meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, November 29th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 November 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. #Mirai Variant Attacking Routers via TR-069 Vuln; #Paypal #OAuth Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, November 29, 2016 edition of the Sands and a Storm Center's

0:06.8

Stormcast. My name is Johannes Ulrich, and I am recording from Jacksonville, Florida.

0:12.2

What better way to snap out of a long weekend than a major botnet that's taking down a large

0:19.3

ISP? In this case, it was a variant of the Mirai botnet that's taking down a large ISP. In this case it was a variant of the Mirai

0:23.8

botnet that now added a new exploit at hacking certain DSL routers. Now really the story

0:31.6

starts on November 7th. That's when a researcher posted a new vulnerability in the D-1000 modem deployed by Irish

0:42.7

ISP IRE. Now, this vulnerability affected the TR-69 protocol. TR-69 is a protocol that ISPs use

0:52.3

to remote configure modems, and in this particular case,

0:56.7

it used port 7,547, a fairly odd port, so nothing that's really used by anything else,

1:03.6

but actually this protocol often also listens on port 5,55555.

1:10.4

Now, this D-1000 modem is a variant of a Syccell modem and that's

1:15.6

really no surprise. Most ISPs really just rebrand a more or less off-the-shelf modem and all

1:23.7

modems of this particular type, not just the ones that I are deployed, are vulnerable

1:29.3

to this exploit, which is very easy to execute.

1:33.0

All you have to do is insert a shell command in the SetnTP server directive in the request,

1:41.1

and your exploit will be executed. There is a meta-sploid module available

1:47.0

that was published on November 7th with the original release of this vulnerability.

1:54.0

So this weekend, about 900,000 customers of German ISP Deutsche Telecom did report that their modem essentially kept crashing.

2:04.3

It's not really clear yet whether that was an intention of the exploit or really just a side effect,

2:10.2

but these modems, while they're not made by Sychcel, also appear to be vulnerable to this exploit.

2:17.8

What we have seen so far is that Mirai did adopt this exploit and is now actively scanning for it.

2:26.3

So all this very intense scanning that we have seen so far from Mirai now also includes scans for this vulnerability.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.