meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, April 8th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 8 April 2024

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Heartbleed 10th Anniversary; Magento Backdoor; Fighting DNS Spoofing; Brocade Vuln; @sans_emea evening talk

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, April 8th, 2024 edition of the Sandsenet Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich and today I'm recording from London, England.

0:12.7

As a quick reminder today, April 7th as I record this podcast, it's also the 10th anniversary of Heartbleed. Heartbleed, of course, is often seen as sort of

0:23.3

a watershed moment in open source security. And we had sort of another moment like this,

0:28.9

just the last couple weeks with the XC Util Back Door. Let's hope that some of the funding

0:35.7

for Buck Bounties and such is expanding.

0:38.7

That's sort of what got started after Heartbleed.

0:42.2

We also got another side note to this entire event, and this is another merch request

0:48.9

that the attacker who planted the XC Util Backdoor made for Lib Archive.

0:55.3

Now this particular request was made November 2021 and it replaced a safe printf function

1:04.2

with just regular F printf function.

1:08.5

So that way escape sequences may not necessarily be encoded correctly.

1:14.7

This function happened in an error message where then unsafe input may be echoed back to the victim

1:22.9

and the insertion of escape sequences could potentially lead to code execution.

1:29.9

It's not clear if this was ever exploited in any way, but of course it's a very typical way

1:35.9

to implant more subtle back doors by including bugs in code that even after a more casual review, even if they're found, are not

1:46.6

necessarily considered malicious, just careless, and as such don't necessarily blow the identity

1:53.0

of that malicious submitter.

1:55.8

The change in lip archive has been removed, but of course that code was out for a lot longer than the XE Util Backdoor,

2:04.6

so definitely something where updates and such need to be applied.

2:10.6

Researchers at SANSAC have found an interesting persistent mechanism being used by attackers attacking the Magento E-commerce

2:20.3

suite. This particular Magento backdoor takes advantage of the layout update database. This database includes

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.