4.9 • 696 Ratings
🗓️ 16 December 2024
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, December 16, 2024 edition of the Sans and a Storm Center's Stormcast. |
0:09.0 | My name is Johannes Ulrich and I'm recording from Washington, D.C. |
0:14.8 | Let's start with a quick update on the Struts 2 vulnerability that I mentioned on Friday. This vulnerability now appears to be |
0:24.2 | exploited. The exploit itself may be a little bit more inspired by it because they're like |
0:29.2 | these two very similar vulnerabilities. So not 100% clear what's being exploited and if the exploit |
0:35.6 | as executed here would work on a |
0:38.8 | vulnerable system I don't have a vulnerable system to test with so far we are |
0:44.4 | seeing one IP address scanning for the vulnerability it first attempts to |
0:50.0 | upload a file called exploit.jSP to the system. This file includes a quick one-liner |
0:58.2 | that just prints back confirmation. The attacker will then try to access that file to check |
1:05.7 | whether or not the system is confirmed as vulnerable. So this is now definitely a must-patch vulnerability. |
1:14.3 | The problem, again, is if you're actually using the upload feature, |
1:18.2 | so if your system is vulnerable, |
1:20.1 | you must rewrite the upload feature |
1:23.2 | because the fix is not backwards compatible. |
1:35.3 | And Citrix published a document in response to a recent increase in password spraying. It hacks against Citrix NetScaler installs. |
1:39.3 | Password spraying, of course, big issue for lots of appliances. |
1:44.8 | Cisco had issues with that earlier this year. |
1:49.0 | One interesting issue here that's noted by the advisory is that it's not just about attackers |
1:54.9 | eventually getting access to the devices, but that these passport spraying attacks are |
2:00.6 | aggressive enough, where they will also cause a denial of service and also overload the lock processing pipeline. |
2:08.6 | In response, Citrix of course recommends multi-factor authentication should pretty much be the default now for appliances like this and then recommends, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.