ISC StormCast for Tuesday, February 20th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 February 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, February 20th, |
| 0:03.2 | 2004 edition of the Sands and its Storm Center's Stormcast. My name is Johannes Ulrich, |
| 0:10.0 | and today I'm recording from Jacksonville, Florida. Today we have another diary from one of |
| 0:16.3 | our undergraduate interns, Raphael Larius, is in our backs program. And, well, he's looking at |
| 0:24.6 | an old favorite, and that's the Marai Botnet. The Mariah Bartnet originally developed in 2016, |
| 0:31.3 | has been taken down multiple times. The original authors have been arrested and convicted, |
| 0:37.4 | if I remember correctly. |
| 0:39.4 | But truth being told, Mirai is not just one botnet. It's now a huge family of botnets |
| 0:46.4 | that all have their own little quirks, their own exploits. This particular one has a couple of |
| 0:53.6 | relatively recent exploits. This particular one has a couple of relatively recent exploits from 2023 that |
| 0:59.3 | Rafael spotted in the spot net. Other net, what really sort of makes Mirai, Mirai, in my opinion, |
| 1:06.1 | is that it has this very efficient S-Sage brute. Proofforce engine and Telnet proof force engine. |
| 1:13.4 | And then also that it does use this echo trick to then transfer binaries to the vulnerable system. |
| 1:23.2 | They're sort of, in my opinion, at least, some of the key properties that sort of identify |
| 1:28.4 | Mirai. |
| 1:29.4 | Others may have a little bit other opinions about this. |
| 1:31.8 | And of course, sometimes you now also see some of the members of that family being called |
| 1:37.5 | by their own and different names. |
| 1:40.5 | And last week I talked about the key trap vulnerability. |
| 1:44.1 | That's the key trap vulnerability. |
| 1:53.7 | That's the DNS sec vulnerability that allows you to shut down many popular bind and unbound resolvers. |
| 2:04.4 | Thanks to researchers, Tepe Fukuda, we now have a proof of concept exploit that has been made public as a series of Docker containers in GitHub. The real critical part of the exploit, if you don't want to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

