meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, September 15th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 15 September 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Webshells and Backdoors; D-Link Patch; Google Play Store Malware; Elasticsearch Malware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, September 15th, 2017 edition of the Santonet Storm Center's Stormcast.

0:08.3

My name is Johannes Ulrich, and the day I'm recording from Las Vegas, Nevada.

0:13.3

Xavier today took a quick look at a web shell that he found on Pastebin.

0:19.1

Now, web shells, of course, are often installed in the aftermath of a web application compromise.

0:26.1

Kind of interesting how this particular web shell downloaded part of its configuration as an image from Google user content.

0:36.4

The image then included XIF data, which actually decoded

0:40.6

to some of the configuration parameters for this particular web shell. In particular,

0:47.8

the email address to which details about infected hosts are being sent. Many of these web shells do have backdoors

0:57.0

like this that essentially report back whenever the web shell is installed on a system.

1:04.0

And earlier this week, a number of severe vulnerabilities were disclosed in the D-Link 850L router.

1:11.6

Now, these vulnerabilities were not disclosed responsibly, instead they were just posted as a

1:18.6

blog without first notifying D-Link.

1:21.6

D-Link now announced that they have a patch ready for these vulnerabilities and they will release it early next week.

1:31.1

So if you do have a D-Link 850L router, make sure you check sometime next week for this patch,

1:39.2

supposed to come out on the 19th.

1:42.3

Now, if you don't run a D-Link router and if you don't run this particular model from D-Link,

1:48.8

I recommend just for good measure, check if there is a firmware update for your router.

1:55.0

We did have a large number of router vulnerabilities disclosed over the last few months.

2:02.1

Really too many to mention them all here in the podcast.

2:05.7

So there is a pretty good chance that there may be an update for your router available.

2:11.0

And as usual, make sure that remote access to your admin interface is disabled.

2:18.4

And web browsers in recent months have become more and more stringent on what they call a secure site

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.