ISC StormCast for Monday, October 18th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 October 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, October 18, 2021 edition of the Sands and its Storm Center's Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and then I'm recording from Riyadh, Saudi Arabia. |
| 0:14.1 | With several working exploits being released for the recent Apache Directory Traversal War on vulnerabilities. No surprise that, well, |
| 0:22.8 | they're actively being exploited. Gee posted a couple of detects from his honeypot that |
| 0:29.6 | are going after these vulnerabilities. Remember, they're two distinct directory traversal |
| 0:34.4 | vulnerabilities, one affecting Apache 2449, one for Apache 245, Apache 2451 is the current fully patched version of Apache. |
| 0:47.3 | If you are running anything older than 2449, don't panic, you're not vulnerable. |
| 0:53.3 | Well, at least you're not vulnerable to these directory traversal of vulnerabilities, and |
| 0:58.5 | attackers are certainly going for the remote code execution option here. |
| 1:03.7 | Not a lot of victims possibly out there given the short amount of time that these Apache |
| 1:10.0 | versions were available. Also, the remote code |
| 1:13.5 | execution does require enabling CGI bin. Interesting, they're not just going after Linux, |
| 1:20.8 | they're also going after Windows it looks like with the attempts to load PowerShell using |
| 1:27.4 | this vulnerability. Some of the attacks, of course, |
| 1:30.8 | are really just trying to figure out if you are vulnerable by, for example, retrieving Etsy |
| 1:36.3 | password. So in short, well, if you are vulnerable, probably too late at this point, you're |
| 1:41.8 | already exploited, but probability of you are actually running the vulnerable version of Apache is very, very low. |
| 1:51.5 | And Scott Fendley posted more of a policy kind of diary dealing with non-removable storage and warranty repairs. |
| 2:03.4 | In the old days, well, if you had to send in a device for warranty repair, you often were able to remove any tribes beforehand, |
| 2:10.3 | or you could pay a little bit extra for your warranty in order to be allowed to keep the |
| 2:15.4 | drive, so it's not actually has to be sent back in case |
| 2:19.6 | even the drive fails. This becomes less and less of an option in particular for portable |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

