4.9 • 696 Ratings
🗓️ 6 November 2018
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, November 6, 2018 edition of the Sansonet Storms and its Stormcast. |
| 0:07.0 | My name is Johannes Ulrich and I am recording from Jacksonville, Florida. |
| 0:14.0 | Apache today released an interesting advisory for Struts 2.3. |
| 0:18.0 | The problem here is that this version of Struts uses an outdated version of the |
| 0:25.1 | Commons File Upload library. This component has been known to be vulnerable to a remote code |
| 0:32.0 | execution vulnerability for about two years, but Struts 2.3 was still distributed with the outdated version of |
| 0:42.1 | this component, making it vulnerable to this vulnerability. If you included it and if you |
| 0:49.2 | actually took advantage of it using the standard struts to file upload mechanism. |
| 0:54.7 | The vulnerable version is 1.3.2. |
| 0:59.1 | The fixed version is 1.3.3. |
| 1:02.6 | You just have to replace that particular jar file if you are still using the outdated version. |
| 1:10.0 | And you can find links to advisories as well as to |
| 1:13.6 | the updated version of Commons file upload in our diary. |
| 1:21.9 | And unknown perpetrators used a number of high profile and verified stolen Twitter accounts in order to steal a good |
| 1:32.3 | number of Bitcoins. Last time I checked, they had about 30 Bitcoins stolen. And the way it all |
| 1:39.0 | worked is that these compromised accounts were advertising a tweet by Ellen Musk or claiming to come |
| 1:46.8 | from Alan Musk that Alan Musk would give away free Bitcoin. All you had to do is you had to |
| 1:53.8 | verify your Bitcoin address by sending a smaller amount of Bitcoin to that address. |
| 2:01.7 | Usually they're asking for about 0.4 to 0.6 bitcoins, which is still a few thousand dollars. |
| 2:09.9 | And then in return, you're supposed to get at least twice, |
| 2:13.3 | but possibly 10 times or more the amount that you send in. |
| 2:18.3 | Now, in order to support this scam, the perpetrators here went through quite a bit of trouble. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.