ISC StormCast for Friday, September 2nd, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 September 2022
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, September 2, 2020 edition of the Sands and at Storm Center's |
| 0:07.5 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.9 | Yesterday I talked about Apache, patching a vulnerability in Geode. I noted how this deserlerization vulnerability CVE 2020-37021 |
| 0:27.6 | only affects Geode if Java 8 is used and if the data is being delivered via JMX. |
| 0:34.6 | JMX, that's the Java management extension, |
| 0:38.4 | is a standard API that allows you to monitor and manage services. |
| 0:44.2 | It is an important vulnerability, |
| 0:47.1 | but overall I didn't consider it urgent, |
| 0:49.8 | given that these are not services that are typically exposed. |
| 0:55.6 | But when looking at my honeypot logs today, I noticed some new scans that started showing up |
| 1:02.6 | around the time the geot vulnerability started to become known. |
| 1:07.8 | The requests used a URL typically for Jolokia, and I hope I'm pronouncing this correctly, |
| 1:14.9 | an HTTP to JMX Gateway. I believe it is plausible that some attempts to find hosts exposing |
| 1:23.5 | GMX via this interface are being conducted here. |
| 1:28.3 | Interestingly, these requests do not use HTTP, only HTTP port 80 and 8080. |
| 1:35.3 | At this point only one particular IP address is sourcing these scans, an unremarkable |
| 1:42.3 | IP address assigned to a Kolo provider. |
| 1:46.4 | I've not really seen any direct exploit attempts, |
| 1:50.0 | and the honeypot that detects these attempts did not really attempt to impersonate any of these applications. |
| 1:59.5 | So if this is just a scan, sort of build a target list or such, |
| 2:02.8 | of course I wouldn't necessarily see the follow-up scans, then, or attacks. So no exploit |
| 2:11.2 | attempts in so far, not clear if they're actually going after the Gio'd vulnerability, but the |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

