meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 3rd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 3 January 2022

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Exchange Server Y2k+22; Agent Tesla Updates; SSD Firmware Tampering; iLO Bleed;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, January 3, 2020 edition of the Sansonet Storm Center's Stormcast.

0:08.6

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.0

Well, it wouldn't be a new year without some problems related to the change of the year.

0:19.1

This time, it's a Microsoft Exchange Server, 2016 and 2019,

0:25.0

I guess, with all the problems we had with Exchange Server last year. It decided to sort of go

0:30.9

out with a bang of some sorts. Well, it wasn't really a security issue, more availability.

0:37.0

And really interesting and odd bug here.

0:41.3

Apparently, Exchange Server internally represents dates as signed integers.

0:47.3

But this integer isn't like a Unix timestamp or so, like a number of seconds from a certain

0:52.3

date.

0:53.3

Instead, it assembles that integer from the actual date.

0:57.5

And the first two digits of the integer are the last two digits of the year. So this changed

1:04.3

from 21 to 22 with the new year. The problem being here is because this is a signed 32-bit integer,

1:14.3

the largest number that came by represented is $2.1 billion,

1:18.8

and with the year 2022, we are now at $2.2 billion,

1:24.6

which then, of course, cost the problem.

1:27.2

If you're affected, email will be stuck

1:30.2

in the transport queues and you'll see event ID 5300 and 1,106. There is a patch available for

1:40.8

Microsoft that you need to apply in order to solve this problem.

1:45.9

And well, even with the new year, some things stay the same, and one is Agent Tesla.

1:51.1

Agent Tesla has been around for a few years and keeps adjusting Brad, sort of keeps track of

1:57.3

that, and wrote a diary with the latest observation as far as ancient Tesla goes.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.