meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, May 23rd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 22 May 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Yet Another BlueKeep Update; SanboxExcaper; Signed Malware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, May 23rd, 2019 edition of the Science and It Storms,

0:06.9

Sturmcast. My name is Johannes Orich.

0:10.1

I'm recording from Jacksonville, Florida.

0:14.5

I put together a quick update regarding the Blue Keep RDP vulnerability.

0:20.3

That's CVE 2019 0708 and they're really

0:25.5

sort of two points I want to make in this blog post first of all don't they

0:31.8

put too much trust into the IDS signatures that have been published so far.

0:38.3

RDP is usually used over TLS and the part of the exploit that these signatures look for is

0:45.3

typically encrypted. So these signatures will probably not detect any exploit attempts.

0:52.3

Also all the current proof of concept and scanner exploits

0:56.8

out there, they all take advantage of TLS. Actually turns out at least in Windows 7 I

1:03.0

played with this quite a bit today, it's pretty hard to turn off TLS. So you should assume

1:10.8

that all RDP connections in your network are

1:14.5

using TLS. The second part that hasn't been mentioned often is network level authentication. That's

1:22.1

an authentication option that you have with RDP. It's sort of suggested when you are setting it up in Windows 7 and

1:31.1

later, but has some problems. It, for example, doesn't allow you to change your password if you

1:38.1

have to change the password as you're logging in, then you kind of have this catch 22 there.

1:46.0

Also in Windows XP, and I hope you don't have Windows XP RDP exposed anymore it may be more

1:51.5

difficult to set it up but the big difference with network level authentication is

1:56.8

that the authentication happens before the protocol details are negotiated.

2:02.2

So this way the exploit will no longer work unless the attacker has a valid username and

2:08.9

password.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.