meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, October 19th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 19 October 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Baselining Servers;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, October 19th, 2017 edition of the Santernet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Singapore.

0:12.6

Renato today published a little script that helped him recently in dealing with an incident. The problem here was that he had a large number of identically configured cloud servers

0:26.6

and had to figure out if any of them were compromised.

0:31.6

So the little trick that he played was to try to compare the files across all of these servers and then create a list

0:41.2

of outliers.

0:43.1

This tool turned out to be very useful to him in this initial triage to figure out which

0:48.4

server to focus on first in particular and that's probably not all that uncommon that there wasn't really much else

0:55.9

installed to help them out on these servers of course ideally people think ahead and install things

1:03.5

like host-based intrusion detection systems and the like before the breach happens but we all know

1:09.4

sometimes you're stuck with whatever you're being

1:12.9

given in the case of an incident like this.

1:15.7

And a test script is now available for the crack attack.

1:20.6

It allows you to verify if a certain access point was patched.

1:26.3

Now, this is strictly a test script, not a proof of concept

1:30.1

exploit in that it does require WPA2 credentials to the access point in order to run the script.

1:38.6

The test script will essentially just check the replay attack and check if the replayed key will be installed by the access point.

1:49.0

If so, then it will consider it vulnerable.

1:52.0

And crypto coin miners are not going away.

1:56.0

Minerva Labs just found a miner that they call water miner. Instead of the more popular

2:03.3

Bitcoin water miner does mine Monero. We have seen Monero being used quite a bit, for example,

2:10.1

in these JavaScript miners, because it is designed to be effectively mined with commodity hardware.

2:19.2

Water miner appears to be mostly distributed as part of gaming mods.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.