meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, November 12th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 12 November 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. TheMoon Still Here; Apply Magento Update; CSS Injection in Slack

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, November 12, 2019 edition of the Sansonet Storms and a Stormcast.

0:08.0

My name is Johannes Ulrich, Entertainment, recording from Jacksonville, Florida.

0:14.2

Got sort of a flashback from back in 2014 today.

0:20.4

A reader asked us why they're seeing all these attacks that trigger the

0:26.5

moon signature in their IDS. Well, the moon was a warm that we described back in 2014. It attacked

0:36.3

Lynx's routers.

0:38.3

Now the signature that's commonly triggered here and that's still triggered today,

0:43.3

triggers on a particular exploit that the moon warm used back then.

0:49.3

Now since then of course things have evolved a little bit.

0:53.3

The exploit has changed slightly, but it still triggers these old signatures.

0:59.6

They essentially just look for the TM unplug.c.c.c.i. and then the TTCPIP parameter

1:09.0

that triggers this particular vulnerability.

1:12.9

Like so, many exploits, this one has been included in a bot that uses multiple exploits against

1:21.4

routers.

1:22.6

It identifies itself with the user agent Licker 1.0.

1:28.7

Now, the real question, of course, here is, is it a problem for you how serious are these attacks?

1:35.5

They essentially will hit any web server listening on Port 80.

1:40.4

80, whether or not the web server is verbal or not.

1:47.8

The signature itself just detects the attempt, as the message also says, not necessarily a successful attempt. Most likely you'll get

1:55.3

a 404 error back because this TM unblocked CGI script only exists in specific Lenses routers.

2:03.8

If you have one of those Lenses routers, well, I hope you patched it in the last five years.

2:10.8

Otherwise, it's probably long gun and compromised.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.