ISC StormCast for Thursday, June 1st, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 June 2023
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, June 1st, 2023 edition of the Sands and Stormsenders Stormcast. |
| 0:09.6 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:16.0 | Last week I talked about how we saw some scans for Apache NIFI. |
| 0:21.8 | Apache NIFI is described as a data orchestration suite. |
| 0:27.4 | It's a pretty nifty software. |
| 0:29.3 | It provides web-based interface and allows you then to read data from, let's say, S3 buckets, |
| 0:36.5 | Kafka from other files and such, then process |
| 0:42.6 | the data, which typically means filter it or converting it to a different format, like from |
| 0:47.6 | JSON to XML or CSV and the like, and then save it back into, let's say, a database. |
| 0:54.6 | So this is a feature that's often used as part of sort of a data ops pipeline, |
| 0:59.1 | like if you have to manipulate business data, if you have to prepare data for machine learning. |
| 1:04.4 | That's of a typical use case for it. |
| 1:07.9 | But it's also being scanned for, and we talked about it last week that we saw some scans for it. |
| 1:13.3 | Well, we now set up actually a full NIFI install and exposed it to some of these scans |
| 1:21.5 | by configuring some of our honeypots to basically just proxy these requests. |
| 1:27.3 | So the attacker saw an actual NIFI instance. |
| 1:31.4 | What we saw were two kinds of attacks. First of all, crypto coin miners. There always has to be |
| 1:38.1 | a crypto coin miner. And the second attack, a little bit more nefarious in my opinion and that was lateral movement |
| 1:45.8 | where the ad hacker was collecting SSH keys from the system then figuring out what kind of |
| 1:52.6 | as H connections were implemented in the past are currently been implemented for example |
| 1:56.8 | looking at bash history looking at as H configuration files and then basically just trying out different keys and seeing what works. |
| 2:05.3 | This is not due to a vulnerability in NIFI. It's really just a bad configuration choice. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

