ISC StormCast for Tuesday, May 21st 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 May 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, May 21st, 2019 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.5 | First, a quick update again on the RDP vulnerability. |
| 0:17.5 | Microsoft patch last week. |
| 0:19.5 | This vulnerability now also has been labeled Blue Keep, |
| 0:23.6 | and yes, there are more reports about people creating exploits for it. At this point, I think |
| 0:30.3 | I counted three or four different groups that claim that they have a denial of service version |
| 0:35.2 | of an exploit. There's also a GitHub repository that has a partial |
| 0:39.8 | exploit that doesn't actually cause any damage at this point. So it's not the denial of service |
| 0:45.7 | and definitely not a remote code execution exploit at this point. But there's certainly quite a bit |
| 0:53.5 | of interest in this vulnerability, probably the best way quite a bit of interest in this vulnerability. |
| 0:56.0 | Probably the best way if you sort of want to keep up to date on this is to monitor the blue |
| 1:02.0 | keep hashtag on Twitter. But of course, there's also plenty of sort of vendors that sort of advertise |
| 1:10.0 | their bears now using this hashtag. |
| 1:14.3 | And talking about attacks against Microsoft vulnerability CVE 2019 0604, that's a vulnerability |
| 1:23.1 | in Microsoft SharePoint. |
| 1:26.2 | It is now being actively exploited and we do have a brief blog from Brad about how to recognize |
| 1:34.4 | exploit attempts and links to how this particular attack works. |
| 1:40.5 | This particular vulnerability appears to be exploited by a variant of the China Chopper backdoor. |
| 1:47.0 | This is a very typical and kind of old by now, ASPX backdoor. |
| 1:53.0 | So the name China Chopper does certainly not imply any attribution here. |
| 1:59.0 | And in teaching about web application security, one chapter we always cover is JSON WebTokens |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

