ISC StormCast for Tuesday, January 30th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 January 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, January 30th, 2020, |
| 0:04.2 | for edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.6 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.8 | Today I noticed in our first scene URL list that we had a new variant for a little bit older confluence |
| 0:25.6 | vulnerability. This vulnerability in Adelaideon's confluence was patched back in October, has |
| 0:34.6 | been exploited since then, but there's sort of a small little add-on to the exploit script. |
| 0:41.4 | So first of all, the exploit sort of usually comes in three requests in this case. |
| 0:48.0 | The first requests sets the setup complete flag for Confluence to false. |
| 0:55.1 | What this means is, well, Confluence thinks it's no longer properly configured, so it will now, |
| 1:01.0 | when you hit Confluence, offer you to add an admin user. |
| 1:05.5 | The second request will then set up that new admin user, and the third request will turn Confluence back |
| 1:14.4 | into its normal setup complete mode, so that way other users will not be presented with |
| 1:20.5 | the page that allows them to set up an admin user. The end effect is that you have a new admin |
| 1:26.5 | user added to the Confluence instance, and yes, |
| 1:30.5 | turning the setup complete on and off does not require authentication, which is sort of the |
| 1:37.7 | real flaw here that was patched by Adelaide. |
| 1:42.3 | So what we're seeing now is a slightly improved attack against this vulnerability. |
| 1:47.0 | It adds sort of a somewhat random-looking string to the end of the URL. |
| 1:52.0 | I don't find any special meaning in it. |
| 1:54.0 | It looks basic for encoded, but it looks like random data starts with the word cache, |
| 1:59.0 | followed by the random data. |
| 2:01.2 | I obviously see the same random data from this one particular attacker. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

