meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 9th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 9 May 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. P2P Botnet Analysis; MSFT Malware Engine Patch; OS X Keychain Vuln (Patched)

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 9th, 2017 edition of the Sandsenert Storms,

0:05.6

and I'm a stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida.

0:11.9

We got an interesting post today from Renato of Morphus Labs, who is writing about his investigation

0:18.9

into a P2P botnet. This botnet, which was mostly comprised

0:25.0

of Unify routers and Raspberry Pis, among a number of other Linux systems like that,

0:33.9

did use a P2P system to communicate with each other, which enabled Renato to actually look

0:40.1

into the size of the botnet by just polling notes that connected to him for their neighbor list,

0:47.4

and then essentially just ask those neighbors for their neighbor list, which resulted in about

0:53.2

5,000 different infected systems by this particular botnet.

0:59.4

Interesting write-up about the command control infrastructure of this botnet.

1:04.4

The use of Zell certificates in certain cases for authentication is also kind of interesting. He also lists a number of

1:14.0

indicators of compromise that you can use to find infected systems in your network. Now, the

1:21.2

main infection vector here appears to be weak passwords, just like that. So often before, I mentioned Unify. The Unify routers often are

1:32.0

configured with a default UBNT account and password. Then there is also Raspberry Pis. Now, in the

1:40.4

past, Raspberry Pi's came with SSH enabled and the default password of Raspberry.

1:47.0

More recent versions of the Raspian operating system actually no longer enable SSH by default.

1:54.0

You have to specifically enable it after you create the SD card.

2:00.0

But typically these botnets aren't very picky.

2:02.9

They take any Linux system or Unixish system they can find in this case, as we have

2:08.2

seen before, the binary that's being uploaded, comes in various versions for different

2:14.2

architectures.

2:15.1

And if you downloaded Handbrake, the popular video conversion

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.