4.9 • 696 Ratings
🗓️ 31 October 2024
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, October 31st, 2024 edition of the Sandcent Storm Center's Stormcast. |
0:08.7 | My name is Johannes Ulrich and I'm recording from New York, New York. |
0:14.4 | First, a quick look at our web honeypots. |
0:17.9 | One scan that kind of stuck out today was scans for RDWeb. This actually only |
0:26.2 | affected sort of a subset of our honeypots, but over the last few days, they got hit by a large |
0:33.3 | number of scans for URLs that start with slash RD Web, which is indicative of RDP |
0:41.3 | gateways. |
0:43.1 | Also interesting that a large number of different IP addresses participated in these scans, |
0:48.6 | we pretty much didn't see any of the IP addresses more than three times, which again indicates that this is a botnet |
0:57.5 | doing these scans. RDP, of course, has heavily been abused by ransomware gangs and others, |
1:04.8 | so definitely something to keep an eye on. Having an RDP gateway is not bad. It's actually |
1:10.5 | often a way to better control RDP, but your authentication, of course, has to be appropriate. |
1:19.0 | And yesterday I talked about the vulnerability in CyberPanel, apparently this vulnerability is now being exploited by the PSAUX ransomware. |
1:31.0 | This information comes from Leekix, that's a vulnerability search engine. |
1:35.8 | Leakex also did the initial scan that found the 20,000 or so vulnerable systems. |
1:43.0 | This is a tricky vulnerability given that it was essentially |
1:47.9 | patched the day the proof of concept exploit was released. Lots of little odd things happening here |
1:54.5 | also with Leakex kind of revealing the ransomware exploitation just as they publish a list of vulnerable systems. |
2:04.6 | So still not everything totally clear here. |
2:07.6 | I'm linking to an article by creeping computer that summarizes things pretty good. |
2:11.6 | Also has links to a statement from a cyber panel on how to properly patch. |
2:19.3 | Let me have yet another way how your NtLM hashes could leak this time it's Windows themes. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.