ISC StormCast for Friday, September 27th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 September 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, September 27th, 2019 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:10.2 | I'm recording from London, England. It took only a couple days for the bulletin-vorn ability to be targeted by Botnet's bad's bad packets has an interesting report of a botnet |
| 0:24.5 | that they observed attacking vulnerable the bulletin instances what it does is it actually well |
| 0:30.9 | sort of patches the vulnerability in adding a password to the vulnerable eval function. |
| 0:39.7 | So now only the owner of the botnet who knows the password is able to actually take |
| 0:46.5 | advantage of the vulnerability. |
| 0:49.1 | It's not clear if the password is unique for particular sites or if they're using the same password across all |
| 0:56.5 | sites, which of course would sort of defeat its purpose now that this password has been made |
| 1:02.4 | public. Just to reiterate what I said yesterday, if you haven't patched yet or if you patched |
| 1:08.3 | sort of in the last 24 hours, essentially after the official patch was |
| 1:12.7 | released, you should assume that your bulletin board has already been compromised. |
| 1:19.0 | This is just one example, how an attacker could use this vulnerability to essentially add |
| 1:25.7 | a back door. |
| 1:34.6 | And then we got a security bulletin from Cisco that affects the Model 800 industrial ISR routers and Model 1000 grit routers. |
| 1:39.8 | Now these devices are typically used in critical infrastructure, which makes the number |
| 1:46.7 | of vulnerable devices probably quite small, but of course their location may be critical. |
| 1:54.0 | The problem here is approach escalation vulnerability, an attacker with guest access, |
| 1:59.6 | could access a VM that only administrative |
| 2:03.6 | users should have access to, and that then of course leads to an elevation of privileges. |
| 2:10.6 | And a few days ago I mentioned the critical vulnerability in the cloud native registry harbor that |
| 2:19.4 | Palo Alto discovered. |
| 2:20.8 | Well, Harbor is used in a number of commercial products as well. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

