ISC StormCast for Friday, May 3rd 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, May 3rd, 2019 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. And I'm recording from Augusta, Georgia. |
| 0:13.2 | Just about a week after we had this critical new vulnerability in WebLogic, SAP security company on NAPSIS released a summary of |
| 0:24.7 | some attacks they are seeing against, well, Oracle competitor SAP, using a set of new exploits. |
| 0:32.7 | Now, none of the vulnerabilities being targeted here are new. It's actually not so much |
| 0:39.2 | vulnerabilities in the classic sense that are being exploited here but more |
| 0:44.2 | misconfiguration in the SAP Gateway and messaging system. Essentially the main |
| 0:51.2 | issue here is that the systems implement access control lists. |
| 0:56.0 | These access control lists need to be properly configured. |
| 0:59.0 | If they are not, then you may allow outsiders to actually execute code on your systems. |
| 1:07.0 | So, an abscess advice is review these access control lists, make sure they are properly |
| 1:13.1 | configured, and they also offer a snort signature to detect if someone is already exploiting |
| 1:20.5 | any weaknesses. |
| 1:23.5 | And Cisco this week released a number of patches. |
| 1:26.6 | Most interesting is a critical patch for the Cisco Nexus 9,000 series fabric switches. |
| 1:35.1 | These particular switches are suffering from a default SSH key vulnerability. |
| 1:41.4 | So essentially all of these switches are accessible via one particular |
| 1:46.5 | ZH key that is stored within these devices. It's the same key for all devices. Interestingly, |
| 1:54.7 | this vulnerability is only exploitable via IPV6. And it's about two months now that the Coin Hive, the website that sort of popularized the idea |
| 2:06.6 | of JavaScript-based cryptojacking shut down its service. |
| 2:13.7 | And Malberabytes use this as an opportunity to take a look at what's currently going on with |
| 2:20.3 | cryptojacking. Well, probably not a big surprise, but there is still an awful lot of coin hive |
| 2:26.8 | code out there. It's no longer functional in the sense that it no longer actually produces |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

