ISC StormCast for Tuesday, June 19th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 June 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, June 19th, 2018 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.1 | Xavier today looked at some obfuscated JavaScript that he found surprise on a compromised WordPress website. |
| 0:21.6 | This JavaScript was in so far different in that it targeted particular mobile browsers. |
| 0:28.6 | And you may have seen some ads on websites that really sort of render the website almost unusable on mobile devices. Now, this is typically not due to malware, just some badly written ads, I believe, but in this |
| 0:44.9 | particular case it was a compromised website that then used JavaScript in order to inject |
| 0:51.1 | these ads. |
| 0:53.0 | Well, Kastaville was observing these ads, they just redirected to spam. |
| 0:58.0 | Now, for the most part, of course, this can change at any moment whenever the attacker |
| 1:04.0 | gets more money. |
| 1:06.0 | For, for example, redirecting users to malware. |
| 1:10.0 | And these days, of course, security camera vulnerabilities are always something to pay attention to, |
| 1:16.6 | given all the botnets, hunting for them, and we do have a new set of them. |
| 1:22.6 | This time they're affecting more higher-end cameras made by Axis. Access makes a wide range of cameras. |
| 1:30.3 | They all essentially run the same software, so pretty much all of them are vulnerable. |
| 1:37.3 | Probably the most severe of these vulnerabilities is an off-occacation bypass. |
| 1:42.3 | At least it's not a default password, but something similarly easy to |
| 1:48.0 | exploit. Turns out that in order to launch commands on the camera, you have to use a file name |
| 1:54.6 | with the dot SRV extension, but the authentication system doesn't necessarily validate the path correctly. |
| 2:03.3 | So if you're appending an URL, a file name that ends in dot SRV to a file name that you |
| 2:10.9 | have access to like index.html, then you may be able to trigger a command without actually requiring a username and a password. |
| 2:22.2 | Now, starting with that and a number of other vulnerabilities that can be exploited, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

