meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, November 3rd, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 3 November 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Inflated PE Files; ActiveMQ Exploit; Firepower Vuln; Malicious NPM;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, November 3, 2003 edition of the Sandcented Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.3

We talked a couple times already this week about attackers using artificially inflated PE files, basically very large files in order to bypass security tools.

0:24.2

Today we got a solution.

0:26.6

DDA is walking us in his quick tip through how to, first of all,

0:32.5

figure out if you're dealing with a file that just has some padding at the end,

0:37.1

and secondly, also how to

0:39.1

remove that padding to make analysis easier it's really a combination of two of dda's famous tools

0:47.0

a p e check will summarize the different sections of a p e file and will tell you that you have this

0:53.4

very large overlay with just one unique

0:57.0

byte and in this case just zeros and then using a second tool at tail.p.I.

1:04.0

It's then able to extract just the part that actually matters.

1:10.0

So hope this helps and for details details again, refer to DDA's diary.

1:16.9

And Apache just patched a vulnerability in Active MQ, the message Q tool that's being maintained

1:24.9

by the Apache Foundation.

1:26.7

This vulnerability does allow arbitrary remote code execution. that's being maintained by the Apache Foundation.

1:35.8

This vulnerability does allow arbitrary remote code execution to anybody with network access to the broker.

1:40.1

This vulnerability is now already being exploited.

1:48.8

Apparently, the Hello Kitty Ransomber group is exploiting this vulnerability, according to Rapid 7.

1:57.5

Proof of concepts have been around for about a week, and sadly, exploitation is actually pretty trivial for this vulnerability.

2:04.3

You literally just have to basically include some XML in the message with the bash command you would like to execute.

2:09.1

And in new vulnerabilities, we did get patches from Cisco, in particular noteworthy.

2:15.2

Here is CVE 2020-8.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.