ISC StormCast for Thursday, October 19th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 October 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, October 19th, 2020, 3 edition of the Sandinid Storm Center's Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.0 | Jesse today is going in his diary over decoding hexadecimal encoded data that is very often seen if an attacker has |
| 0:24.4 | access to a console but now wants to transmit a binary file over that connection. |
| 0:32.2 | First time I've seen this in sort of widespread use was with Mirai. |
| 0:37.3 | The Mirai. |
| 0:44.9 | The Mirai bot spread via these echo commands, just like what Jesse is describing here, |
| 0:50.2 | and see it a lot with all of these sort of Mirai derivatives. |
| 0:56.7 | They're basically an attacker is just breaking into a system, using a simple password that was set in the system, |
| 1:04.9 | and now needs to use the connection they have established here to the console, to the terminal, to transfer a binary file. |
| 1:09.0 | The methods that Jesse is going over here is using Cyber Chef. |
| 1:11.9 | First of all, pretty easy to do it with that. And then, well, my favorite method is basically just using XXD. That's the command line utility you find |
| 1:18.1 | calmly installed on Unix systems that converts hexadecimal back into binary or back. And then we got |
| 1:27.0 | today Oracle's quarterly critical patch update. |
| 1:30.8 | This is the October edition, and it fixes 387 vulnerabilities. |
| 1:38.3 | Of course, this large number has to be put in context of all the different products that Oracle has to offer. |
| 1:46.9 | A couple of highlights here, of course. |
| 1:48.4 | I'm not going to talk about 387 different vulnerabilities, but a lot of these |
| 1:54.2 | vulnerabilities are in open source Java components, and there are a couple that sort of |
| 2:00.0 | keep repeating like Apache Spark and |
| 2:03.2 | Commons collections and such that are being patched here. Some of these vulnerabilities I believe |
| 2:09.0 | are actually a little bit older and not really that terribly recent vulnerabilities in these |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

