meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, March 8th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 7 March 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Ukraine Scam Followup; Dirty Pipe; Firefox Update; Azure AutoWarp; Terramaster Vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, March 8, 2020 edition of the Santernet Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich, and today I'm recording from London, England.

0:12.8

Quick follow up on the Red Cross donation scam that I talked about yesterday and wrote up on Friday.

0:21.8

Well, the original scam asked for a donation via Bitcoin,

0:26.2

but it actually offered an email address to send an email to if you needed help with that.

0:31.4

So I did that, and turns out they're also willing to scam you via PayPal.

0:37.2

I did report the affected address to PayPal,

0:41.8

so hopefully that'll get shut down pretty quickly. The Bitcoin scam wasn't really successful,

0:49.1

still only seeing about $10 or so a single transaction being received by the Bitcoin address.

0:55.7

I hope that this was just a test.

1:00.0

Let me have an interesting vulnerability in the Linux kernel that allows for ProVitch

1:06.4

Escalation.

1:08.0

The developer of that found the vulnerability Max Kellerman did call it dirty pipes

1:14.4

based on its use of pipes. Now, in Unix, you often transfer data between processes via pipes,

1:22.4

and there's a special mode here how these pipes can be used called splice. Now, if you splice pipes,

1:29.2

what this means is instead of copying the data from one buffer to another, from one process

1:35.3

to the other process, several processes share the same piece of memory. That can then under certain

1:43.2

circumstances lead to confusion where data intended for one process

1:48.3

ends up at a different process with different privileges.

1:53.9

Max Kellerman did develop a proof-of-concept exploit and published today a blog post with

1:59.3

details about the vulnerability.

2:01.6

The proof of concept exploit does allow overriding part of the Etsy password file.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.