ISC StormCast for Tuesday, September 24th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 24 September 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, September 24, 2019 edition of the Sands and the Storms Center's |
| 0:06.7 | Stormcast. My name is Johannes Ulrich, and today I'm recording from London, England. |
| 0:13.6 | All the big news today is from Microsoft. Microsoft released an out-of-band security advisory and patch to fix a vulnerability |
| 0:24.2 | in Inaudet Explorer's scripting engine. |
| 0:28.0 | This particular vulnerability does not only allow for code execution, but it is also already |
| 0:34.6 | being exploited in the wild, which prompted Microsoft to release this |
| 0:40.4 | special patch. |
| 0:42.6 | So it's probably something you do want to roll out rather quickly. |
| 0:47.9 | Pretty much all versions of Windows that are currently supported all the way back to Windows |
| 0:53.0 | 7 and Windows Server 2008 |
| 0:56.1 | are affected and patches should be available. |
| 1:00.9 | As a workaround, Microsoft offers assistance in how to restrict access to the affected |
| 1:07.2 | jescript.dll. However, implying these particular workarounds pretty much |
| 1:12.8 | disables JavaScript in an explorer and that's often not a viable solution so |
| 1:19.9 | definitely apply the patch and Cloudflare released a blog post with |
| 1:26.9 | details regarding its bot- fight mode that it just |
| 1:31.3 | released as an option for its web application firewall. |
| 1:36.5 | Once enabled, this bot fight mode should prevent malicious bots from reaching protected websites. |
| 1:45.0 | Now the way it is implemented according to Cloudflare is that first of all, of course, |
| 1:50.0 | this particular bot fight mode will look for known bad user agents, but it will go way beyond |
| 1:57.0 | that. |
| 1:58.0 | It will do tricks like for example profile traffic to see if it matches the |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

