meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, May 14th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 14 May 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Odd njRat Like Scans; Signal (Electron?) vulnerability; Electron Vulnerability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, May 14th, 2018 edition of the Sansanet Stormsendors Stormcast.

0:07.3

My name is Johannes Orich, and today I'm recording from Jackstville, Florida.

0:12.2

Friday, Ramco wrote about some traffic that he saw hitting his honeypots.

0:17.6

Now, the traffic looks very much like command control traffic from the

0:22.1

NJ RAT tool. Now typically you wouldn't really expect a honeypot to receive

0:28.3

traffic like this unless you happen to inherit the IP address of a command and

0:34.2

control server. What appears to be a little bit different here is that three IP addresses

0:40.5

in China are scanning the internet essentially using this type of traffic. Not sure if they're trying

0:47.1

to find command control servers or if they're looking for infected systems, probably more the former than the later.

0:56.5

Now, some strings in this traffic implicate North Korea.

1:00.5

However, that appears really just to throw off investigators, potentially.

1:05.5

It's kind of almost too obvious to be actual North Korean traffic.

1:11.5

The IP addresses are consecutive, so there are three different consecutive IP addresses

1:16.0

that are scanning for this.

1:18.6

Web servers running on these IP addresses, identifying them as part of the

1:23.7

Y-Team Network Security Team, that according again to that website focuses on

1:30.3

internet-wide network attacks.

1:33.2

And Argentinian security researcher Alfredo Ortega published a brief video on Twitter showing

1:40.3

a possible vulnerability in the popular messaging application signal.

1:46.0

Signal of course is in particular used as an encrypted and secure messaging application.

1:52.0

And so far, this could potentially be a pretty big deal.

1:56.0

What it shows looks very much like cross-site scripting.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.