meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 11th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 11 March 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SharpRDP; F5 Vulnerabilities; Netgear Updates; sigstore

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 11th, 2021 edition of the Sands and the Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.9

Well, what's an attacker going to do after they got initial access to your network and are now

0:20.3

trying to spread to different systems in the network.

0:25.0

Classic tools that are often used, of course, are PS remoting with PowerShell and PSXEC.

0:31.8

However, defenders have heavily invested into detecting these tools and attackers always are looking

0:40.6

for a new trick to bypass some of these detection strategies. One protocol that's available

0:49.4

to the attacker is RDP and RDP does not necessarily mean that you set up a full GUI session to the

0:57.5

remote system. The RDP protocol does allow for a lot more, like the simple execution of remote

1:05.6

commands. And a tool, Sharp RDPDP takes advantage of this ability.

1:12.6

Rob today wrote up a diary with a couple of quick examples,

1:17.1

how to take advantage of Sharp RDP,

1:20.1

and of course also some defensive strategies,

1:24.5

how to protect yourself from attacks leveraging this tool. And well, if you're

1:31.6

done patching all of your exchange servers, all of your Microsoft DNS servers, and well,

1:37.3

what else came up over the last couple days, there is something new for you to patch, and that's

1:43.9

F5. F5 released bulletins for

1:48.9

seven new vulnerabilities, four of which are rated critical. And two of the critical

1:56.3

vulnerabilities do allow unauthenticated remote command execution. So something you certainly need to patch

2:04.4

quickly. One is in the eye control rest and the second one in the traffic management user interface

2:13.5

or TMUI. We certainly have seen quite a bit of exploits against prior F5 vulnerabilities, so don't neglect them.

2:23.7

Some of the mitigation here can be accomplished by just not allowing public access to these vulnerable interfaces.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.