ISC StormCast for Monday, November 27th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 November 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, November 27, 2017 edition of the Santernet Storm Center's Stormcast. My name is Johannes Ulrich, and the I'm recording from Augusta, Georgia. |
| 0:12.0 | A critical patch has been released for the XM Mail Server, not the most popular mail server out there, but still quite popular with the Linux crowd. |
| 0:22.9 | And according to Shodan, there are a couple million of them still out there exposed to the |
| 0:28.5 | internet. And what of course makes this particularly dangerous is that mail servers kind of have |
| 0:35.1 | to be exposed to the internet. So there isn't really much you can do in terms of, well, a proxy, |
| 0:40.8 | basically putting another mail server in front of that vulnerable mail server. |
| 0:45.2 | That's kind of uncommon. |
| 0:47.3 | And as a result, this is certainly something where you have to pay attention. |
| 0:52.0 | Make sure you're not running XM. |
| 0:55.1 | And if you're running XM, and if you're running XIM patch as quickly as possible, a proof of concept exploit already has been released |
| 1:02.4 | over the weekend. And a little bit unusual for proof of concept exploit, but in this case, |
| 1:08.1 | it will actually open up a shell on the system. |
| 1:13.5 | And then we got a couple of cryptocurrency news that accumulated over the weekend. |
| 1:19.6 | First of all, Coin Pouch. |
| 1:21.9 | Coin Pouch is soft. |
| 1:23.2 | It allows you to store various cryptocurrencies in one place. |
| 1:28.3 | And apparently they recently added Verge, which is a relatively new, privacy-oriented cryptocurrency, to their portfolio. |
| 1:36.3 | Well, sadly, they made a mistake, the exact nature of the mistake or whether it was an attack is not really clear at this point and lost users |
| 1:46.7 | cryptocurrency. In this particular case about $650,000 of Verge tokens got lost. And you may have |
| 1:56.8 | noticed that this weekend cryptocurrencies really have gained quite a bit in value. Looks like it |
| 2:03.6 | may be sort of one of those hot gift items or so for the holidays. Well, to summarize some of |
| 2:11.1 | the attacks that you have seen over the last few years, I published a post with about nine |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

