meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, June 5th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 June 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MoveIT Transfer Exploited; Atomic Wallet Theft; Magecart Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, June 5th, 2023 edition of the Science and at Storm Thunder's Stormcast.

0:08.1

My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:13.6

I want to start out with a vulnerability that I already covered on Friday but has been really a big issue this weekend, so I do want to cover it again.

0:23.7

It's a vulnerability in Move It Transfer.

0:28.5

Move It Transfer is software that's used to transfer files, often used in larger organizations.

0:34.2

It does support a number of different protocols. HDP, HDPS is affected here.

0:41.9

The root cause is a SQL injection vulnerability, but a SQL injection vulnerability that does

0:48.3

allow arbitrary code execution. Typically, an ad hacker will use it to upload a web shell. Once they have

0:56.0

a web shell, of course, then this sky is the limit, and they'll do whatever they need to do,

1:01.2

to for example, exfiltrate additional files, or maybe upload and run additional code.

1:09.1

Initially, the vulnerability was made public by progress,

1:13.1

the company behind Moved Transfer on May 31st.

1:18.2

There are patches available, at least for the more recent versions of Moved Transfer.

1:25.1

However, the exploit has also been pretty much released as soon as the patch was released

1:33.5

so now you have bots basically scanning the internet and exploiting exposed instances if you do have an

1:42.3

exposed instant of move it, assume it has been compromised,

1:48.0

even if you have applied the patch as early as Friday, just because by that time already

1:55.0

we saw a ton of the exploits going around and looking for exposed systems.

2:02.5

The CVE ID of the vulnerability is 2023-34-362.

2:09.8

And if for whatever reason you're not able to patch,

2:13.4

well, then you pretty much are left with disabling HTTP,

2:25.7

which I don't think is really that much of a real solution for this particular problem.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.