ISC StormCast for Thursday, February 29th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 February 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, February 29th, 2004 edition of the Sandtonet Storms, Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.2 | Today I looked at some of our Honeypot logs and noted a sudden increase in requests for the URL forgot user password. |
| 0:25.3 | Dot action. |
| 0:26.6 | This URL appears to be related to the Atlassian Confluence product. |
| 0:33.6 | At first, I thought, hey, maybe this is just someone trying to sort of exploit, badly implemented, forgot password feature. |
| 0:43.2 | But there seems to be more to it. |
| 0:45.7 | The URLs, the parameters being passed to it, look a little bit more like some kind of template injection or dieselization vulnerability. If anybody has any idea what the |
| 0:58.0 | exact CVE number that may be exploited here is, let me know. At this point, |
| 1:05.3 | will it appears to be just scanning for instances, not necessarily exploiting or launching a specific exploit, but we'll have to look |
| 1:14.6 | at it a little bit further to really see what's going on here. So any hints about any recently |
| 1:21.7 | patched vulnerabilities or so in forgot user password.com. Action are quite helpful. |
| 1:28.0 | And if you're running Confluence, |
| 1:30.5 | well, double check your logs |
| 1:32.1 | and see if it was abused using this particular URL. |
| 1:39.8 | And you probably noticed about a few high profile compromise |
| 1:43.6 | of healthcare businesses lately. |
| 1:46.3 | Now, we always had attacks against hospitals that has been sort of going on for a couple years now. |
| 1:53.1 | The latest bigot hack, and I may have mentioned it before in a podcast against change health care or optum, |
| 2:04.1 | did affect billing for a large number of pharmacies. |
| 2:05.7 | Well, the FBI now is paying attention to the news too, and SISA and the couple other agencies |
| 2:12.1 | have released a bulletin with some of the indicators of compromise and general techniques being used in |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

