ISC StormCast for Friday, May 18th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 May 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, May 18th, 2018 edition of the Santernut StormSenter's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida. |
| 0:11.0 | Got an interesting case we have been working on for the last few days about scans for port 3,333. |
| 0:20.0 | This port is heavily used by miners and has also been used as a remote admin interface |
| 0:28.0 | for the Claymore miner. Claymore added an unauthenticated JSON RPC API that essentially |
| 0:36.8 | allows remote code execution. |
| 0:39.6 | Now while this wasn't the intent of the API, the exploitation is pretty straightforward |
| 0:45.9 | and has been known at least since February. |
| 0:49.1 | The problem is that not only the configuration file but also a reboot batch file can be overwritten using |
| 0:57.6 | this API and then just by rebooting the software you are then able to execute that file. |
| 1:06.4 | Now the most common command that I have seen being executed this way is just restarting Claymore |
| 1:12.3 | Miner, of course, with different parameters, gaining money to whoever launched the exploit. |
| 1:18.5 | Interestingly, they retain the admin interface on the same port, so these systems can easily |
| 1:25.2 | be exploited again and again. |
| 1:28.3 | If you are running Claymore Minor, there are a couple things that you can do. |
| 1:32.3 | First of all, you can just disable this particular remote admin API. |
| 1:37.3 | That's probably the safest course of action. |
| 1:39.3 | You can also make it listen on a different port or by giving it a negative port number. So let's say minus |
| 1:47.0 | 5,000. Then it will listen on port 5,000, but it will disable some of the more dangerous |
| 1:53.2 | commands like overriding configuration files. Taking a quick look at some of the mining pools and |
| 1:59.9 | the earnings of the mining pool IDs that we have seen indicates that the hackers here made about a thousand dollars or so, but varies based on the attacker. |
| 2:11.4 | And well, for everybody here worrying about PCI, a new miner version of PCI was released version 321. Last version was 3.2, which |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

