meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 6th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 6 April 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. jq and cowrie; NEXX Vulnerability; OneNote Changes

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, April 6, 2020,

0:03.6

edition of the Sandsenet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

These days, JSON is everywhere, and with that, it's really kind of important that you learn to use the tool,

0:24.2

JQ, the ubiquitous jason parser for the command line today we do have a nice diary by jesse who goes over how to use

0:31.9

jq in order to parse cowrie data cow of course, is part of our honeypot,

0:38.0

so that's sort of the motivation for him to look at Cowry logs closer.

0:42.9

They are stored in JSON, at least that's one of the log format options you have.

0:47.8

So he goes over how to summarize your logs quickly with JQ.

0:54.1

And if you have an interesting vulnerability in garage door openers as well as other devices

0:59.6

made by Next, that's N-E-XX.

1:03.3

The trick with these garage door openers is that they connect to Wi-Fi.

1:08.8

So it's not one of those simple garage door openers where you

1:12.5

have to be in a certain vicinity and use one of those rotating a code kind of transmitters.

1:18.5

Instead, you may be able to open your garage door from anywhere in the world.

1:24.6

In order to facilitate this, there is an MQTT server. MQ is a message

1:30.0

queue. It's often used for IOT devices like this. A garage door controller here could,

1:35.9

for example, send status requests or updates to MQ. The trick here with Nix is that all devices use the same password in order to connect

1:48.8

to this MQTT controller. So the end effect is that once you know what that username and password

1:56.7

is, and that is sent to every single device with next and it's also present in the firmware

2:03.2

you'll be able to update any other garage door that uses the same controller and it's even not

2:11.6

that hard to search for it because everybody uses that same account messages to garage doors worldwide are all broadcast to every single garage door,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.