meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 2nd 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 2 March 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. #LDAP and #STARTTLS; NextGen Gallery #SQLi; Breaking CAPTCHAS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 2, 2017 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes.

0:08.5

Ulrich and I'm recording from Jacksonville, Florida. Today we got a quick diary from Boyan about TLS on unexpected ports.

0:18.3

In this case, Port 389. Port 389 is usually used for LDAB but

0:24.5

LDAP has an option where you can use start TLS to enable TLS on the fly for an

0:31.4

existing connection typically that's done for SMTP and quite commonly done

0:37.4

for SMTP for LDA done for SMTP for LDAP.

0:39.9

It's not as common and not as well known that you can actually use that option.

0:45.8

Of course, once you enable that option, you have to make sure that TLS is configured correctly.

0:51.9

And that's exactly what Boyan was testing here with the NMAP script

0:57.2

that he used to verify the TLS configuration. And if you're still daring enough to run Wordpress

1:04.8

and have the NextGen gallery plugin installed, it's time to patch. SQL injection vulnerability has been made public in this plugin with sufficient detail

1:17.1

to exploit it.

1:19.2

So I wouldn't be surprised if we already have people going around and scanning for vulnerable

1:25.8

implementations.

1:28.1

So this vulnerability does not affect all WordPress installs, but only those that have this

1:33.3

next-gen gallery plugin installed.

1:36.3

The German Fraunhofer Institute looked at nine different popular Android password managers

1:43.3

and found that all of them are to some extent

1:46.6

vulnerable. Now, some of the vulnerabilities are common to many of the applications. For example,

1:54.6

insecure storage of master keys. Other vulnerabilities are only affecting some of these applications.

2:02.6

One that comes up a couple times and is probably almost more severe is that passwords may be

2:09.6

leaked to the wrong subdomain.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.