meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, July 22nd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 22 July 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. php malware; iNSYNC breached by Ransomware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 22nd, 2019 edition of the Sandcent Storm Center's Stormcast.

0:08.5

My name is Johannes Ulrich.

0:10.1

And today, I'm recording from Jacksonville, Florida.

0:14.4

This weekend, Xavier presented a new version of an old favorite, PHP malware.

0:21.7

With PHP being installed on many Linux systems and also some Windows systems and vulnerable

0:28.4

PHP sites, of course, being a common issue in exposed web servers.

0:35.4

PHP has never really gone away as a platform to create malware,

0:40.3

in particular to attack these types of servers.

0:44.3

But the malware found typically isn't as exciting as new malware families written in

0:50.3

PowerShell and JavaScript and well, maybe even Python.

0:55.7

Xavier found this example on Pastebin.

0:59.5

The example he found has a couple of interesting features.

1:04.6

It appears to be targeting WordPress sites.

1:08.5

So again, there is your PHP link and not only has a blacklist

1:14.2

of IP addresses, it won't attack because, for example, they appear to be owned by security

1:19.8

companies. That's something you see very often in malware, but it also checks Google's safe

1:26.8

browsing API to make sure it doesn't bother

1:30.7

to infect a site that is already blacklisted.

1:34.5

This is likely a very common problem for this type of malware because, but here these

1:40.1

word press scans, they're ubiquitous, it's by far the top sort of scan. I'm seen against

1:47.4

the web servers. So if someone comes across a vulnerable web server, well, there's a good chance

1:53.1

it already has been infected and as a result may already be blacklisted. And by the way, talking about web application vulnerabilities,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.