4.9 • 696 Ratings
🗓️ 1 September 2016
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, September 1st, 2016 edition of the Sandsenet Storms anders Stormcast. |
0:07.8 | My name is Johannes O'Rich and the day I'm recording from Jacksonville, Florida. |
0:12.3 | Adobe released a surprise bulletin for Cold Fusion and 11. |
0:17.5 | So no, it's not for Flash, so most Adobe users out there don't have to worry about this, |
0:24.9 | only affects the server component called Fusion. Also, the priority rating is only meaning that |
0:32.2 | there is no current exploit available for this. A little bit surprising that they bothered with sort of this out-of-band update for it. |
0:42.3 | It does affect the XML parser, essentially an external entity issue, so an attacker could |
0:50.3 | submit crafted XML to a Colfusion application and probably get system files in return. |
0:58.4 | Typically, once identified, these XML external entity issues are relatively easy to exploit. |
1:05.0 | Maybe that's the reason why Adobe came up with this out-of-band update. |
1:10.3 | And if you downloaded the OS10 BitTorn client transmission during the last few days, be aware |
1:18.6 | that via the official site you may have downloaded a backdoor version of this software. |
1:26.6 | Apparently the software was available from August 28th, |
1:30.3 | 29th for about 24 hours and it did include a version of the Heatnap Trojan that tries to steal |
1:39.3 | your key chains. It's not really clear how this happened, but the version of transmission that |
1:47.2 | included this Trojan was signed with an Apple developer certificate, but a certificate |
1:53.9 | that's different from the one typically used for transmission. The affected version is |
2:00.2 | 2.9.2, but not all copies of that version are affected. |
2:05.6 | After removing the backdoor, they did not change the version number. Also, that version wasn't |
2:13.6 | some time before the backdoor was installed. |
2:18.3 | And Kerspersky's Securelist.com site has a nice write-up on the demise of Lerk gang. |
2:25.3 | Lerk is commonly being held responsible for the Angler Exploid Kit. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.