ISC StormCast for Thursday, September 26th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 September 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, September 26, 2019 edition of the Sandstone Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:10.1 | And then I'm recording from London, England. Today we got a diary from Brad talking about how Melsbaum is distributing the Quaser Remote Access tool. |
| 0:24.8 | This remote access tool is publicly available via GitHub, but often distributed maliciously in |
| 0:32.7 | email attachments like the one that Brad documented. |
| 0:36.4 | As usual, you'll find links to packet captures and the like. |
| 0:41.3 | So create a little example to hone your packet skills. |
| 0:46.3 | And we got an update to the Bulletin vulnerability that I was talking about yesterday. the Bulletin has now released a patch for this vulnerability. |
| 0:59.6 | You should apply it very quickly. It's critical. It's already being exploited. |
| 1:06.4 | Actually, according to Cerrodeum, this particular vulnerability has been known in the underground for about the last three years and has been actively exploited since then. |
| 1:19.6 | Of course, a little bit odd that the vulnerability hasn't been patched before that or hasn't been reported to the bulletin over the last three years. |
| 1:30.3 | The vulnerability itself is actually really straightforward, shouldn't really be that difficult to find |
| 1:37.3 | and really in any kind of code review, this particular code snippet which directly calls the Eval function in PHP with user input |
| 1:48.0 | should certainly have been flagged. |
| 1:51.0 | The bulletin is not free software. |
| 1:53.0 | It's software that you have to pay for, so I haven't been able to review the patch that the bulletin came up with. |
| 2:00.0 | The bulletin user has also come up with an unofficial patch. |
| 2:05.6 | This unofficial patch will essentially just comment out the Eval function |
| 2:10.6 | and possibly will break some functionality. |
| 2:14.6 | Not sure what the ultimate patch that the bulletBulletin came up with actually does. |
| 2:20.5 | I've seen a couple of reports from V-Bulletin users that they have seen attacks against |
| 2:25.6 | their sites. |
| 2:26.8 | In one case, at least, essentially, the attacker just deleted the V-Bulletin database. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

