ISC StormCast for Thursday, February 3rd, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 February 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, February 3, 2022 edition of the Sandton and Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:13.1 | ELFinder is a real neat tool that allows you to get essentially a GU-like experience in the web browser in order to manage files on your |
| 0:23.8 | web server. |
| 0:25.1 | So you're able to upload, download files. |
| 0:27.8 | The overall user interface is a little bit like the Finder in a Mac OS, which gave it |
| 0:34.4 | its name, Yel Finder. |
| 0:36.4 | There are two parts to the tool, a front end written in JavaScript and a back end written in |
| 0:43.3 | PHP, and that back end well has had some issues as recent as July last year. |
| 0:51.3 | There were two remote code execution vulnerabilities discovered in the tool. In particular, |
| 0:57.5 | the problem here appears to be sort of unrestricted file uploads where an attacker may be able |
| 1:03.6 | to upload a file and then execute code. But even just the ability to upload files without actually executing any code can be quite useful to an attacker. |
| 1:15.6 | And these last couple of weeks we have seen a marked increase in scans for EL Finder against our honeypots. |
| 1:24.4 | The tool comes as a standalone tool, but also as a plug-in to systems like |
| 1:29.5 | WordPress and you may not necessarily be aware that you're using ELFinder in those cases. |
| 1:35.4 | So do yourself a favor and scan your web server for some of the URLs the attackers are looking |
| 1:40.7 | for and double check that if you are using EL Finder, that it's |
| 1:45.0 | properly up to date and that it's also properly password protected. These kind of tools are |
| 1:51.0 | often used by fissures to then upload phishing pages to websites and basically use your system to also in some cases collect the data that the |
| 2:05.0 | phishing pages provide. And if you're using IBM's Spectrum Protect Plus product for backups, |
| 2:12.5 | in particular popular, of course, for containers, well, be aware there is a critical update available. |
| 2:19.0 | This critical update fixes problems with data tables, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

