meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 16th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 16 January 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Skype/Team Foundation Server Patch; SCP Client Vulnerabilites; Hosting Vulnerabilites; Industri

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 16th, 2019 edition of the Sandsonant Storms,

0:07.2

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:14.6

Microsoft today released updates for Skype for Business and Team Foundation server. A little bit odd that these were published today sort of out of the ordinary.

0:25.4

They're only rated as important and moderate.

0:29.3

For Skype for Business, it's a spoofing vulnerability.

0:32.3

Apparently it can then also lead to cross-site scripting.

0:34.9

Team Foundation server, there's one cross-side scripting vulnerability

0:39.4

and an information disclosure vulnerability. At this point, no real reason to rush these out.

0:48.2

But probably kind of more interesting almost is vulnerability in SCP, the Secure Copy Command

0:54.1

that comes with SSH.

0:57.0

This vulnerability was found by Harry Centonov F Secure.

1:02.0

The problem here is that the SCPs actually derived well from good old RCP, an 80s command used back then to transfer files without

1:13.8

encryption and RCP allowed the server to actually specify the file name.

1:20.0

SEP still does that, the protocol still does that but the client is supposed to verify that

1:26.3

the file being delivered, the name is actually

1:28.8

the file name expected.

1:31.0

Well, apparently SCP doesn't do a great job with this.

1:35.4

The result is that an attacker running a malicious SCP server could override arbitrary files

1:42.9

on the user's system.

1:45.0

Interestingly, all major versions of SCP are affected.

1:50.0

OpenSH, PUDD, as well as WinnSCP.

1:54.0

There is no patch for PUDD available at this point.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.