meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 29th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 October 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. PHP 7 RCE Exploited; Finding Shellcode; iOS/tvOS/Safari Updates; Sextortion Blogs

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, October 29th, 2019 edition of the Sansonet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich Entertainment recording from Jacksonville, Florida.

0:13.8

Last week, the Ph.P. Project did release a critical update for PHP 7. This was released for PHP 7.1.2 as well as for PHP 7.3, and the vulnerability

0:29.6

being fixed here is already being exploited in the wild. The vulnerability appears to be only

0:36.6

exploitable if PHP is run using PHP, FPM, the fast

0:41.8

CGI process manager in Engine X. In other versions of PHP, the vulnerability is present, but

0:51.4

doesn't appear to be exploitable.

0:55.0

Now overall exploitation is pretty straightforward.

0:58.0

It only requires a new liner carriage return in the URL which is URL encoded.

1:04.0

So percent 08, percent zero Ds, what you would typically see in a URL that's trying to exploit this vulnerability with

1:15.1

proof of concepts and working exploits being out there.

1:17.9

No surprise that this is already used in the wild and definitely something that you have

1:24.1

to pay attention to if you are running PHP 7 in this vulnerable configuration.

1:30.3

And in Diaries today, we have another one by Dedi. Today he's introducing SED bug.

1:39.3

That shell code debugger is actually quite useful, runs on Windows and can help you explain

1:46.2

shell code. And one thing that DDA is going over, this time is an option to actually

1:53.5

have SCD bug find the shell code for you in case it doesn't start at the beginning

2:00.2

of whatever file you're analyzing.

2:03.9

And Apple today released iOS 13.2 as well as TVOS 13.2. While these are first of all feature

2:13.9

updates, they also have some security content, sadly, not yet available.

2:20.2

There are no details yet about what security fixes are included in this update.

2:25.8

Also, iOS 12.4.3 was released.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.