ISC StormCast for Friday, September 8th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 September 2017
⏱️ 16 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, September 8th, 2017 edition of the Sansonet Stormers Stormcast. My name is Johannes Ulrich, |
| 0:08.8 | and the time recording from Jacksonville, Florida. Well, and sadly, it looks like struts vulnerabilities are not going away. |
| 0:18.0 | We do have a second vulnerability here in Apache struts. This vulnerability is also |
| 0:24.5 | a remote code execution vulnerability but it only affects fairly specific |
| 0:31.0 | expressions so if you're not using these particular constructs in your code then you |
| 0:37.3 | shouldn't have a problem. |
| 0:39.0 | Of course, there will be a problem that you now have to figure out whether or not you're |
| 0:43.2 | using these constructs in your code and that could make things a little bit more complicated. |
| 0:49.5 | But well, the short answer is patch and update to the yet latest and greatest version. |
| 0:57.6 | That would be struts 2512 and struts 2334, depending on if you're on the 2.5 or 2.3 branch. |
| 1:08.4 | At the same time, we are actually seeing exploit attempts against the earlier struts |
| 1:14.0 | vulnerability. So that definitely has taken off after the meta-sploid module was released. |
| 1:21.3 | The exploit attempts that we have seen so far appear to be triggered by that meta-sploid module. |
| 1:28.3 | So individual attempts, no big kind of warm at this point, but we all know that's coming |
| 1:34.3 | next and that's probably going to show up within the next few days. |
| 1:39.3 | Still, I'm seeing enough of these exploit attempts where I would say if you are running a somewhat |
| 1:46.1 | higher profile website, someone probably already tried this particular exploit against your |
| 1:51.7 | site. |
| 1:52.7 | So again, before you update or as you update, make sure that your site hasn't already been compromised. |
| 2:00.3 | I usually don't cover a lot of breaches here because there are just too many of them, |
| 2:04.3 | but we do have one that's quite significant that was made public today, |
| 2:10.3 | and it affects the U.S. Credit Bureau Equifax. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

