meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 1st 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 1 May 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Real Bad #WebLogic News; Facebook Messages Spread Malicious Chrome Extensions

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 1st, 2018 edition of the Sansonet Stormtonus Stormcast. My name is

0:07.7

Johannes Ulrich and I am recording from Jacksonville, Florida. If you're listening to this and if you're

0:13.6

running WebLogic, you probably know something bad is going to come. In April, Oracle released a critical patch update for its products.

0:24.2

With that it also patched yet another deserilization and remote code execution vulnerability in

0:31.5

web logic. Now there are two things that really make this particular flaw probably worse than the ones we had before.

0:40.3

First of all, there is an exploit out, so yes, if you haven't patched, you probably have already

0:46.1

been attacked. And secondly, while there is an exploit out, the patch actually doesn't

0:52.7

fix all the ways how this particular vulnerability could be exploited.

0:58.2

Oracle opted to just blacklist one very specific feature.

1:03.9

However, it did not patch the underlying vulnerability.

1:09.0

Now, ever since this proof of concept was released about a week ago,

1:12.6

we have seen very intense scans for Port 7,001 trying to exploit it, using sort of your

1:20.6

usual payloads. Haven't seen anything specifically yet that tries to bypass the patch, but

1:27.1

that's probably only a couple days

1:29.5

away if it hasn't been released already.

1:33.5

This modified exploit shouldn't really be all that difficult to pull off, so I highly

1:38.8

recommend that you do block port 7,001 to your Weblogic servers. That's the default port weblogic is listening on and that's what you do block port 7,001 to your Weblogic servers. That's the default port web logic is

1:46.5

listening on and that's what we usually see being scanned here. If you do need Port 7,001

1:53.8

exposed to the outside world for whatever critical business reason, then watch your Weblogic

2:00.7

servers very, very carefully.

2:02.7

Not really sure what else I could recommend there.

2:05.5

Maybe something like a web application firewall may buy you additional time until Oracle

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.