPs; Cisco Patches; ILS Hacks

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, May 17th, 2019 edition of the Sandton and Storms, Stormcast. My name is

0:08.0

Johannes Ulrich. And the I am recording from Jacksonville, Florida. Xavier came across an interesting

0:15.3

attack, taking advantage of authenticated vulnerability scans. In this particular case, the attacker was trying

0:24.9

to do an NTLM relay attack. Now, an NTLM relay attack does need an authenticated user that actually

0:32.3

logs in into a system in order to then relay the connections and that way take advantage of credentials.

0:40.9

The user being used here happened to be the vulnerability scanner.

0:46.0

Now, the advantage of an attacker using a vulnerability scanner is that first of all, the credentials

0:51.7

usually work with pretty much all systems on the network.

0:56.0

Secondly, there are sometimes elevated credentials in order to accurately assess the target system for security vulnerabilities.

1:05.0

Also, in monitoring connections from the vulnerability scanner to many hosts your network may not really

1:12.8

show up as an anomaly because that's what vulnerability scanners do unlike any other user that

1:19.8

usually only logs in to a couple different systems in which case well it sort of shows up

1:26.5

if you're looking for it and that's sort of one of the standard anomalies that many systems look for, where you have one user connecting all of a sudden to many different systems.

1:36.8

Not too much you can do about this.

1:38.7

You do want a vulnerability scanner.

1:40.9

You do want it to authenticate itself.

1:43.4

The real fix here is to prevent

1:46.0

these NTLM relay attacks using SMB version 3 and enabling SMB signing. And remember, it may not

1:55.0

be that easy to pull off the attack without the vulnerability scanner, but of course it's still possible, so it's not the vulnerability

2:02.5

scanner really sort of being necessary here for the attacker. And Aaron won an important court

2:10.9

battle regarding the fraudulent transfer of IPV4 addresses. Due to IPV4 addresses being in short supply IPV4

2:22.0

addresses of course have been transferred between companies but in this case the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.