meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 17th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 17 June 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. June Forensic Quiz; ThroughTek IP Camera Vuln; Peleton Vuln; MSFT Defender Detecting Jailbreak

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 17th, 2021 edition of the Sansand-Stormsanders Stormcast. My name is Johannes

0:08.8

Ulrich. And today I'm recording from Jacksonville, Florida, and again virtually teaching in Paris, France.

0:17.1

And today we got another forensic quiz from Brad. Just like in prior months, there is a packet capture that you need to analyze.

0:26.2

Beyrshark being sort of the preferred tool here in order to participate.

0:31.2

But of course, you're free to use other tools if you would like to.

0:35.6

There are a number of questions that you need to answer. Submit your

0:38.9

answer, please, via our contact form, and we'll give away a Raspberry Pi again. Last month,

0:46.3

we had a little bit sort of a mad dash for people trying to be the first to submit, because we

0:50.9

sort of stated that the first correct submission will be the winner.

0:55.9

This time we sort of do a little pseudo-random drawing among the correct submissions,

1:02.3

so you don't necessarily have to be the first one.

1:07.3

And then we have yet another vulnerability in IP-based surveillance cameras.

1:13.4

The tricky part here is that the vulnerability is in a software development kit to implement

1:19.8

a P2P protocol in order to access the video stream from these cameras.

1:25.9

The vendor of the software development kit is through tech. However,

1:31.2

you are unlikely going to sort of see this labeled on the camera. This particular software

1:37.4

development kit is used by numerous different vendors. The vulnerability overall, well, I don't actually personally consider it that super critical,

1:48.0

even though it has a CVSS score of 9.1.

1:52.0

Essentially, the problem here is that video feeds are not encrypted.

1:57.0

They're just obfuscated.

1:59.0

So an attacker would be able to possibly view the video feeds if they can intercept the traffic.

2:07.9

There is a possibility to add TLS to these video feeds, and that's essentially the mitigation

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.