meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 25th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 25 April 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. NVD API Updates; Cisco Patches and Backdoor; Keyboard App Vulns; node-mysql2 vulns;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, April 25, 2020, 24 edition of the Sanchez and its Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:13.8

Three years ago, Rob published some scripts to make it easier to read the NVD database, in particular on Windows systems.

0:23.4

Well, Rob updated these scripts now in order to adapt them to the newer version of the API

0:31.3

that is being offered by NIST.

0:33.9

If you're interested, the more details, you can find them in Rob's diary from the day.

0:41.5

And Cisco released a blog post together with patches for three different vulnerabilities

0:48.2

in response to some attacks that they have observed taking advantage of these vulnerabilities.

0:56.2

Effected are Cisco is A and firepower devices, and the vulnerabilities being addressed

1:03.7

here are really more the privilege escalation part.

1:06.9

The initial attack vector, how the attacker originally got access as an authenticated user,

1:13.9

is not included here and they say they don't really know. So one assumption is that likely

1:19.4

that initial attack vector was just some weak username and password combination that was

1:25.9

brute forced or found somewhere else.

1:29.3

Cisco believes that the attacker started working on this back in July and in January

1:34.6

started actually launching the first attacks using this particular pattern and set of vulnerabilities.

1:42.8

Out of the three vulnerabilities, there are two particular interesting.

1:47.0

One is a local code execution vulnerability, the other one a command injection vulnerability.

1:53.0

Between the two, I think there is at least one sort of directory traversal vulnerability.

1:59.0

For example, one of these vulnerabilities allows an attacker who is able to

2:03.1

restore a backup to override files that they're not supposed to override. That's very common

2:10.7

when you're extracting SIP files and the like and not properly validating the paths. The files

2:17.4

are being written into,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.