ISC StormCast for Thursday, December 5th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 December 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, December 5th, 2019 edition of the Santernet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich. |
| 0:09.9 | And I'm recording from San Francisco, California. |
| 0:14.0 | Today, I got a couple of vulnerabilities to start out with that again relate to |
| 0:19.5 | web servers that are installed on |
| 0:23.0 | client systems and are listening to local host. |
| 0:27.3 | First one is part of the Adelaideon companion app in order to use this companion app and |
| 0:35.7 | allow users to edit confluence files in their own |
| 0:39.3 | preferred desktop application. |
| 0:42.0 | There is this |
| 0:43.1 | web server that Adelaideon |
| 0:45.1 | installs on the user's |
| 0:46.9 | desktop. Now, this |
| 0:49.2 | web server listens on loopback |
| 0:51.5 | and Adelaideatian |
| 0:52.9 | did set up a specific domain, Adelaician dash domain, dash, |
| 0:59.4 | 4, local host, dash, connections, dash only.com. That does usually resolve to local host, |
| 1:08.5 | and, well, the connection is done via HDPS. |
| 1:11.6 | Now I mentioned before that really doing HTTP on local host is first of all not really |
| 1:18.6 | necessarily and second by using HTTP at Leishin also provides a certificate and a private key and it's the same certificate and |
| 1:30.5 | private key for every single install of this application. So now an attacker could grab this |
| 1:39.3 | key pair and use it to impersonate this host name on the web. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

