ISC StormCast for Monday, August 10th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 August 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, August 10th, 2020 edition of the Sanctur Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.5 | And this weekend, DefCon, of course, happened remotely as everything these days. |
| 0:19.5 | And one of the big topics, again, IoT and cameras. Now, |
| 0:25.4 | Guy also took a look at his honeypot and saw exploitation attempts against some older vulnerabilities |
| 0:33.2 | from 2017, actually, against wireless IP Wi-Fi cam cameras. This is a generic type that's |
| 0:43.5 | being produced and marketed under 1,250 different brand names and models. So essentially |
| 0:51.2 | the same camera shows up in different housings and under different names, |
| 0:57.6 | making it pretty difficult to identify if your camera is vulnerable. The exploit as often for |
| 1:05.3 | these type of systems is pretty straightforward. Just a simple get request with the right parameters, allow you to execute arbitrary code. |
| 1:15.0 | Now, the one type of attack that Guy was sort of zooming in on here is those that establish backdoors with Netcat. |
| 1:22.7 | Essentially, they are setting up Netcat in order to then connect back to the source of the attack and expose |
| 1:29.8 | a shell. |
| 1:30.8 | Very simple, very straightforward attack and of course a bit more robust the sense that |
| 1:36.3 | the attacker doesn't actually need to prude force a password in this way. |
| 1:41.6 | They just get a shell back and then of course can do whatever they need to do using that shell using a follow-up attack. |
| 1:51.2 | And today, of course, we'll be a little bit DefCon heavy, and we have a second story here coming from Checkpoint. |
| 1:56.6 | It was actually pre-announced on Thursday and it's about vulnerabilities that checkpoint |
| 2:03.1 | discovered in Qualcomm's Snapdragon. |
| 2:06.9 | If you have an Android phone, it's very likely that one of these Snapdragon chips is powering |
| 2:13.0 | your phone. |
| 2:13.9 | They're often referred to as a DSP or digital signal processor because it does a lot more than really just a CPU. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

