ISC StormCast for Thursday, October 29th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 October 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, October 29th, 2020 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.4 | Well, I don't do this usually unless I get the date wrong, but we had some late-breaking news just as I made this podcast live so I'm |
| 0:24.0 | stitching this in and re-releasing the audio file we're seeing some active |
| 0:29.7 | exploitations against a web logic vulnerability that was patched a week ago |
| 0:35.9 | CVE 2020 14882. It had a CVSS score of 9.8. And as you can tell by |
| 0:44.7 | some of the exploits that we are seeing against our honeypots, this is possibly a trivial remote code |
| 0:53.1 | execution. |
| 0:54.5 | At this point, we are just seeing attackers probing our honeypot to figure out if it's vulnerable. |
| 1:01.6 | So more about this, probably any day during the day tomorrow or today, depending on when |
| 1:08.7 | you're listening to this. |
| 1:20.6 | Back in March, Microsoft published a patch for the SMB Ghost Vulnerability, CVE 2020-0796. And this vulnerability has rightfully so gotten quite a bit of attention because its CVSS score was 10, basically allowing |
| 1:30.4 | a full remote compromise without any logging in or any user interaction. |
| 1:36.8 | So it's as bad as it goes. |
| 1:39.5 | Jan today reminds us that there is still a lot of vulnerable systems that are still connected to the |
| 1:46.6 | internet. About 8% of all IP addresses that have port 445 exposed to the internet are vulnerable |
| 1:55.7 | to the SMB ghost vulnerability. And well of course we can just guess what it looks like internal to network, |
| 2:04.0 | so in not publicly exposed IP addresses, but I would expect this to be even worse. |
| 2:10.7 | The real problem here is that we have about 8% of hosts that are unmaintained, |
| 2:16.7 | unpatched, and probably vulnerable to a lot more than |
| 2:20.5 | S&B Ghost, but it's actually a little bit, one of the more difficult to exploit vulnerabilities. |
| 2:28.3 | And while the individual owners of these machines may not really care about these machines, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

