ISC StormCast for Tuesday, July 7th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 July 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, July 7, 2020 edition of the Sansanet Storms on a stormcast. My name's |
| 0:08.1 | Johannes Ulrich, and then I'm recording from Jacksonville, Florida. Yesterday I mentioned the |
| 0:15.5 | F5 Big IP vulnerability CVE 2020-509-022 and as I sort of alluded to in yesterday's podcast, yes, |
| 0:27.5 | exploits are out there and on Monday we really sort of saw a flood of different exploits |
| 0:34.0 | hitting our honeypots. So certainly this is now in full swing. |
| 0:39.4 | And if you have a system that hasn't been patched yet, |
| 0:43.2 | you certainly should assume it to be compromised. |
| 0:47.5 | Some of the more dangerous exploits that I've seen is, |
| 0:51.7 | first of all, sort of a backdoor that was added to Cron. It will essentially |
| 0:56.4 | just pull a URL and download whatever script it finds at that URL and execute it. There was also |
| 1:04.3 | an exploit that added an additional admin user to our honeypot. And lastly, we had an good old IRC bot that was actually written in |
| 1:16.0 | neat obfuscated pearl and essentially also represented a backdoor into the system. |
| 1:23.4 | Due to the number of exploits that we have seen, I'm planning on doing a special webcast |
| 1:29.7 | at 1 p.m. Eastern time on Tuesday, so join me there. |
| 1:35.9 | Probably will be a little bit shorter. |
| 1:37.9 | Half an hour or so we'll see what we'll do, but I'll do a detailed walkthrough to how |
| 1:43.6 | these exploits work and also show |
| 1:46.5 | some of the exploits if you collect it in our honeypot. And of course, we'll also go a little bit |
| 1:52.4 | over how to detect if you have been already exploited and how to figure out what the attacker |
| 1:59.3 | may have done to your system. |
| 2:02.9 | And I think it was back in January when Microsoft announced web content filtering as a beta |
| 2:09.6 | feature, sort of a public preview, they call it, for their advanced threat protection or ATP. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

