ISC StormCast for Monday, March 4th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 March 2024
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, March 4, 2020, edition of the Sansonet Storm Center's Stormcast. |
| 0:08.2 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:13.6 | I mention Confluence pretty regularly. |
| 0:18.0 | Well, it turns out that some of the older vulnerabilities are still being exploited. |
| 0:24.6 | Gee rode up an attack against one of our honeypots that tried to exploit CVE 2020-226-134. |
| 0:33.1 | So about a two-year-old vulnerability. A classic OGNL interaction. In this case, it's being used to |
| 0:39.9 | inject a little bash script that will then download additional malware. Personally, I doubt that |
| 0:47.2 | these attacks are actually all that terribly successful, given that the vulnerability is reasonably |
| 0:52.9 | old and it's heavily exploited. |
| 0:56.1 | So any confluence server that you may actually still find to be vulnerable probably already |
| 1:01.8 | has been exploited multiple times. |
| 1:05.8 | And in a blog post on attack ships on fire, we do have a problem that I have actually been struggling |
| 1:12.3 | with in the past with our In the Storm Center website. We used to use Google Analytics on |
| 1:19.5 | our website and we also do use content security policies. I found it back then terribly difficult to come up with a decent |
| 1:30.3 | common security policy while still using Google Analytics. Actually, more recently, |
| 1:37.3 | I removed Google Analytics in part for that reason. And this blog post now outlined some of the |
| 1:43.2 | pitfalls here where really you kind of have to implement a very open conscript policy in order to allow the Google Analytics script to work. |
| 1:55.5 | Similar issues are also run into with if you're using like the standard code to detect if someone is connecting from Europe |
| 2:02.4 | to sort of display them the annoying cookie banners, they also make it very difficult to then |
| 2:10.2 | still use a relatively useful con and security policy. In general, when it comes to con security |
| 2:17.1 | policies, I love them, I use |
| 2:18.9 | them, but I always tell people you have to understand they are hardly ever perfect. There is |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

