meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 30th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 January 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Phishing IPv6 Miss; Facetime Bug Update; Outlook 365 Error

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 30th, 2019 edition of the Sands and its Storm centers.

0:07.0

Stormcast, my name is Johannes Ulrich, and I'm quoting from Jacksonville, Florida.

0:14.0

Just a quick update on the Microsoft Exchange of Vulner, the Priv Privilege escalation exploit that it brings along

0:23.2

with it. Yesterday I talked about it already and one thing I said we didn't have yet was a good

0:29.2

way to detect if you're under attack. Well, figured it out thanks to readers that also commented on this

0:36.1

and the thing to look for is event code 4624.

0:41.3

You should see then a log on type 3 and authentication package NTLM.

0:46.7

This will then detect the account, the NTLM relayed part of the attack.

0:53.1

So that's where the attacker actually tries then to escalate privileges.

0:58.0

Another good event to look for is 5136. This one is the event that'll show up if the axe

1:07.0

control lists have been modified. So that would be after the attack succeeded.

1:12.6

Boyan added details regarding this to the diary post from yesterday.

1:19.6

But also got sort of interesting, a little bit different good old fishing attack today. Now, it arrived as an email

1:31.3

as they often do and the lure here was attachment that promised final closing statement. So

1:38.4

someone who is just about to close on a house of of course, would be at risk here.

1:44.8

And the intent is not really to infect you here.

1:48.1

The link, this PDF, actually, just goes to a legitimate OneDrive page.

1:54.4

And from there, well, you're being then redirected to the attacker's page.

2:00.7

The attacker actually went through the trouble to get something

2:04.5

that looks a little bit, OneDrive like the host name they're using is Drive Document 1. But they made

2:13.8

a crucial mistake here in that they weren't ready for IPV6.

2:20.3

They do deploy as many of these phishing pages a blacklist where they're sort of trying

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.