meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, October 7th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 October 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apache Flaw Details; VMWare ESXi Ransomware; AT&T SIM Forensics; Google Pushing 2SV

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, October 7, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.9

Today I took a little bit of closer look at the Apache vulnerability. That's CVE 2021-47.41773. Remember, that's the directory traversal vulnerability that only

0:27.2

affects Apache 2449. According to some of the commit comments in that version, they tried to

0:35.0

optimize performance of these checks that check whether or not a URL

0:39.8

is valid and inside the document route.

0:42.9

Well, they were a little bit too efficient here.

0:45.1

That's sort of what happened.

0:46.4

And then in Apache 2.450, which was released this week, they essentially added then again some code to look specifically for the

0:58.5

URL encoded dots. The vulnerable version was only available for download for about two weeks

1:05.9

from September 15th. So unless you downloaded Apache during that time, you shouldn't worry too much

1:12.4

about it.

1:13.2

However, if you do run 2449, there is also a possibility that you are subject to a remote code

1:21.2

execution vulnerability if you have CGI been enabled.

1:26.0

So it's pretty much exactly the same kind of issue that we had back in

1:29.6

2000, 2001 with IIS. Back then it was the scripts directory instead of CGI, but the similar mechanism

1:38.5

that could lead to code execution. Now, by default, an Apache CGI bin is usually not configured these days and also not really used as much.

1:48.4

So we have a relatively small population of servers that run the vulnerable version. Even less of them are subject to the remote code execution.

1:58.4

Interesting flaw in particular in a popular product like Apache. Totally get how stuff

2:04.2

like this can happen. Could have happened to me very well as well. This is fairly old code.

2:09.8

Some of the comments in this particular file go back to 1996. And so far this year we had a couple of critical war on abilities in VMware's

2:22.9

V-Center and VMware ESXI. Softos now has an interesting write-up describing some ransomware

2:30.9

that specifically goes after ESXI.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.