meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, August 18th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 August 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apache Struts; Emotet Bug;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, August 18th, 2020 edition of the Santernut Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.0

In case you had some issues connecting to the Internet Storm Center website this morning for change wasn't a problem with our web servers, but appears that the

0:24.4

Cisco Talas blocklist had our URL listed as malicious. This must have resolved sort of early

0:32.8

afternoon, so after that everything should have been cleared up.

0:37.7

Not clear why the URL made it onto this block list, but apparently some piece of malware

0:44.5

or so reached out to the internet storm center website.

0:48.8

I was looking on VarysTorl and found one piece of malware that just had a URL listed within its code,

0:57.2

but didn't actually connect to it.

1:00.4

This can be a technique to actually do force URLs like the Net Storm Centers onto Blocklist,

1:08.2

and yep, that may have been just what happened. And thanks, of course,

1:13.6

to everybody who reached out to us as well as to Cisco for having this resolved reasonably

1:19.1

quickly. In late last week, Apache released an update for Struts 2 that you should probably take serious.

1:29.7

There are two vulnerabilities that are of interest that are being patched here.

1:34.9

Now, the one that I'm most concerned about is CVE 2019-0-230.

1:42.0

This is a forced double- object graph navigation language evaluation vulnerability

1:47.6

or OGNL, short for object, graph navigation language. The problem with this vulnerability

1:56.0

is that it may in some circumstances lead to remote code execution. Part of the problem here is struts,

2:04.5

but part of the problem is also how people use struts. According to the guidance given by

2:13.7

struts, developers should avoid using raw expression language and they should use struts

2:20.8

tags instead. So whether or not you're vulnerable or whether this problem is exploitable

2:26.0

for your struts application really depends on the code that you are running, which makes

2:33.2

a little bit tricky to sort of figure out how severe

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.