meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 8th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 8 December 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Webshells; AWS Outages; Kafka Exposed; Windows 10 RCE; Browser XS Bugs

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 8, 2021 edition of the Sansonet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.2

What up a quick diary this morning that's sort of a little bit based around a new feature we're actually playing with,

0:20.1

and that feature is displaying newly hit URLs from our web application honeypots.

0:28.4

So any URL that we haven't seen in the past is sort of displayed there.

0:32.2

And what sort of stuck out a little bit yesterday actually was a particular host that was scanning

0:39.4

the internet it looked like for

0:41.1

web shells. Web shells, of course,

0:43.3

are associated with many reason

0:44.9

compromises, whether it be solar winds or

0:47.2

whether it be many of the

0:49.2

Microsoft Exchange server

0:51.2

compromises that we have

0:53.0

seen recently.

0:54.7

This particular actor, well, is such a sort of parasitically trying to find pre-installed

1:00.7

web shells and then trying to exploit them.

1:04.6

And apparently looking for things like, for example, default passwords that are often used

1:10.0

with these web shells.

1:11.9

Total of 28,454 requests from this single IP address over the day on Monday, hitting about 40 honeypots that are supplying us with data.

1:25.9

And as usual, if you're interested in running a honeypot,

1:28.2

well, check our site.

1:31.5

Of course, the big news item today was also the Amazon outage.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.