ISC StormCast for Friday, October 9th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 October 2020
⏱️ 20 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, October 9th, 2020 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:13.5 | When you're using APIs and cloud services, you often deal with a large number of API keys that of course have to be maintained, |
| 0:23.6 | have to be rotated, and have to be kept secret. |
| 0:27.6 | To simplify some of this, we have essentially the equivalent of a password manager for API keys |
| 0:35.6 | and that's I guess how you can describe HashiCorp's |
| 0:41.2 | wall. So what this product essentially does is that it maps your users to particular |
| 0:49.1 | users and roles that you define in various cloud products like for for example, AWS or Google Cloud. |
| 0:57.0 | Well, Google's project, Zero, took a closer look at Hashikorp Walt and found two interesting |
| 1:04.0 | vulnerabilities. One is actually related to how Go the language that the Hachorp's Walt is written in deals with XML. |
| 1:14.6 | Most XML parsers, if you feed them documents that are part XML, part something else, |
| 1:21.6 | well, they will just refuse to parse the document. |
| 1:25.6 | Now in Go's XML decoder, anything that's not XML in the beginning |
| 1:31.7 | will be ignored. So one trick these researchers played was to actually trigger a response. |
| 1:40.2 | It was actually JSON encoded, but included the XML response that they tried to get the |
| 1:47.6 | Hachicorp wall to accept, and that's sort of how they bypassed some of the authentication |
| 1:54.6 | in Hachicorp's wall. |
| 1:56.9 | Now, this essentially then worked against EWS and the attacker would have been able to essentially |
| 2:03.6 | authenticate to AWS using this vulnerability in Hachercorp. |
| 2:09.6 | The second vulnerability, also authentication bypass vulnerability, but against Google's cloud, is different in that it does abuse |
| 2:21.9 | vulnerability how JSON Web tokens are implemented by Hashy Corp Walt. All of these |
| 2:28.8 | vulnerabilities have been addressed by Hashy Corp so it should no longer really |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

