meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 31st 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 August 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. ConnManDo Vulnerablity; Trickbot Goes After Coinbase; Pacemaker Patch; Inaudible Audio Commands

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, August 31st, 2017 edition of the Santernight Storm Center's

0:06.5

Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida.

0:13.0

Japanese security company NRI has released information regarding critical vulnerability in Conman.

0:21.7

Now, a Conman is short for Connection Manager,

0:24.8

and it is a network manager that you often find in small devices,

0:30.6

typically Internet of Things devices.

0:34.3

The vulnerable component is a DNS proxy and Conman 1.3 and earlier are vulnerable to a buffer overflow that can lead to remote code execution or of course to denial of service.

0:50.3

The one saving factor here is that in order to exploit the vulnerability, an attacker has to send DNS responses directly to the device, so responses aren't forwarded by recursive DNS servers.

1:07.2

But if an attacker can do that, they can take full control of the device.

1:12.1

And since it is actually a stack-based buffer overflow, it's not that hard to pull off.

1:18.6

So in particular, in a more targeted attack, if an attacker already has control over part of the network,

1:24.8

this may be sort of an interesting lateral movement into industrial

1:29.1

control devices.

1:31.2

Now a patch for this has been made public via Conman's Git repository, but of course you

1:36.9

may need to wait for your respective manufacturer to come up with updated firmware.

1:43.5

NRI has not released any proof of concept.

1:47.0

However, if you look at the patch, it's pretty straightforward to figure out where the problem actually lies.

1:55.0

And Trickbot, the latest banking malware, keeps evolving and as part of its bag of tricks it now added

2:04.0

the recording of credentials for Coinbase. Coinbase is a Bitcoin exchange that's quite

2:10.4

popular and we have seen this over the last few years in particular recently with the increase

2:16.0

in the price of Bitcoin, that Malware is going

2:19.5

more after Bitcoins directly. In addition to Coinbase, this latest version of Trickpot also goes

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.