ISC StormCast for Thursday, January 27th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 January 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, January 27, 22 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. I'm recording from Jacksonville, Florida. |
| 0:13.8 | There are a couple of things you just shouldn't expose on the internet. This may be, for example, your networked storage devices like your QNAPs, |
| 0:22.1 | analogy, and the like your homemade Wordpress websites, and of course any kind of system |
| 0:29.5 | that is used to manage your server, like for example the HP integrated lights out management |
| 0:37.1 | interface or ILO, which is very similar |
| 0:40.4 | to Dell's DRAC system. |
| 0:44.1 | And of course, that's another thing that you shouldn't expose. |
| 0:47.2 | So Jan took a look at how many of these systems are actually exposed and using a couple |
| 0:52.8 | different techniques, like, for example, searching on |
| 0:55.7 | Google as well as on Shodan. He found about 20,000 servers exposed to the internet. This is rather |
| 1:05.0 | unfortunate because these are servers that are usually sold to more professional environments. |
| 1:10.6 | These are not home user systems. |
| 1:13.7 | And over the years, they have been a number of critical vulnerabilities |
| 1:17.3 | that essentially allow the complete takeover of these servers without any credentials. |
| 1:24.4 | So please, please double check that any system like this, and like I said, it's not |
| 1:28.8 | just restricted to HP's implementation, Dell and others, any kind of IPMI interface and |
| 1:35.6 | such, should be in the same category, should never be exposed to the public internet. And yes, this isn't |
| 1:42.8 | new. And actually, someone on Twitter asked whether or not this changed due to the pandemic. |
| 1:47.6 | And Jan did sort of a quick historic search and didn't really find a significant change in the number of exposed devices pre versus post pandemic. |
| 1:59.3 | And Apple today did its usual, well, patch everything a day. |
| 2:04.0 | WatchOS is now 8.4 iOS and iPadOS is 15.3. |
| 2:10.3 | Same for TVOS. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

