4.9 • 696 Ratings
🗓️ 25 October 2024
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, October 25th, 2024 edition of the Sansonet Storm Center's Stormcast. |
0:08.1 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:13.6 | Today I wrote about scans that we are seeing against development tools that are often left enabled on production websites. These are typically |
0:23.3 | plugins or additional features that you may enable to help developers debug code on the website. |
0:30.5 | As part of this feature set, they often leak critical information about the website, like |
0:36.9 | the configuration, credentials, |
0:39.5 | and in some cases do provide the ability to execute arbitrary code. |
0:44.6 | I'm just going in this post over some of the scans that we're seeing for these tools. |
0:50.6 | There are, of course, many more out there that I probably missed when I sort of was |
0:54.8 | scanning through the logs there. If there are any that I should have mentioned, let me know, |
0:59.4 | and I'll take a look how actively they are being exploited. But this is certainly something |
1:05.3 | that you want to proactively scan for. And while we don't have any 40 net vulnerabilities today to talk about, instead, we have |
1:15.5 | one from Cisco, less severe than what we have sort of seen lately, but it's already being |
1:20.5 | exploited. |
1:21.4 | It's a denial of service vulnerability in the ASA and Firepower VPN Appline. |
1:28.3 | So only if you have the remote access VPN service enabled, you are vulnerable, and it's a |
1:34.8 | pretty straightforward denial of service vulnerability that's being triggered by brute force |
1:40.9 | login attempts. |
1:42.1 | One thing to point out from the Cisco advisory regarding these attacks is that they observed |
1:48.9 | predominantly originating from Tor exit nodes and other anonymizing tunnels and proxies. |
1:56.2 | So there may be a block list approach here that can help you a little bit mitigate these attacks. |
2:03.9 | Another Cisco Warnaby that was addressed that has a pretty high CFSS score of 9.9, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.