ISC StormCast for Monday, January 30th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 January 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 30th, 2017 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.5 | It looks like there is yet another attack vector for internet-connected DVRs and cameras. |
| 0:18.6 | Last week we observed an increase in scans for port 5358. This port appears to be associated with |
| 0:28.6 | the web service on devices API, something used by some of the same devices that we have seen |
| 0:36.4 | being attacked by Mirai and similar bots in the past. |
| 0:41.8 | If anybody has some packets with payloads, then please send them in. |
| 0:46.5 | I tried a little Netcat listener, didn't really get anything with that, |
| 0:52.1 | so it may expect a certain response, still trying to simulate that a little bit |
| 0:57.7 | better. And if you are running open as H, an older vulnerability originally fixed in 2015 has sort of |
| 1:06.6 | come back with a new exploit. CVE 2015-65-65 was originally reported as a denial of service |
| 1:16.7 | and a possible privilege escalation vulnerability. The possible privilege escalation |
| 1:22.5 | vulnerability is now confirmed with the release of a rather straightforward exploit. |
| 1:28.3 | This is yet another case where a file, in this case, the TTI terminal, |
| 1:34.3 | is writable by other users and then code is executed by root. |
| 1:41.3 | The vulnerability only effects OpenSH 6.8 and 6.9 and as I said, has been |
| 1:48.0 | patched a while ago. Let me have a couple cases where ransomware is sort of cutting over |
| 1:53.9 | into the Internet of Things realm. Now, the first one isn't classic Internet of Things. It did |
| 1:59.9 | affect traffic cameras and apparently mid-January. |
| 2:03.6 | Just a week before the inauguration, Washington DC had to shut down a large percentage of |
| 2:10.5 | its traffic cameras because PCs that you were used to control these cameras were infected |
| 2:16.7 | by ransomware. So in this case it was |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

