ISC StormCast for Friday, November 17th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 November 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, November 17th, 2017 edition of the Sands and at Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.4 | And today I'm recording from Jacksonville, Florida. |
| 0:12.6 | Xavier today posted about his Splank dashboard that he's using to look for anomalous DNS activity. |
| 0:25.4 | Pretty nice queries in here. He promised for tomorrow blog post that describes how to actually build this particular dashboard, but the queries |
| 0:33.2 | themselves are of interest, of course, and could also be applied to other systems, not just |
| 0:41.0 | to Splunk. |
| 0:42.8 | And Oracle released a critical surprise update for PeopleSoft. |
| 0:48.7 | This update fixes a total of five different vulnerabilities in Jolt. |
| 0:53.0 | Now Jolt is part of Tuxedo, |
| 0:55.1 | which in turn is the application server |
| 0:58.1 | that PeopleSoft uses to deal with non-Java applications. |
| 1:04.7 | And of course, given that this was a surprise update, |
| 1:07.9 | the vulnerabilities addressed here are rather severe. The first one does allow an attacker |
| 1:14.6 | with network access, but no authentication to take over Tuxedo and essentially compromise PeopleSoft |
| 1:23.5 | systems via TXedo. Second one, not quite as bad because the attacker first has to log in, |
| 1:30.3 | but once the attacker logs in, the attacker is able to read arbitrary memory from the system. |
| 1:37.3 | Then we also have the ability to prude force domain passwords to gain read-only access to data, stack overflow that could be used to bypass authentication, |
| 1:51.0 | and finally a heap overflow that, while difficult to exploit, can also be used to bypass authentication. |
| 1:58.0 | So a total of five different vulnerabilities definitely rated as a patch now. |
| 2:05.4 | I didn't see any exploits published yet for any of these vulnerabilities, but given the |
| 2:10.8 | prominence of PeopleSoft, I'm pretty sure someone is already working on an exploit. |
| 2:28.3 | Now, this vulnerability in jolt affecting PeopleSoft is a typical example of a vulnerability that's being introduced to software due to dependencies. GitHub is trying to help developers that are using GitHub to identify these vulnerabilities better. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

