meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, September 21st, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 21 September 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. OMIGOD Scans; Apple Updates; ADSelfService Plus Exploit

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, September 21st, 2021 edition of the Sandstone Stormst Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.5

And then I'm recording from Jacksonville, Florida.

0:13.4

I briefly mentioned yesterday the increase in scans for Port 1270, one port that is associated with the oh my god vulnerability, the open management

0:25.5

interface issue that affected Microsoft's open source implementation of this protocol, and of course,

0:34.2

for the most part, Azure users.

0:38.1

Half of the scans were originated by researchers, as far as we could tell.

0:44.5

Now, we may not have captured all the research IP address that are being used to scan the Internet.

0:51.2

Only one particular group apparently attempts to do some form of exploitation.

0:57.0

The reason I call it just one specific group is that they're downloading a second-stage

1:05.1

payload then using the vulnerability, and they're always using the same IP address.

1:11.8

None of the payloads appear to be available, so this may really more be an attempt to see

1:17.7

which systems will reach out to the particular payload URL.

1:24.3

In addition, we have also seen a couple of simple attempts to just launch the ID or Who Am I Command, again, just to fingerprint the particular target and figuring out if it's vulnerable.

1:39.1

None of these additional sort of exploits came from researchers.

1:44.1

Again, as far as we can tell,

1:45.8

researchers so far are just leaving it with a simple port scan and maybe grabbing a banner.

1:52.4

Census, one of the research groups and probably one of the more established and respected

1:58.0

ones published that they only found 56 known exposed services worldwide.

2:06.2

So very small number and kind of suggesting that this service isn't really used outside of Azure.

2:13.7

And Apple today released iOS 15, iPad OS 15, Watch OS 8, TVOS 15, Xcode 13, Safari 15, and iTunes 12.12 for Windows.

2:29.4

With those updates, of course, came a number of feature improvements, but we also got a number of security

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.