ISC StormCast for Monday, January 13th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 January 2020
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 13th, 2020 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich. |
| 0:09.1 | Today I'm recording from Jacksonville, Florida. |
| 0:14.0 | Well, a big event today and probably taking most of this podcast, if not everything, is the outbreak of exploits against the recent |
| 0:25.0 | Citrix ADC vulnerability. Also known as CVE 2019, 19781. The first exploit was published on Friday, |
| 0:37.1 | at least late Friday. |
| 0:38.7 | My time may have been Saturday for some people in Asia and just around midnight UTC. |
| 0:46.0 | The first exploit by Project Zero India was a simple shell script, essentially just three |
| 0:53.0 | different curl commands. |
| 0:55.7 | The first one would upload the file using the directory to reversal file upload vulnerability. |
| 1:02.6 | Second one would execute the content of the file and the third one would retrieve the response |
| 1:08.9 | from the command. |
| 1:10.5 | Now shortly thereafter, trusted SEC did publish their version of the exploit, quite a bit more |
| 1:17.2 | professional and nicer done. |
| 1:20.2 | It actually runs sort of Python code on the Citrix system and then establishes a reverse |
| 1:27.4 | shell. |
| 1:28.3 | And since then we have literally dozens of different exploits that people published, but pretty much all of them are sort of variations of these two themes. |
| 1:37.3 | And of course, shortly after these exploits were published, the requests against our Honeypots sort of went through the roof. |
| 1:47.0 | And we have sort of identified a number of different payloads that people used using these exploits. |
| 1:54.0 | Most of the exploits sort of follow that Project Zero India scheme, but they just use simple curl commands but we also see some |
| 2:01.6 | that sort of use these more encoded Python scripts just like what trusted sec |
| 2:07.8 | did now the vast majority of these exploit attempts are essentially just checking |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

