ISC StormCast for Thursday, February 20th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 February 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, February 20th, 2020 edition of the Sandcent, Center Storm Center's Stormcast. |
| 0:07.1 | My name is Johannes Ulrich. |
| 0:08.9 | And then I'm recording from Jacksonville, Florida. |
| 0:13.2 | One of the trends over the last year has been vulnerabilities in security device. |
| 0:18.9 | And we have yet an additional example of this. This time it's Sonic |
| 0:23.8 | Walls, Secure Remote Access, SRA, and also the SMA devices. Ellen Moat found this and he sort |
| 0:32.4 | of followed the pattern that Orange Zai originally implemented with Palo Alto, Ftnet and Pulse Secure, |
| 0:40.3 | he downloaded the virtual machine implementation of the Sonic Wall, Firewall, and then essentially |
| 0:46.5 | inspected the code. |
| 0:48.6 | Now he found a number of serious vulnerabilities, for example,, SQL injection vulnerability does not require |
| 0:56.6 | authentication and allows access to arbitrary data. That one is rather easy to implement, but there |
| 1:04.6 | are also some arbitrary code execution vulnerabilities, like for example, buffer overflow in lipciss.s.o and a third unauthenticated |
| 1:15.8 | vulnerability that allows directory traversed. In addition, he found three other vulnerabilities that do |
| 1:22.5 | require some form of authentication. Sonic Wall did patch these vulnerabilities in mid-December, but Alan, nice of him to wait |
| 1:33.3 | until now to actually publish the blog post with quite a bit of detail about how to exploit |
| 1:39.4 | these vulnerabilities. |
| 1:41.1 | So better make sure you are patched. |
| 1:45.0 | And talking about patches you should have applied by now. |
| 1:49.0 | Well, the Microsoft February patched Tuesday is just about a week old, and we do have an |
| 1:55.0 | exploit now for a remote code execution in SQL server reporting services. |
| 2:04.4 | This was CVE 2020-0618. |
| 2:11.5 | MDSEC originally found this vulnerability, and they now published a blog post, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

