meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, July 9th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 9 July 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Obfuscated Malware; PAN-OS Vulnerability; Citrix Vuln Details; Mozilla Suspends Send

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, July 9th, 2020 edition of the Sandcent Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.3

In Diaries today, we got a nice walkthrough by Xavier showing how he de-obuscated a Windows script that he recently came across.

0:24.7

This script essentially carries the second stage along with it as a large array that's then

0:33.5

being decoded via character substitution and, well, good old basics,

0:39.5

for encoding in part.

0:42.6

But well, imagine that,

0:44.2

perimeter device securities are still coming out.

0:49.1

And today it's Palo Alto Network's turn

0:53.4

with an update for PanOS.

0:55.9

Now, this is a little bit an interesting issue here.

0:59.8

Palo Alto rates this as a CVSS score of 8.1,

1:05.3

but again, it is an unauthenticated network-based attack

1:10.1

that can execute arbitrary operating system commands

1:13.7

with root privileges, which I think really sort of puts it more in the 9 to 10 range

1:21.1

as far as vulnerabilities go.

1:23.8

They state that the attacker would require some level of specific information about the configuration of an impacted firewall.

1:32.3

My guess, and I'm totally guessing here, is maybe IP addresses, and the attacker would be able to prude force these parameters.

1:42.6

Now, to be vulnerable, you need to have the Global Protect Portal feature

1:47.6

enabled. Another little twist to this vulnerability. While this is a new distinct vulnerability

1:54.0

CVE 2020-2034, the advisory states that if you applied the patch for CVE 2020, 2021, then you're also protected

2:08.6

for this issue. I'm not aware of any additional details or exploits for this vulnerability,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.