meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, July 29th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 July 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Port 34567 Uptick; LibreOffice Macro Code Exec; Extracting Private Keys from Amazon Music

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 29th, 2019 edition of the Sandstone Storm Center's Stormcast.

0:08.5

My name is Johannes Ulrich.

0:10.1

And today I'm recording from Boston, Massachusetts.

0:14.3

On Friday, Kevin observed a significant uptick in scans for port 34567.

0:22.4

That's 34,567.

0:27.4

This port appears to be associated with network cameras,

0:31.6

and I look at a couple of the IPs that are scanning for this port.

0:37.0

It looks like they're also scanning

0:40.0

port 9527, 9,527, which is another IP webcam associated port. The second one actually has a

0:50.5

specific vulnerability associated with it, C 2017 11633 that vulnerability it's an

0:59.6

information leakage vulnerability and apparently it can be used to retrieve usernames and passwords

1:05.9

so in general this looks like sort of yet another variant of some botnet I'm going to call it Mirai because we don't have any code yet, but there are so many of these

1:16.5

Mirai notar variants going around looking for vulnerable cameras.

1:22.7

In this case, they appear to be looking for what I call secondary vulnerabilities, not the big ones like usernames and passwords and such, but maybe vulnerabilities that other bots missed.

1:35.8

Given how hard these cameras have been hit, there are probably only very few cameras left with default passwords, if any, that have not already been infected.

1:50.0

And if you are using Libra Office, the free and open source office suite, be aware with documents

1:59.0

and macros. Now, for Microsoft Office users, macros have long been recognized as evil, and users are by default as for permission before any macro is executed.

2:12.2

Now, Leaper Office, macros are a little bit different in a sense that they can be pre-installed with Leaper Office.

2:20.6

You can add your own macros to Leaper Office and then documents can use them.

2:27.1

But there are issues with some macros allowing arbitrary code execution, if not intentionally.

2:36.0

So, well, by mistake.

2:38.0

So for example, by default, Leipro Office ships with a simple macro,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.