meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, April 30th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 30 April 2024

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DLink NAS Exploit Variation; DNS and Great Firewall of China; Android TV Data Leakage

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, April 30th, 20204 edition of the Sansonet Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:14.7

Last few days we have been seeing sort of a second wave of attacks that appear to target a vulnerability in D-Link NAS devices.

0:24.9

There are really sort of two vulnerabilities at play here. The more severe one is a simple authentication

0:31.8

bypass. These devices use a user message bus without password. So user and attacker can just simply authenticate

0:42.6

with user equals message bus leaving the password empty. The original proof of concept for

0:49.1

this vulnerability was released about a month ago by a GitHub user who goes by the name of network security

0:57.1

fish, and it used a specific CGI to actually then execute arbitrary commands, and that's

1:03.7

NAS underscore sharing.cgi. And that's all of a little bit the second vulnerability here, that

1:10.1

in order to then execute

1:11.8

arbitrary commands using this easy-to-access user, you need to have a URL like NES underscore

1:20.4

sharing that allows you to actually just send commands to the device.

1:25.9

Shortly after the vulnerability was announced, we did see sort of a

1:30.4

wave of attacks that basically just exactly used the proof of concept exploit. What we started

1:37.0

seeing then mid-month and in the last few days it really has sort of spiking is the use of

1:43.8

another CGI script, Oros P-C-O-C-O-C-G-G-I, no real idea how to pronounce it.

1:53.4

It appears to be possibly a Turkish word, but it's nothing that I sort of really found documented anywhere.

2:00.2

The URL parameters that are being used to look exactly the same as we see used against NAS underscore sharing.

2:07.5

However, it's possible that this other script actually is more something like later introduced backdoor,

2:15.6

maybe using the first vulnerability and is now taking advantage

2:20.3

of that same authentication bypass in order to execute code.

2:25.6

If anybody has any more details, maybe you own one of these affected D-Link NAS devices.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.