4.9 • 696 Ratings
🗓️ 19 April 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, April 19th, 2020, |
0:04.5 | 3 edition of the Sandinert Storm Center's Stormcast. |
0:08.7 | My name is Johannes Ulrich, and today I'm recording from Augusta, Georgia. |
0:14.3 | Well, today I got to write about a little bit an old vulnerability and an old feature. |
0:20.1 | UDDIs, UDDIs back in the day were supposed to basically organize little bit an old vulnerability and an old feature. UDDIs. |
0:21.6 | back in the day, we're supposed to basically organize enterprise web services have since |
0:28.1 | been kind of forgotten. Don't think anybody sort of really uses them much anymore, but there |
0:35.1 | are still some vulnerabilities out there that occasionally get the interest |
0:38.9 | of attackers. The one that I observed sort of having increased the last day or so was CVE 2014 |
0:49.3 | 4-210. This is Weblogic server--side request for jury vulnerability. The feature itself is linked to |
0:58.6 | the UDDI Explorer in WebLogic and essentially allows you to connect from the WebLogic server to |
1:08.2 | arbitrary URIs via the operator parameter. |
1:12.6 | Interesting kind of vulnerability. |
1:14.9 | I doubt it's really that fruitful, interesting that it offers such and sort of has this |
1:19.0 | search in activity. |
1:21.2 | We've seen sort of little blips over the last few months with hits against this vulnerability, |
1:27.2 | but nothing compared to what we saw yesterday, |
1:30.0 | which was something like close to 1,500 hits for this vulnerability |
1:35.5 | that usually gets nothing, |
1:37.7 | and every month or so we may get like five or so hits. |
1:42.1 | Normally, WebLogic listens on Port 7,001. And the latest search of activity |
1:49.8 | came from what looks like a Chinese ADSL IP address. And the number of government agency, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.