ISC StormCast for Tuesday, November 7th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 November 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, November 7, 2020, |
| 0:04.7 | edition of the Sands and its Storm Center's Stormcast. |
| 0:08.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | After hearing about some exploits being released for the latest Latian Confluence |
| 0:20.2 | Data Center and Server vulnerability. |
| 0:22.6 | I took a look today at our data to see if we do actually see any exploitation attempts against this vulnerability. |
| 0:31.6 | This is CVE 202023-2518, and the URLs involved here are all starting with JSON slash setup dash restore. |
| 0:45.3 | There are sort of three different here, one local and also progress URL that's being used here. |
| 0:52.3 | Apparently it's also required that you are using an |
| 0:55.6 | ex-edlation token header with a no check parameter. On GitHub you'll easily find |
| 1:03.5 | three different exploits for this one ability. I haven't tested them yet. They do look |
| 1:09.4 | legit. One is a bit more complex, appears to add some |
| 1:13.7 | additional functionality, including looking for another URL slash rest slash API slash user. |
| 1:22.1 | The first exploit attempt we have seen came from 206-189-179-132. |
| 1:30.6 | This is a Digital Ocean IP, and haven't really seen much from that IP before back in |
| 1:37.2 | March. |
| 1:38.0 | They also looked for slash T4, which I believe is associated with WebLogic. |
| 1:44.6 | Now, this initial attempt I posted a complete request in the diary that I wrote today about |
| 1:51.3 | this does actually not include the token header. |
| 1:54.9 | So this may just be a quick check if that particular system is actually running at least and whether or not that URL is |
| 2:04.2 | reachable. |
| 2:05.7 | There are then a couple of other URLs that have exploited this vulnerability in the last few |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

