ISC StormCast for Friday, May 26th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 May 2017
⏱️ 14 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, May 26, 2017 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich, |
| 0:08.5 | and the I'm recording from Jacksonville, Florida. And well, it's just barely a week after one a crypt, |
| 0:15.2 | and we already have another important SMB vulnerability. Now, this one isn't quite as bad as the one that |
| 0:23.4 | led to that famous ransomware warm outbreak but still pretty bad if you are running |
| 0:31.0 | Samba. Samba is the open source implementation of the SMPP, often found on Linux-based systems. |
| 0:40.2 | And the problem here is that NetHacker that can upload a file to your system is then able |
| 0:46.8 | to execute that file. So first of all, the attacker has to be able to upload a file, which |
| 0:53.4 | typically means that the attacker needs credentials in order to upload a file, which typically means that the |
| 0:54.4 | attacker needs credentials in order to accomplish that. |
| 0:57.5 | So that's a little bit more of a hurdle than what we had with the Wanacript exploit that |
| 1:02.7 | did not require any authentication. |
| 1:06.4 | The bug is actually pretty simple here. |
| 1:09.6 | In SMB, we have the opportunity to connect to named pipes. |
| 1:14.6 | Now, if the named pipe is actually, if the name of that pipe contains a path, then that particular file is executed. |
| 1:23.6 | So really what they forgot here is they forgot to check for the slash in the pipe name. |
| 1:29.1 | And this is really what this patch does. |
| 1:32.8 | All recent versions of Samba, meaning 3.5 and up are vulnerable. |
| 1:38.9 | Now, if you are a Windows shop and typically don't run Linux, then this may be less of interest to you. But remember, |
| 1:46.7 | if you have any of these network storage devices like QNAP, Synology, and the like, they typically |
| 1:53.1 | do use Samba in order to share files with Windows systems. So you may be affected. I've seen a patch |
| 2:00.5 | from Synology. I haven't really looked |
| 2:02.4 | at the other manufacturers yet if they already came up with something. Billy Ross, who has looked |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

