4.9 • 696 Ratings
🗓️ 10 January 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, January 10th, 2023 edition of the Sandstone Storms, Stormcast. |
0:08.9 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:14.3 | Big diary today is sort of related to Circle CI, but not related to the Circle CI breach recently. |
0:22.7 | And the diary is about, well, attackers who are searching for Circle CI configuration |
0:29.1 | files. |
0:30.3 | These YAML files are essentially scripts that tell CircleCi how to build a certain project and yes they may include |
0:39.9 | usernames and passwords so that's why the attackers are going after them in the |
0:46.5 | particular case that I observed in our honeypots there were two IP addresses both |
0:51.5 | hosted on OVH and likely related as they also scan for a number of similar |
0:59.6 | URLs like various configuration files for different software. |
1:05.4 | We keep seeing these configuration files being looked for sort of one of the more common attacks. |
1:11.6 | We do see in our honeypots, so make sure you properly configure these configuration files. |
1:17.7 | If possible, don't keep them in the document route or at least them. |
1:22.2 | Maybe you want to do both. |
1:23.4 | Configure your web server not to actually serve these configuration files. |
1:28.3 | Interestingly also that they went sort of for some backup files like with the dot-back extension, |
1:34.3 | which may be done in order to evade some of these filters if you were sloppy and left backup files behind. |
1:41.3 | And just to reiterate, this is not at all related to the Circle |
1:45.8 | CI breach, so you still want to rotate your credentials if you haven't done that yet. |
1:51.9 | And Amazon announced that it will now encrypt all objects stored in S3 by default. This has |
1:59.9 | been an option in the past, but now that's the default setting. |
2:04.4 | This essentially is no encryption at rest. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.