ISC StormCast for Thursday, March 28th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 March 2024
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, March 28, 2004 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.3 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | This week our honeypots detected an uptick in queries for Apache OFBiss. |
| 0:21.8 | OFBiss is sort of an e-commerce, enterprise resource planning, |
| 0:25.4 | a kind of suite, looks like pretty massive software. |
| 0:29.4 | I'm not really that familiar with the particular software, |
| 0:32.1 | and it does not appear to be one of those super popular piece of software with about 500 to a thousand |
| 0:40.2 | of them being exposed to the internet. However, they had a number of vulnerabilities recently, |
| 0:49.0 | one of them allowing arbitrary code execution without any authentication. |
| 0:55.1 | So it's very possible that people like cryptocurrency gangs and such |
| 0:59.5 | picked up on that and are going to pick off the remaining OFBIS servers shortly. |
| 1:05.9 | What we're seeing in our honeypots is just scanning. |
| 1:09.1 | Our honeypots are not emulating OFBIS, so these scans |
| 1:13.9 | probably just tell the attacker that we are not vulnerable. |
| 1:18.4 | And next ployd for the most recent remote code execution vulnerability was published on GitHub |
| 1:24.8 | earlier this year. |
| 1:27.7 | And then we got an interesting vulnerability in, well, old Unix utilities, and that's always |
| 1:33.3 | a little bit of favorite of mine. |
| 1:34.9 | In this case, the culprit is the wall command, the command that you're using to send |
| 1:41.3 | messages to all users. |
| 1:43.3 | Typically, it's used, for example, to announce a system shutdown or a similar action that |
| 1:50.6 | you all users who are currently locked in, you want to be aware of. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

