meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, August 29th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 August 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DVRs Again; Disabling Intel ME; Wire-X Android DDoS Bot

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, August 29th, 2017 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich.

0:09.7

And the I'm recording from Jacksonville, Florida. I did a little experiment late last week where I rigged my DVR that is vulnerable to the infamous Merai exploit to just reboot every five minutes

0:25.3

in order to allow it to be continuously exploited. So the export we're talking about here is

0:32.1

the default password for Root that is XC 3511.

0:38.3

And ever since Mirai sort of popularized that particular attack, we have seen a never-ending stream

0:46.3

of infected systems looking for more bots.

0:51.3

Now I call these attacks Mirai, it's really dozens of different botnets and variations of this

0:59.2

basic exploits that pretty much do the same thing.

1:03.0

They try a small number of popular passwords in order to take over these systems. Using my small business cable modem connection with 5 IP addresses, it took about two minutes

1:17.6

between exploits for this DVR.

1:21.6

So what this really comes down to is that these kind of exploits are still alive and well. As far as I can tell, based on some

1:30.6

Shodan data, the sources of these scans are pretty much other vulnerable systems that got

1:37.4

taken over by different botnets. Sadly, there's very little that the end user can do about this. For example, for the DBR that

1:47.8

I'm using, I still haven't found a firmware update yet, and there's nothing that you can do

1:54.4

configuration-wise in order to disable that backdoor password. So really, the only thing you can do

2:00.8

is put these devices behind a firewall.

2:03.6

And cross your fingers that we don't have anything behind the firewall that will start

2:08.6

scanning for this vulnerability. And Intel's management engine that's included in many modern systems has cost, of course,

2:20.4

some security concerns in the past, either via vulnerabilities or the ability to access systems

2:28.4

via this feature or just its use as a covert channel.

2:33.6

Now, given all of these security issues, of course,

2:36.0

a lot of people have looked into disabling this feature,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.