4.9 • 696 Ratings
🗓️ 19 April 2021
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, April 19th, 2021 edition of the Santernut Storm Center's Stormcast. |
0:08.1 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:13.8 | This weekend, the day went a little bit more into depth with decoding Cobalt strike traffic. |
0:21.0 | Remember, he talked about this in the past, |
0:23.3 | and one of the features here to remember with Cobalt Strike |
0:27.4 | is that the traffic is not encrypted if the attacker |
0:31.8 | uses the trial version of Cobalt Strike. |
0:35.5 | So that's sort of how you would get access to the data, but then of course |
0:39.3 | it's still encoded, so the DA walks you through some of the decoding of that traffic. |
0:47.8 | And I may have yet another significant breach that may affect your software supply chain. This time |
0:53.8 | it's CodeCove that's affected. |
0:57.0 | CodeCove makes software that checks code coverage during testing, |
1:01.5 | so it's often integrated in your CICD pipeline. |
1:06.4 | According to a statement on CodeCov's website, |
1:10.3 | the attacker was able to exploit a weakness in the Docker image creation process at CodeCuff that then gave the attacker access to a bash uploader script that's often used with CodeCuff and the attacker modified the script, essentially copying data to a third-party's |
1:31.7 | web server. So since this tool is often integrated in your development pipeline and essentially |
1:38.1 | conducts automatic tests and reports on them, any credentials that you used in your CICD pipeline may have been at risk. |
1:50.0 | A reasonable detailed statement by code curve that is linked to in the show notes does explain |
1:57.7 | what to look for, how to check whether or not the copy of this |
2:01.9 | batch uploader script that you're using is affected, and also how to fix the |
2:07.9 | problem if you're running into any affected bash uploader scripts. And |
2:13.4 | according to the statement, if you're self-hosting code curve, then you're less likely |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.