ISC StormCast for Friday, October 30th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 October 2020
⏱️ 15 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, October 30th, 2020 edition of the Sandstone Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich. |
| 0:09.2 | And today I'm recording from Jacksonville, Florida. |
| 0:13.5 | So yesterday I mentioned that we did see first exploit attempts against our weblogic honeypots using CVE 202014882. |
| 0:25.6 | This is a vulnerability that was patched about a month ago as part of Oracle's quarterly |
| 0:32.6 | critical patch update. |
| 0:34.6 | The only activity that we have observed so far is just testing the vulnerability, |
| 0:41.1 | but it is actually trying to exploit it, for example, triggering DNS lookup and not installing |
| 0:50.5 | any code or running any malicious commands other than whatever is required to trigger |
| 0:57.0 | the DNS lookup. What is however interesting also is that around noon today, the exploit |
| 1:03.9 | activity has ceased, at least against our honeypots. We identified about three or four different entity, it seemed like, |
| 1:13.6 | based on the exploits being used. Now, they all used the same basic exploits, but everybody said |
| 1:20.0 | they had their own little trick how they probed for vulnerable systems. So we can only assume |
| 1:26.5 | that by now they're done scanning the internet and |
| 1:30.3 | well, maybe they'll come back and launch actual exploits against systems that they found to be |
| 1:36.6 | vulnerable. What's a little bit odd is that the exploit activity really has sort of completely |
| 1:41.6 | stopped over the last few hours. Typically with something |
| 1:45.2 | that's so easy to exploit, we tend to have plenty of script kitties that go after these systems. |
| 1:52.7 | Maybe it'll take them a couple more days to get this exploit integrated into whatever kit |
| 1:58.7 | they're using. But well, the advice remains patch. |
| 2:02.6 | Patch as fast as you can if you are running WebLogic. |
| 2:06.6 | We tested these exploits against our own WebLogic setups, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

