ISC StormCast for Thursday, March 12th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 March 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, March 12th, 2020 edition of the Sandstone Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:12.2 | First of all, a little bit an update and clarification correction about the mystery SMB version 3 vulnerability that I mentioned yesterday. |
| 0:23.6 | Not actually a lot of news here. We still just have the Microsoft security advisory to go by. |
| 0:30.6 | Now one mistake I made yesterday and thanks for Rob to correcting me here on Twitter, I mentioned that this vulnerability is similar to Blue Keep. |
| 0:39.6 | Well, I got the vulnerabilities mixed up here. |
| 0:42.5 | Blue Keep is the RDP vulnerability. |
| 0:45.0 | This is really more like Eternal Blue, which was the Smb version 1 vulnerability. |
| 0:51.3 | And there is a CVE number for this vulnerability. |
| 0:53.7 | CVE 2020-0796. So other than that, |
| 1:00.0 | not really a lot about it. There are a couple attempts to name the vulnerability. I've seen |
| 1:05.6 | Corona Blue being used or SMB ghost, but not sure if I really like either name. There are a couple of |
| 1:14.6 | scanners that people release to detect if you're vulnerable. Now, what they're looking for here |
| 1:21.1 | is that you are supporting SMB version 3.1.1 and that you have compression enabled. Now, SMB compression |
| 1:32.0 | has actually been available back in SMB 1.0. There is also SMB protocol acceleration. Sometimes |
| 1:41.7 | the two words are sort of used a little bit interchangeable, I believe, |
| 1:46.0 | but for this vulnerability, only Windows 10 is vulnerable and Windows server version 1903 and |
| 1:56.8 | 1909. |
| 1:57.5 | Also that's for Windows 10, it's version 1903 and 1909 that are vulnerable. Of course, |
| 2:06.0 | it's not a certain clear if some older versions may be vulnerable, but aren't explicitly |
| 2:11.5 | sort of pointed out by Microsoft. Now, the workaround I told you about yesterday remains. It's essentially |
| 2:18.8 | disabling this compression feature. Go by Microsoft's guidance here. I've seen a couple of |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

