ISC StormCast for Tuesday, February 15th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 February 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, February 15th, 2020 edition of the Sandcent, and at Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.3 | A quick reminder today from our honeypots that if you ever see some of these backslash x16 sequences in your weblog, it's probably |
| 0:24.9 | just someone trying to use TLS to connect to a web server that doesn't support TLS. |
| 0:31.3 | Seeing this all the time, in particular, of course, these days with TLS being sort of the default, |
| 0:36.6 | a lot of bots and such that are connecting |
| 0:39.9 | to web servers, are also using TLS by default, and that's all this is about. |
| 0:46.2 | So not necessarily an attack and maybe just someone using the wrong tool or legitimately |
| 0:54.0 | trying to connect to your web server |
| 0:56.3 | that may not be configured correctly. |
| 0:59.4 | But talking about real attacks against web applications, turns out there is a new vulnerability |
| 1:06.5 | in Magento 2, the Adobe e-commerce platform, |
| 1:11.1 | and that vulnerability, which was patched on Sunday, |
| 1:16.0 | is already publicly being exploited. |
| 1:20.6 | So Adobe did release the patch. |
| 1:22.6 | You are warable if you are running anything before Magento 3.7p2 or 243P1. So the 2.3 and 2.44 branches are vulnerable. |
| 1:39.3 | The vulnerability does lead to unauthenticated remote code execution, so it's about as bad as it comes. |
| 1:47.4 | Sadly, the patch is a little bit tricky to implement. |
| 1:50.3 | It arrives as a zip file and a patch file that you sort of have to manually apply. |
| 1:57.7 | And if you look at the patch that was published, it does insert two new code segments |
| 2:05.5 | that will replace a particular pattern that consists of two nested scurly brackets. So |
| 2:14.4 | that's basically what the vulnerability is all about. According to Sandsk, you could |
| 2:18.9 | theoretically look for sort of this squarely pattern here in a web application firewall, but |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

