ISC StormCast for Monday, August 5th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 August 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, August 5th, 2019 edition of the Sansonet Stormson. |
| 0:06.4 | My name is Johannes Ulrich. |
| 0:08.9 | And I'm recording from Jacksonville, Florida. |
| 0:13.4 | We've got a nice blog post by Avinajian. |
| 0:17.2 | And he's talking sort of about a follow-up of some discovery that he made a couple months ago |
| 0:23.8 | about exposed Jira servers. |
| 0:27.4 | Now, back a couple months ago, it was in particular about a NASA Jira server that he found, |
| 0:34.2 | but he took that a little bit further. |
| 0:37.4 | And what he found was literally hundreds, |
| 0:40.7 | if not thousands of GERA servers, some of them belonging to Fortune 500 companies that are |
| 0:47.8 | exposing user details. The problem here is that in GERA, when you're setting up a project, by default, the visibility |
| 0:57.7 | is set to all users and everyone, which actually means, well, literally all users, not just |
| 1:03.6 | users that are registered with the server. |
| 1:07.4 | Instead, it exposes, for example, user names and email addresses as well as their |
| 1:14.2 | roles and gira groups to anybody who comes across that gera server. |
| 1:21.0 | jera is quickly becoming sort of one of those systems that you probably should not expose to the public internet at all. Now, this can be tricky |
| 1:31.2 | given some of the global nature of some development teams, but maybe protected behind VPN or |
| 1:40.6 | some other form of additional layer of authentication, |
| 1:45.0 | maybe a better idea. |
| 1:47.7 | Avinaj was able to find some of these servers |
| 1:50.2 | with simple Google queries |
| 1:52.2 | because after all, Google knows everything. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

