ISC StormCast for Thursday, March 21st, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 March 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, March 21st, |
| 0:03.3 | 2004 edition of the Sansonet Stormers Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.3 | Today I dove a little bit into logs related to the recent 40 net 40 OS vulnerability CVE 2020 24 21762. This vulnerability |
| 0:28.2 | I talked a little bit about yesterday. We just sort of had an exploit released for it. |
| 0:32.9 | So I was wondering if you see any scans for it, this vulnerability is a little bit more tricky than |
| 0:39.4 | most of vulnerabilities that we usually sort of talk about. It's actually a good old-fashioned |
| 0:46.4 | buffer overflow, not one of these code injection or directory traversal vulnerabilities. So it does actually require a little bit preparation of the |
| 0:58.5 | system before the memory is kind of set up correctly for the exploit to work. The exploit |
| 1:07.6 | itself could be launched just against the index URL, so just looking for |
| 1:13.2 | URLs, which is what we usually do in our honeypots, is not really all that telling. |
| 1:18.7 | But the exploit that's out right now, and that's what an attacker is most likely going to use, |
| 1:25.9 | uses a specific URL, remote slash host check |
| 1:30.7 | underscore validate to do that memory preparation. And this particular URL is being used because it can |
| 1:38.4 | be used to send significant data to the system, which then helps in setting up the memory correctly. |
| 1:47.5 | Interestingly, we do see very little activity for this particular URL. |
| 1:54.4 | We saw some in January and in February,, they actually all came from two different IP addresses |
| 2:04.6 | that are related to each other. Not only are they in the same slash 24, they are also using |
| 2:12.4 | the exact same set of exploits in addition to this Fortnite 1. |
| 2:18.3 | They're using the same user agents and everything. |
| 2:21.2 | So highly likely that this is the same actor just using this particular URL. |
| 2:27.3 | This is also a decent URL if you're trying to fingerprint these devices. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

