meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 4th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 4 August 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. l9explore User Agent; Arris Vulnerability; Malicious Fork Flood; Paloalto Master key; Laravel; Cisco and DrayTek Vulns;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, August 4, 2020 edition of the Sands and at Storm Center's

0:08.0

Stormcast.

0:09.0

My name is Johannes Ulrich, and today I am recording from Jacksonville, Florida.

0:14.0

Today I noticed a small group of IP addresses scanning the same set of a bit unusual odd vulnerabilities.

0:22.8

The vulnerabilities are odd because they're not your normal, simple remote code execution

0:27.2

vulnerabilities that we often see by botnets, but they're really more looking sort of for

0:32.9

information leakage issues like exposed environment variables and configuration files.

0:39.1

Well, turns out the scans all use the L9 Explorer user action, so I dug a little bit into

0:45.8

that.

0:46.5

And turns out it's related to the Leakex platform LeakeX, according to the site is sort of a

0:53.2

buck bounty helper tool to help identify,

0:56.1

notify sites leaking data. You may, of course, just block the user agent. We also offer

1:02.2

a feed-off leakix associate IP addresses, but then again, why not just use that list of

1:08.3

URLs they're scanning for and double check that you are not exposing

1:13.3

any data via these URLs. And researcher Derek Abdein uncovered a critical and simple to exploit

1:23.6

directory traversal vulnerability in ERIS DSL and fiber routers.

1:29.6

ERIS is one of the larger manufacturer of these devices.

1:34.0

They also make cable modems, and it's not clear if they are affected as well.

1:39.2

The root cause here is really the MyHTPD demon.

1:43.7

That's the web server that's installed on these devices.

1:47.0

You may also find ARIs devices being used by various ISPs and sort of preinstalled by them

1:54.0

if you rented your modem or router from your ISP, and they're sometimes then also

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.