ISC StormCast for Friday, November 18th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 November 2022
⏱️ 14 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, November 18, 2020 edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.0 | Just a quick diary from myself today here at the Internet Storm Center, that's about well not quite security related. |
| 0:22.8 | It's really sort of availability related if you're trying to do failover and you're trying to |
| 0:28.7 | figure out if your connection is up and running. |
| 0:31.5 | Well, a ping is sort of your go-to utility. |
| 0:35.3 | Turns out not a working utility if you are using T-Mobile's 5G home service |
| 0:41.8 | as a backup as I'm doing here. Well, it turns out that T-Mobile does filter all ICMP traffic, |
| 0:49.9 | including error messages, which can also cause some interesting issues. |
| 0:55.7 | So just a little bit here for awareness, ISP sometimes don't play nice |
| 1:00.7 | and definitely don't really play any more by the RFCs than many attackers. |
| 1:07.6 | And then we got an interesting vulnerability from Adlation in its Bitbucket server and |
| 1:13.6 | data center products. |
| 1:15.6 | A little bit difficult to figure out how severe this issue is. |
| 1:19.6 | And that's something that you probably have to figure out yourself. |
| 1:23.6 | Adelaideon only rates it as low, but it is an arbitrary code execution vulnerability. However, it does require authentication and does require that the user is able to change their username. But what can then happen is that the environment variable gets set that then leads |
| 1:45.7 | to operating code execution. So I imagine a scenario where the user basically changes the username |
| 1:51.8 | to something that contains shell code that will then be executed. And Mitiga, a company that deals with Cloud Incense Response, has released a blog post where they looked at leaks of Amazon's RDS snapshots. |
| 2:12.3 | RDS, that's the relational database service that Amazon offers as part of its AWS offerings. |
| 2:20.5 | And, well, it's a database, of course, with sort of my SQL or Postgres backends. |
| 2:25.4 | And it has the ability to share a copy of the database as a snapshot. |
| 2:30.3 | And that's also done with a regular database off. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

