ISC StormCast for Wednesday, January 27th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 January 2021
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, January 27th, 2021 edition of the Sandtonet Storm Center's Stormcast. |
| 0:08.4 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.0 | Wallace today dropped the interesting vulnerability in Sudo. |
| 0:18.7 | Sudo, the tool that's used to allow for limited privilege escalation |
| 0:24.2 | in many Unix versions, is vulnerable to a relatively straightforward buffer overflow. |
| 0:32.6 | And of course, the end result is that you're able to escalate privileges without any restrictions. |
| 0:40.3 | Patches are already available for major Linux versions, so please update. |
| 0:47.3 | This is relatively straightforward to exploit vulnerability. |
| 0:52.3 | Qualis did publish a benign proof of concept that you can use to test if your system is vulnerable. |
| 1:01.9 | Sudo has had a history of vulnerabilities. |
| 1:04.8 | It was actually just about a year ago that we had vulnerability in S pseudo with the password feedback function. |
| 1:13.6 | That particular vulnerability was a little bit more limited in scope. |
| 1:17.2 | It only affected pretty specific configurations, |
| 1:20.9 | while this new vulnerability does appear to affect a much wider range of versions and configurations. |
| 1:31.8 | And then we have an update on Quagbot or QBot from Bradden. |
| 1:36.6 | Apparently that's sort of, well, also, |
| 1:39.2 | a Malver campaign returning from the holidays. |
| 1:43.6 | I guess they took a little bit longer holiday than some |
| 1:46.2 | of the others. Last time that Brad observed this was mid-December. And back then, well, |
| 1:53.6 | the particular campaign that he was observing here that Brad is calling TA551 or chat hack. |
| 2:01.6 | This campaign was spreading iced ID and now they switched over to Quagbot or QBot. |
| 2:10.6 | The campaign follows the all too well-known pattern where you receive an email with an attached SIP file. Now, this particular campaign |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

