meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 6th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 December 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cobalt Strike Analysis; ColdFusion Exploited; Atos Unify Vuln; ExteremXOS Vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, December 6, 2020,

0:04.3

edition of the Sandus and Stormstar, Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.1

The day today published a great diary with an update to his 1768.py tool.

0:21.6

That's the tool that's used to analyze Cobalt Strike configuration.

0:26.8

Now, traditionally, it was only able to deal with the configuration from the Cobalt Strike Beacons.

0:35.0

But thanks to the update that Did he put together in version 070, it's now able

0:42.6

to actually get the runtime configuration that's stored on the heap. So that's basically

0:50.1

what the CC++ code creates and is able to parse it. The tool will look for the

0:58.0

configuration, will extract the information, and then represent it. DDI has a little sort of demo

1:06.2

in the diary that goes over how to use this particular tool and what the output will look like.

1:14.4

But you'll, for example, get the IP address where that's being sent to URLs, user agents and such

1:20.7

being used by this particular Cobalt Strike configuration.

1:25.3

So create information to then go back and figure out what systems were exactly affected by

1:32.5

this compromise and to just learn more about how this particular install of Cobalt Strike

1:39.0

was configured.

1:41.7

And talking about good blog posts, Sisa has a nice write-up with details regarding some recent

1:47.9

attacks involving Cold Fusion. The vulnerability being addressed here is not terribly new, I think

1:53.9

March was released. Exploids were available pretty easily soon after the vulnerability became known and the patch was released.

2:04.5

But, well, still, Cold Fusion is not necessarily the easiest thing to patch, lots of dependencies,

2:10.9

depending on what software you run on top of it.

2:13.9

So good here for Sisa to actually walk us through how some of these exploits work and how this particular vulnerability is being taking advantage of.

2:23.8

Always a huge fan of people actually talking openly about compromises like this, because I think that's how we all learn how to better detect these attacks.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.