meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 17th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 17 February 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Port 26; MSFT Servicing Stack; Centreon; NPM VSCode RCE;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 17, 2021 edition of the Sand Center at Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

Jim today wrote about an increase in Port 26 scans, and well, about a year ago he noticed a similar increase so interesting to

0:23.7

have a repeat of this event looks like the attacker is expecting a Telnet server on

0:31.4

port 26 and then trying to a spread version of the Satori botnet, according to some of the strings being sent,

0:40.8

which is one of those standard.

0:42.7

Hey, let's log into a Linux system with a weak password-style botnets like Mirai and the like.

0:50.0

The target here is most likely gigabit Ethernet passive optical network interfaces.

0:57.3

These modems or access points are often vulnerable.

1:01.7

A reader on the D-Shield Slack channel actually pointed us to a GitHub page that describes an exploit against one of these devices that will open up a Telnet server on Port 26.

1:15.6

And the attacks that Jim observed are somewhat consistent with this backdoor.

1:21.6

So by default, the Telnet server is not running, but with this exploit, it's possible to start it up on Port 26.

1:31.8

And what we are seeing now looks really more sort of like a secondary exploit than trying to

1:37.2

find these leftover telnet servers.

1:42.2

It looks like some Windows users had issues with Fabri's patch update where it stalled around 24%.

1:50.0

The reason was that you likely applied a servicing stack update first.

1:56.0

That servicing stack update was released on Friday, so after the Patch Tuesday update, but if you

2:02.6

first released that and then applied the Patch Tuesday update, then you ran into this hanging

2:08.6

update. Servicing Stack, that's the part of Windows that's responsible for applying updates,

2:14.6

and apparently there was a problem with that most recent release.

2:20.5

If you ran into this problem, the fix is to uninstall that servicing stack update and then

2:27.9

reapply the February cumulative update.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.