ISC StormCast for Monday, December 30th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 December 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, December 30th, 2019 edition of the Sandsonet Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.0 | Last week I mentioned that we made a webcast about the new Citric vulnerability, |
| 0:18.0 | that effects like the Citric slash NetScaler Gateway devices. |
| 0:23.7 | We decided to do one on Tuesday. So tomorrow on Tuesday, 1 p.m. Eastern, we will do this |
| 0:30.6 | webcast to fill you in a little bit on this. And, well, a link to the signup page will be in the show notes again so far it looks like |
| 0:41.3 | this maybe a little bit slower than originally expected there is no proof of concept exploit |
| 0:47.7 | public yet which probably is sort of holding back the flood of requests trying to exploit this. |
| 0:55.0 | Haven't seen any sort of active exploitation of this vulnerability so far. |
| 1:00.0 | But while I'm talking about these VPNs and perimeter security devices, |
| 1:05.0 | Fox IT has an interesting report about some recent activity they're calling Operation Wokau or they're also associating |
| 1:12.7 | this with Chinese origin APT 20. |
| 1:17.7 | Now, this particular attack sort of was different in so far that the attacker got persistent |
| 1:24.1 | access to a VPN that did require two-factor authentication. |
| 1:29.9 | Of course, two-factor authentication is always mentioned as the solution to prevent someone |
| 1:35.8 | from just stealing credentials. |
| 1:38.5 | Apparently what happened here was that the victim did use a soft token. Now, soft tokens come in different forms and shapes. |
| 1:48.1 | For example, you can have them like on a mobile device, like a phone. In this case, the soft |
| 1:53.4 | token was installed on the laptop, which made it particular vulnerable. Pretty much all it took |
| 1:58.8 | was to copy that software, including the seed file that's |
| 2:03.2 | being used to actually generate these tokens to a different system, and the attacker was able |
| 2:09.2 | to then create these one-time passwords independently. Now, the victim here used the RSA implementation of these soft tokens, and typically |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

