meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, August 18th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 August 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Laravel Bug Exploited; ThroughTek Kaley Vuln; Fortinet FortiWeb; Google Chrome Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, August 18th, 2021 edition of the Santernet Storm Center's Stormcast. My name is Johannes Ulrich,

0:10.3

and the I'm recording from Stockholm, Germany. La Ravel, a PHP framework that includes a component called

0:19.2

Ignition, whose main purpose is to make debugging easier and

0:24.6

also display prior error messages.

0:27.6

Well, it turns out that in older versions of Larravel, that's 842 and earlier, this component

0:36.6

suffered a remote code execution vulnerability that we are now seeing exploited.

0:44.1

The vulnerability is being tracked as CVE 2021-31-29. It was discovered or at least patched fairly early this year, exploit attempts will be able to modify

0:59.1

variables and execute arbitrary code. What we are seeing so far are attempts to essentially

1:06.0

detect if a server is vulnerable. No actual exploit seen yet, but our honeypots also are not

1:13.3

vulnerable, so we probably don't yet see that second part that actually then would load

1:19.8

some kind of exploit payload. First of all, components and frameworks like Laravel need to be

1:26.8

regularly updated. This is not the only

1:29.6

vulnerability that has affected Laravel in the past. But on the other hand, the ignition

1:36.7

component is specifically meant for debugging. So it's only being enabled if Larval

1:43.9

is running in debug mode.

1:46.0

This is a configuration setting.

1:48.0

So you don't actually need to uninstall here anything on a live server.

1:52.0

You just need to make sure that the live version of a site is running in the correct configuration.

2:00.0

So this debug code is not loaded. And regardless,

2:05.9

the remote code execution vulnerability, you never really should run a life site in debug

2:12.4

mode like this and provide attackers with very nice looking and detailed error messages.

2:20.6

And the fire I disclosed limited details regarding a vulnerability in the ThruTech Kalea protocol.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.