ISC StormCast for Tuesday, April 2nd, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 April 2024
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, April 2, 2020, 24 edition of the Sansonet Storm Center's |
| 0:07.1 | Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:13.5 | I'm just going to start with a quick wrap-up and some small updates regarding the XC Utils Backdoor. |
| 0:23.1 | Overall, no major news really sort of broke today regarding it. |
| 0:28.0 | A lot of clarifications and details. |
| 0:31.8 | Boyan did post the reverse engineering details that I mentioned yesterday. |
| 0:37.6 | So if you're interested in some of this, take a look at the blog post. |
| 0:42.1 | We're still hoping to put together some kind of video content for Tuesday. |
| 0:48.0 | Once that's live, I'll definitely advertise it on the Internet Storms on our website and our various social media outlets. |
| 0:56.4 | I would expect it to go live afternoon, Eastern Time. |
| 1:00.8 | As far as updates and details go, Andrews Freund did clarify that the initial indicator wasn't |
| 1:09.6 | the delayed login, but instead just logins failing. |
| 1:13.8 | This is definitely a feature slash bug in the early versions of the back door, |
| 1:20.2 | in particular the one that was released with 560. |
| 1:23.9 | I've seen at least one attempt to create a honeypot, also one sort of demo of the actual backdoor in order to create the demo. |
| 1:32.3 | A different key was used to log in to the SSH server. |
| 1:38.3 | Remember that the backdoor triggers on a particular key being used to connect to SSH. |
| 1:44.6 | Of course, the private key here is not known, |
| 1:47.9 | and the demo base just swapped the keys out for a known key, |
| 1:53.0 | so the backdoor actually worked. |
| 1:55.9 | That's helpful to kind of verify some of the static code analysis |
| 2:00.6 | that people like Boyon have performed on this backdoor. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

