meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 19th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 February 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Discovering Files in Windows; Ring 2FA (and Nest); VPN Vulns; WordPress @hyp3rlinx

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 19th, 2020 edition of the Sandstone Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich.

0:09.0

I'm recording from Jacksonville, Florida.

0:13.0

Error messages leaking information is probably a concept that's very popular to people who have done any kind of network reconnaissance

0:22.8

or intrusion detection.

0:24.8

For example, if you do get a port unreachable error message back, you still know that the

0:29.9

host that sent the message exists.

0:33.0

But similar concepts also apply to operating systems and file systems.

0:38.4

And Jan looks at the particular interesting feature in Windows.

0:43.3

In Windows, if you don't have read access to a folder, you're not supposed to be able

0:48.9

to see which files exist in this particular folder. But turns out you get different error messages

0:56.6

depending on whether the file exists or doesn't exist. If the file doesn't exist, the

1:01.7

operating system will tell you the file doesn't exist. If the file exists, then you get

1:06.5

a permission denied error. So Jan actually wrote a little C sharp script in order to take

1:14.8

advantage of this and prude force folder names. A reader pointed out that Jan wasn't actually

1:20.9

the first one to come across this. Actually no real surprise like this. A fairly common problem

1:26.7

where error messages leak information.

1:29.0

John Page also did write up on this issue back in September of last year.

1:37.6

The issue has been reported to Microsoft, but it didn't sort of meet the threshold where Microsoft is going to come up with a patch

1:47.1

for the problem.

1:50.0

And the Amazon security camera subsidiary ring has of course been in the news in bad ways

1:57.4

in recent month, typically with attackers just prude-forcing users' passwords.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.