4.9 • 696 Ratings
🗓️ 20 April 2022
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, April 20th, 2020 edition of the Sands and at Storm Center's |
0:07.5 | Stormcast. My name is Johannes Ulrich, and then I'm recording from Mary Esther, Florida. |
0:14.8 | Today I wrote up a quick post on how to deal with Linux systems that are using the U-boot bootloader. |
0:24.1 | U-boot is an alternative to crop. |
0:27.5 | It's often used for better devices, switches and the like. |
0:31.5 | So if you ever find yourself like I did to have to reset a password on a system using U-boot instead of Krupp. |
0:40.5 | You may find the post helpful. |
0:42.9 | Also, quick reminder here. |
0:44.4 | The reason I did this was for a net optics matrix switch that I got used at a good price, |
0:51.2 | and well, it still held logs back to 2008 in this case the logs also |
0:57.5 | included passwords and such so before you resell devices like this please go ahead and reset them |
1:05.8 | and today was oracle's critical patch update or a CPU CPU as Oracle abbreviates it for the quarter. |
1:15.2 | This quarter Oracle fixed a total of 520 different vulnerabilities across all of its products. |
1:23.9 | One vulnerability in particular stuck out and that was log 4j. |
1:28.3 | I did a quick search on their summary and found 110 mentions of Log 4J. |
1:34.3 | Of course, there are less vulnerabilities like this. |
1:37.3 | Sometimes log for j is just mentioned as a comment or such, but I would say it's fair to guess |
1:42.3 | that there are about 80 to 100 |
1:44.3 | vulnerabilities that are Log 4J related. Not all of them are critical based on the exploitability |
1:51.6 | of the individual vulnerabilities, but for example, there is a 9.8 CVSS score vulnerability |
1:59.1 | related to Log 4J in Oracle's healthcare repository. |
2:04.9 | So if you use any kind of Oracle products, this includes Java, this includes things like |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.