meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 17th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 16 January 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Whitelisting #Apache Extension; #Wordpress 4.7.1 released;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, January 17th, 2017 edition of the Sansanet Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich, and I'm recording from Brussels, Belgium.

0:13.2

On Friday, Xavier wrote about how various backup files can get you in trouble with Apache

0:18.9

if you leave them behind in the document route.

0:22.1

Now, the solution that Xavier suggested and it's of the standard solution to this is, first of all,

0:27.7

don't keep those files in the document route, and then also consider blacklisting certain

0:33.0

extensions.

0:34.6

Plaquisting is always dangerous because it's easy to miss a particular extension

0:39.9

that may be used, for example, by an editor as a backup file that you were just not aware of.

0:46.1

So today I wrote a little bit a diary with a different approach for you, white list extensions

0:51.7

with Apache that you would like to serve.

0:56.1

This way you avoid the issue of having to enumerate all the bad extensions that could

1:01.3

possibly happen.

1:02.8

And at least for a reasonably simple website, the white listing approach should work just fine.

1:10.6

As usual, any feedback regarding the scripts that I posted is appreciated.

1:15.6

They work for me, but I certainly have not tested them for all possible configurations of Apache.

1:22.6

And of course, would also be nice to extend it, for example, to EngineX, or maybe even for mod security,

1:29.3

which I haven't done yet. And WordPress released version 471. Among the vulnerabilities being

1:37.0

fixed in this version is the famous PHP Mailer vulnerability that we have talked about around New Year.

1:45.6

Now, it wasn't really clear whether or not this vulnerability was actually exploitable in standard

1:51.0

WordPress installs.

1:53.0

But while the PHP Mailer Warner Warner Warner is probably the best known, there are also a number

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.