meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 1st, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 1 December 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Composer vs PHPUnit; Microsoft Defender False Pos; HP Printer Vuln; Win10 Arbitrary File Read

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 1st, 2021 edition of the Sands and a Storm Center's

0:06.3

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.7

Took a look this weekend, actually, at one of our honeypots that we tuned a little bit towards some of

0:20.7

the word press exploits.

0:24.0

And one thing I noticed was more than I expected attacks against an old PHP unit vulnerability.

0:33.4

It was a very straightforward remote code execution.

0:37.3

Essentially a PHP unit sort of comes with a built-in web shell that was exploited back in 2017,

0:45.9

or actually, well, is exploited still today, as it turns out.

0:50.6

And one thing I noticed is that aside from the WordPress plugins that were targeted,

0:56.4

there were a couple other packages that apparently sort of were targeted for a PHP unit,

1:03.3

not necessarily for a vulnerability of the package itself. A little bit more digging led me to a tool

1:10.4

called Composer.

1:11.6

If you are familiar with PHP, you heard of Composer.

1:15.6

It's a package management tool for PHP that will like all these package management tools automatically install dependencies.

1:24.6

And turns out that all of these attacked plugins and such have

1:30.7

PHP unit as a dependency. So whenever you install the plugin PHP unit may be installed as well

1:39.6

and really depends on how you install it. When you are using Composer, you do have the option to specify

1:47.7

different environments like a live production versus a development environment. And in this case,

1:54.5

PHP unit is usually installed if you specify that it's a development environment.

2:02.0

So this may explain that there are still a lot of these vulnerable PHP unit installs around.

2:07.3

They got installed back in the day without the user really noticing that it was installed,

2:14.1

maybe on the development system, or maybe development features were enabled on a

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.