ISC StormCast for Monday, May 6th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 May 2019
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, May 6th, 2019 edition of the Sands and the Storms, Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and I'm quoting from Jacksonville, Florida. |
| 0:12.7 | On Friday, a large number of reports surfaced stating that Git repositories were deleted and replaced with a ransom node. |
| 0:23.5 | And this did not just affect GitHub, which some news outlets reported, but it did affect |
| 0:30.2 | various Git platforms. |
| 0:32.7 | Also, BitBucket apparently was also affected by this particular ransom node. Now, first of all, if you are |
| 0:40.9 | affected by this particular ransom note, if you are seeing this note in your Git repository |
| 0:47.1 | that all your content is gun, it looks like very likely your content is actually still there |
| 0:53.6 | and available and you should be able to recover it. |
| 0:57.0 | The link to the register article that I'll post with the show notes has some hints on how to get your data back. |
| 1:05.0 | Of course, if you do have a local checked out copy of the content, then definitely you should be in pretty good shape. |
| 1:13.4 | The real question at this point is, how did it happen? And the most likely explanation I've |
| 1:19.1 | seen so far is that some of these repositories had websites that expose the dot-git directory. Make absolutely sure that dot-git is not |
| 1:31.9 | exposed on any of your websites. It has sometimes contained credentials for your Git repository |
| 1:39.0 | and definitely will include the URL of it so an attacker could use this in order to launch attacks against |
| 1:46.4 | your Git repository. So while this attack is scary right now, it's actually not the worst |
| 1:52.1 | thing that could have happened and probably a good sort of warning shot that you probably |
| 1:57.8 | should protect your Git repository better. |
| 2:01.6 | In February, I talked about how the crypto ransomware did attack various network accessible |
| 2:08.6 | storage devices made by D-Link. |
| 2:11.6 | Now, D-Link back in February did release some updates for the DNS 320 and 327 devices, but only last week released |
| 2:22.7 | an update for the DNS 325, which is also affected by this particular vulnerability. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

