meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 26th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 26 May 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. IR Case/Alert Mgnmt; GitLab Exploit; Expo OAUTH Vuln Details; Mitel MiVoice and DLink Vulnerabilities;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, May 26, 2023 edition of the Zanz and the Storm Center's Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida. If you're looking for a system to manage alerts and cases in your sock.

0:21.2

Tom has a great little diary for you today looking at the hive.

0:26.7

That's a very famous and a frequently used system for this.

0:30.4

And then DFR Iris.

0:33.3

These two systems are both open source.

0:36.2

They do support alert cues.

0:38.7

They have case management, playbooks, everything you need in order to basically have some robust

0:45.5

alert and case management for your SOC.

0:49.4

So quick introduction here to, in particular,FIR iris and with links for more information.

1:01.4

And yesterday I mentioned how GitLab released version 16.0.1. It fixes a critical C-VAS score.

1:12.5

10 vulnerability.

1:15.6

It's a directory traversal vulnerability.

1:20.7

And, well, one of the questions, of course, always, how it's going to be exploited.

1:24.8

Well, we do have a proof of concept exploit available now. One of the dependencies here is that the project that you are

1:30.8

actually submitting a comment with an attachment to has to be nested in at least five

1:36.7

groups. This then triggers the directory traversal, essentially a URL encoded slash that's

1:43.8

not properly escaped, and with

1:47.0

that Netnet hacker is able to read arbitrary files from the system. The proof of concept just reads

1:54.9

the Etsy password file. So this is now definitely a vulnerability that you do want to patch before you leave for the weekend.

2:03.6

Yes, it has some dependencies like these nested projects and such,

2:08.6

but I wouldn't count on you finding all the projects and all the nested relationships

2:14.6

to adequately make sure that you're not vulnerable.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.