meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 21st 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 21 January 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Drupal Patch; WPML Hack; Google Drive for C&C; Packet Challenge Solution

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, January 21st, 2019 edition of the Sands and at Storm Center's

0:06.3

Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:14.0

Still running a website using Truple? Well, it's time to patch again. This latest update addresses two different

0:23.2

vulnerabilities. Now, the first off, these vulnerabilities really fixes a bug in the external

0:29.1

tar library. This vulnerability could be exploited to override files on the system, and in

0:35.5

some cases, based on the files the attacker can

0:39.1

override it could lead to arbitrary code execution.

0:43.0

Now TAR of course is a tool that packs various files into an archive when they're untarred

0:50.4

as it's often called then of course there is a risk that file names inside the

0:55.5

TAR archive are being used to override files on the system and probably we're talking

1:02.0

about a similar issue here where you can somehow bypass some of the file name validation

1:09.0

being done.

1:10.0

Now the second issue deals with PHP stream wrappers, and that has been an issue that has led

1:17.1

to a lot of problems in the past.

1:19.5

In PHP, not all URLs already created equal.

1:24.1

There are some special URLs, these stream wrappers, and in that case, the URL itself is actually

1:30.7

then, for example, treated as a file or as code, and that can lead to problems.

1:36.4

So in this particular case, if the URL starts with PHAR or FAR, that means that the remainder of the URL is really a PHP code archive and that

1:49.1

could be executed. Now the problem of course is that as a software like in this case

1:55.5

triple accept URLs from users they have to make sure it's not one of these special

2:00.7

stream URLs and so far

2:03.3

PHP has not considered far stream wrappers as dangerous which led to this arbitrary code

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.