meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 13th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 June 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Geoserver Cryptominer Attacks; Fortinet Update; Bitwarden Key Leak; Western Digital SMART abuse;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, June 13th, 2020,

0:05.0

edition of the Sansonet Storm Center's Stormcast.

0:09.1

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.0

Last week I talked about attacks against a duo server.

0:19.7

We saw some scans in our web honeypots last week, and I promised

0:24.4

I'll look into that a little bit deeper. Well, got around to setting up our usual honeypot

0:32.1

that actually implements the full geo server. It's a Docker container in that case.

0:38.3

That's out of how we set it up.

0:40.3

And, well, a big surprise.

0:42.3

It was the same group that is also going after these NIFI servers.

0:46.3

Very similar software and issue here in some ways.

0:50.3

With NIFI, we had a Java application that does allow as part of its normal functionality

0:57.6

that a user can execute arbitrary code.

1:01.8

Similar here with GeoServer, again, it's written in Java and has functionality to then execute

1:10.0

code.

1:15.6

GeoServer is meant to essentially manage map data.

1:22.4

It's an open source project. And just like NIFI, if you just sort of install the basic software,

1:29.7

again, I did it with a Docker container, then you have no authentication pre-configured.

1:34.6

There's one advantage from a defensive point of view running it in the Docker container. I used the default geoserver container, a little bit an older version to see if maybe they

1:41.2

were going after some vulnerability or such.

1:47.8

But by running in a Docker container,

1:54.5

there's not a lot of software that the attacker can actually here use things like curl, for example, don't exist inside a Docker container,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.