ISC StormCast for Monday, October 17th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 October 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, October 17th, 2020 edition of the Sandsenet Storm Center's |
| 0:07.8 | Stormcast. My name is Johannes Ulrich, and today I'm back in Jacksonville, Florida. |
| 0:15.1 | First of all, an apology that on Thursday due to time zone issues, I recorded a Friday podcast |
| 0:20.5 | actually quite early. Turns out, |
| 0:23.0 | well, it was too early as we had an important update to the 40 OS 40 proxy vulnerability just after I |
| 0:32.2 | recorded. As announced earlier in the week, Horizon 3 AI released then later on Thursday, |
| 0:40.5 | a technical deep dive and proof-of-concept exploit. |
| 0:44.8 | Well, soon after that, we did actually see exploit attempts hitting our honeypots |
| 0:50.8 | that matched what Horizon 3 published. |
| 1:01.0 | As usual, at this point, you should consider vulnerable devices that are exposed already exploited, do not just patch, but investigate devices if there is any evidence of compromise. |
| 1:08.0 | The root cause of the vulnerability is, yet again, we had this with F5, |
| 1:13.6 | we had this with VMware, where web servers and web applications just trust headers that |
| 1:19.0 | proxies are supposed to set. And yet again, these headers are controlled by the attacker, |
| 1:25.6 | and with that authentication and access control is bypassed. |
| 1:31.5 | So it's part of normal operation. A proxy receives the request, then pass it on to the application, |
| 1:36.7 | but the application implicitly trusts any request with a client IP of 1-27-001 and a user agent of report runner, which is easily set by |
| 1:49.6 | the attacker. |
| 1:50.6 | And that user agent report run is exactly what we're seeing in some of the exploit requests |
| 1:57.7 | against our honeypots, the blog points out again the similarity to what we saw with F5 and VMB. |
| 2:05.6 | The end result is that this vulnerability is an authentication bypass for the rest API, so the attacker can do whatever the rest API allows them to do. |
| 2:18.1 | One of the features that's exposed here is the ability to add an ZH key to the authorized keys file on the system. |
| 2:26.4 | And that's exactly what the proof of concept exploit that Horizon 3 published does. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

