ISC StormCast for Thursday, May 2nd 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, May 2nd, 2019 edition of the Sansanet Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and then I'm recording from Augusta, Georgia. |
| 0:13.0 | If you have a Dell computer, make sure that the support assist software that's delivered by default on most Dell computers has either |
| 0:25.1 | been disabled or updated. Dell patched a critical vulnerability in this software that could lead |
| 0:33.0 | to remote code execution. The problem here is the ever so ubiquitous cross-site request forging |
| 0:39.9 | problem. The Dell Support Assist does run a rest API that's only accessible via local hosts, |
| 0:48.3 | so you would think, well, not easily accessible for a remote attacker, but your browser can easily be tricked into sending |
| 0:57.3 | a request to this API since the API does not verify the origin of the request. |
| 1:05.5 | The API is all powerful, allows you to download and execute software. |
| 1:10.7 | It's intended for, as the name implies, support purposes and also to allow you to install updates and the like. |
| 1:18.6 | And that's really what this API is supposed to accomplish. |
| 1:22.6 | But due to the missing origin check, anybody whose website you visit is able to send requests to the API |
| 1:30.9 | triggering these updates and downloads. Bill Demarcopi found this vulnerability originally |
| 1:38.2 | October 26th last year reported it to Dell. Dell released an update for this vulnerability about two weeks ago, |
| 1:47.7 | and on Monday, Bill published a blog post with details about this vulnerability, |
| 1:54.5 | including proof-of-concept exploits. |
| 1:58.9 | And then we got 14 vulnerabilities in the AM 100 and AM100 and 1stress on Air Media Presentation Gateway. |
| 2:08.6 | These are devices that allow you to present wirelessly from a laptop or a mobile device. |
| 2:16.6 | And sadly, many of these 14 vulnerabilities do allow remote code |
| 2:22.6 | execution. To make things even more interesting, Creston announced that for some of these |
| 2:29.5 | vulnerabilities you may receive a patch end of the month. For others, you do have to wait until July. |
| 2:36.6 | I've seen these devices in multiple hotels, also at universities. Now, the product itself has |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

