meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 20th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 June 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. WebLogic Critical Patch; Exim Exploits against Other Mail servers

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 20th, 2019 edition of the Sansonet Storms and Stormcast.

0:07.4

My name is Johannes Ulrich, and the time I'm recording from Washington, D.C.

0:13.9

Oracle today released a special out-of-band security bulletin regarding a new vulnerability in WebLogic.

0:23.6

Just like prior vulnerabilities in WebLogic, this is an XML decoder, deserilization vulnerability

0:31.6

again and can to lead to arbitrary code execution. It actually appears to be yet another version of this vulnerability.

0:40.3

We have seen quite a number of them in WebLogic already so far.

0:45.3

They tend to be pretty easy to exploit and this particular issue was apparently already exploited in the wild. Orgel has released patches for most

0:58.5

versions of Weblogic. Apparently 12.2.1.3 is still waiting for a patch, but by the time

1:08.7

you're listening to this, the patch may already be available.

1:12.6

As far as the overall risk goes, Shodon actually only sees about 2,000 to 3,000 different exposed

1:21.6

WebLogic servers. At this point, I would think that most serious users of WebLogic have gotten the message

1:29.5

that it's not a good idea to expose these systems directly to the internet.

1:35.1

The ones that are exposed, I would guess, are probably already exploited because we do

1:41.0

see a large number of exploit attempts against our honeypots.

1:46.0

Whether or not these exploit attempts are this latest vulnerability or one of the prior ones is difficult to tell.

1:53.0

The endpoints are the same. They're being attacked here and the vulnerabilities are similar enough

2:00.0

where it can be difficult to

2:01.4

distinguish the different exploit attempts. I've got an interesting log snippet

2:08.4

from a reader's mail server. Now this mail server isn't running XM but still

2:15.1

was attacked using the recent XM vulnerability.

2:19.3

This is the vulnerability that's also known as Return of the Wizard

2:23.3

that has been known for about two weeks now and has pretty much been exploited as soon as the vulnerability became known.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.