meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 4th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 4 May 2018

⏱️ 15 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More WebLogic xploits; Ouch! GDPR ; GitHub/Twitter pw loggin; #sans_edu Disrupting PowerShell Empire

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, May 4th, 2018 edition of the Sansonet Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich and I am recording from Jacksonville, Florida.

0:12.0

Renato took another look at his Weblogic Honeypot. No surprise, he's finding plenty of exploits taking advantage of the most recent WebLogic vulnerability.

0:24.4

Remember, this is the one that's not perfectly patched yet.

0:28.8

We have also seen over the last couple weeks pronounced Spike in Scans for Port 7,001,

0:35.4

which is the port typically used by WebLogic. As far as payloads go,

0:40.6

Renato found yet another crypto miner, but in addition, it also installed a scanning component

0:46.3

that will look for additional vulnerable systems. We have not seen that much of it in the past.

0:52.9

Usually they just installed a miner, don't install

0:55.8

the scanner, probably getting a little bit more aggressive in trying to find hosts that got

1:01.6

missed by all the other scans for this Weblogic vulnerability. On average, only takes a couple

1:08.2

hours these days for a vulnerable host running web logic

1:12.9

to be exploited.

1:14.9

Another sort of shift that we have seen and that's also here something that Renato observed

1:20.2

using his honeypot was that more and more of these attacks are not targeting Windows hosts,

1:27.0

probably because all the Unix hosts have already been

1:30.2

exploited. WebLogic can run on Windows or Unix either is vulnerable, so instead of a

1:37.8

Bash script you'll see a PowerShell script used if the attack is targeting Windows.

1:45.0

And the Sand Security Awareness Project did publish its monthly Oach newsletter on Thursday.

1:52.4

This time it's all about GDPR.

1:54.7

GDPR will go into effect later this month.

1:58.9

If you haven't heard about it yet, it's probably too late to learn about

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.