meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, August 20th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 19 August 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. CVE-2018-8373 (VBScript Vulnerability); PHP Deserialization Vuln; HP Fax Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, August 20th, 2018 edition of the Sandcent, Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich, and I'm recording from Stockholm, Germany.

0:13.3

Remko published a diary collecting some of the resources regarding the fragment smack attack.

0:20.4

And essentially just summarizing what we know

0:22.5

about this attack so far, I mentioned it last week. That's this denial of service attack in

0:28.7

recent versions of Linux that's triggered by IP fragments. You don't actually need to necessarily

0:36.2

apply the patch to protect yourself from this problem.

0:40.2

You can also just reduce some of the fragment buffers back to the values actually they had before this became an issue.

0:50.4

Then I have another item that actually may have belonged into last week's podcast, and that's

0:58.0

a faxploit.

0:59.0

That's an exploit that checkpoint found against a number of HP multifunction devices.

1:06.0

What was sort of neat different about it was that in order to exploit this vulnerability, you have to send

1:11.4

a fax to that device via a good old phone line.

1:16.2

Now, one of the reasons I didn't actually cover it last week was the checkpoint release about

1:22.4

this, used a lot of hype in it.

1:24.7

Yes, it's a problem.

1:26.0

Yes, in particular large companies still use faxes. A lot of small companies too, I know a lot of hype in it. Yes, it's a problem. Yes, in particular large companies still use faxes.

1:29.4

A lot of small companies, too. I know a lot of contractors and such construction contractors

1:34.7

use still faxes. But there's sort of another facet to this that a reader sort of alerted me to.

1:41.6

And that's that, yes, HP has released updates for these machines but

1:46.8

if you're not using Windows you probably have a hard time applying this patch the patch so far

1:55.3

has only been released as a Windows executable so to apply it from a Mac, you essentially need to somehow boot Windows,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.