meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, September 9th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 9 September 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Mirai Updates; Bluekeep in Metasploit; Gmail Spam Response; Exim TLS SNI Exploit

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, September 9th, 2019 edition of the Sands and the Stormsendors

0:06.2

Stormcast. My name is Johannes Ulrich.

0:09.2

I'm recording from Sevalde, Germany.

0:14.2

Last week, Guy observed a new kind of scan in his honeypots that appears to originate from the Mirite botnets or some of its successors

0:25.6

and well again targeting DVRs but this time it looks like it's more going sort of for

0:31.6

web application vulnerabilities. In particular it's looking for the Mount Custom Product Definition File, not

0:40.4

absent what it's kind of looking for, but if you have any more details, please let us know.

0:47.9

There are a couple of sort of tweets about some activity from Craynois and others. But well, what I reported

0:58.3

before, Mirai sort of keeps on changing, keeps on expanding the overall arsenal of vulnerabilities

1:06.6

it's scanning for. And yes, what we all were waiting for somewhat has happened and we now have

1:15.2

a bluekeep exploit module in Metasploid. Of course, this did very much lower the threshold

1:23.7

of attackers targeting your systems with this exploit.

1:28.3

You had plenty of times now to apply patches and for sure that exploits have been developed

1:36.3

and have been available in commercial products for quite a while now.

1:41.3

Now this exploit isn't quite as straightforward as some other

1:45.6

mid-asploid modules by default. It will just tell you if a system is vulnerable or

1:50.8

not. You have to apply additional configurations based on the operating

1:57.0

system you are targeting. It currently works with the 64-bit versions of Windows 7 and

2:04.6

Windows 2008 R2, according to a blog post released by Rapid 7. Now, one word of caution, if you're

2:14.2

using this exploit module in internal penetration tests, there is a good chance

2:20.3

that you will actually trigger a blue screen if you are not running this module correctly,

2:27.3

or if your exploit is interrupted, for example, by network issues.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.