meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 26th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 26 April 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. New Drupal RCE Vuln; Bash IRC Bot; Insecure Hotel Locks; Alexa Allowed Malicous Apps to Evesdrop

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, April 26th, 2018 edition of the Sansonet Storms and a Stormcast.

0:07.0

My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida.

0:13.0

Well, triple users be aware there is a new critical remote code execution vulnerability that you need to patch for and this time the vulnerability

0:23.7

has already been exploited by the time I record this. Now this new remote code execution vulnerability

0:32.5

is apparently a variation of the vulnerability that was patched in March, but apparently the patch didn't go far enough

0:40.2

and still allowed some versions of the attack to pass. Given that, it's no surprise that attackers

0:48.1

were able to weaponize this new vulnerability rather quickly. Exploid code has been published to paste bin. The exploit

0:57.2

against Drupal 7 published to pastebin does require that the attacker is logged in to the system.

1:05.0

So a little bit more tricky to exploit in this particular variant than the old one, but there is a possibility that other

1:13.5

exploits that do not require authentication may be released as well. If you have looked at

1:21.2

Linux malware, like the ones that may be installed by the triple vulnerability, you probably

1:26.8

came across a number of shell scripts.

1:30.2

What attackers often do is they use Unix utilities like WGet or curl to then download additional code.

1:38.6

But Xavier today wrote up a little shell script that a redirection submitted to us that uses neither.

1:46.3

It does establish a simple IRC bot using nothing but batch.

1:52.3

The trick that's being used here is that you can actually pipe data to dev TCP and

1:59.3

establish TCP connection that way and stream data both ways.

2:04.6

Now, of course, a lot of the low-level work has to be done in batch as well, but for something simple,

2:10.6

like for example, an IRC bot, this may actually work quite nicely.

2:16.6

And in particular, if you're thinking minimum

2:19.0

systems in and of things style systems, tricks like this may work on systems that don't have

2:24.9

a lot of these tools like W get and curl installed. And if you're like me traveling quite a bit,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.