ISC StormCast for Monday, January 4th 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 January 2021
⏱️ 4 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 4, 2021 edition of the Sandcent Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich. |
| 0:09.5 | And today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Well, to start the year, we have a couple of cleanup items here from last year. |
| 0:19.8 | First of all, Brad published an end-of-year traffic |
| 0:23.7 | analysis quiz. So if you are in the pack analysis, if you like your wire shark, then take |
| 0:30.0 | a look at the traffic he has and, of course, he'll at some point and also publish a solution. |
| 0:38.0 | And on December 23rd, which is probably why I missed it, |
| 0:41.1 | Niels Tusing from Dutch security company I Control, |
| 0:46.2 | did publish an advisory about a backdoor in various products made by Sykesel. |
| 0:53.5 | Now, Sykesel is pretty famous for sort of DSL modems and such, but they also make VPNs |
| 1:01.0 | and their Seiwall. |
| 1:03.2 | That's also a quite common. |
| 1:05.4 | USG Flex is another product that is affected by this. |
| 1:09.6 | And essentially, it's your good old username and |
| 1:12.8 | password that's hard-coded in the firmware and cannot be updated by the user. |
| 1:19.2 | This can be exploited via SSH and via the web interface also as VPN credentials which tends |
| 1:26.6 | to listen on port 443 on these devices. |
| 1:31.2 | A firmware update has been released by Sychcel, but doesn't look like it's available yet |
| 1:38.8 | for all devices. Now, I'm not terribly familiar with Syccell, but they're saying for their |
| 1:43.9 | AP controllers, the patch will be coming in April. |
| 1:48.8 | Now, sadly, one publication that reported about this issue did also publish the full password. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

