ISC StormCast for Monday, January 17th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 January 2022
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 17th, 2020 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.9 | And today I'm recording from Jacksonville, Florida. Friday got some little bit odd scans from researchers that apparently are looking for alternate data streams. |
| 0:20.4 | At least that's sort of |
| 0:21.1 | what the scans are looking like. The other thing they sort of share is that they're looking |
| 0:26.2 | for index.jsp. So what you would see is index.jSP, then colon, colon, dollar data, |
| 0:34.0 | which does match the format of the NT file system, alternate data streams. |
| 0:41.6 | Not sure if it will actually work. |
| 0:43.2 | I tried it against a quick window system I had set up here. |
| 0:47.6 | Didn't really work for me, but again, it did not actually run Java. |
| 0:53.4 | So not sure if that's only Java or if I didn't have to write file system. |
| 0:58.4 | If anybody has any insight into what they were looking for, let me know. |
| 1:03.4 | Also, later we got some feedback that other attackers are looking for similar patterns, |
| 1:09.8 | not just against index.jsp. |
| 1:13.2 | The intent here is likely according to some of the FAQs from OASP, for example, and their cheat sheets |
| 1:20.1 | to bypass filters that essentially are trying to reach a certain file like index.js.p, |
| 1:27.1 | but you're not trying to use that file name |
| 1:29.6 | by appending colon-colon-dollar data. |
| 1:32.5 | Functionally, the same thing as looking at index.js. |
| 1:36.0 | But a weblication file wall or some other filter like this |
| 1:39.7 | may get fooled into believing |
| 1:41.9 | that you're actually looking for a different page. |
| 1:46.1 | And after releasing its monthly updates last week, Microsoft, of course, experienced some problems |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

