4.9 • 696 Ratings
🗓️ 31 May 2016
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, May 31st, 2016 edition of the Santernet Storm Center's |
| 0:06.5 | Stormcast. |
| 0:07.5 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:13.3 | According to a vulnerability note is released by cert.org, a METhost preoperative information management systems, essentially where you keep patient data |
| 0:24.0 | and the like, suffers from hard-coded usernames and passwords. |
| 0:29.6 | These passwords aren't widely known, but if someone does get a hold of it, they can log in |
| 0:36.4 | to any instance of this particular software and retrieve |
| 0:41.3 | patient data stored in the system. |
| 0:44.3 | I don't think I'm really surprised by this. |
| 0:48.3 | After all, this is just a database. |
| 0:51.3 | It's not actual equipment connected to the patient, which has had similar vulnerabilities |
| 0:57.6 | and verse before. And in general, medical software has been sort of part of the low-hanging |
| 1:04.6 | fruits when it comes to finding vulnerabilities like this. What's different here compared to most of these cases I've seen in the past, the vendor |
| 1:13.3 | actually patched the flaw. |
| 1:15.4 | So if you're using this particular software, you can apply the vendor patch in order to fix |
| 1:20.7 | this vulnerability. |
| 1:23.2 | And well, I missed it last week, but there is a new version of Chrome and Chromium fixing 42 different |
| 1:31.6 | vulnerabilities. |
| 1:33.3 | I am seeing here nine different vulnerabilities rated as high. |
| 1:38.4 | Some of them allow quote execution. |
| 1:41.8 | Others are cross-origin vulnerabilities that could be exploited, for example, |
| 1:46.6 | for cross-site request forging and information leakage. And the payment card industry security |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.