ISC StormCast for Wednesday, July 19th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 July 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, July 19th, 2020, |
| 0:04.7 | edition of the Sansonet Storm Center's Stormcast. |
| 0:08.6 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.1 | Our first scene URL feature did discover an interesting attack today against the Staggle navigation for |
| 0:23.6 | GERA menus and themes. This is a plugin for Gira that does implement some sort of nicer |
| 0:32.5 | design options for GERA make it look prettier. Well, the problem is in March, there were two |
| 0:39.6 | vulnerabilities disclosed in this particular plugin CVE 20203-26255 as well as CVE 20203-26256. |
| 0:52.1 | Both vulnerabilities are directory traversal vulnerabilities, just in different parts of the |
| 0:59.1 | particular plugin, and well, this can be used to read arbitrary files on the file system |
| 1:06.2 | often affected GERA server. We see it being used to, first of all, read Etsy password, but then also DBconfig. |
| 1:16.2 | comfix.xml password. |
| 1:18.0 | The second file is used by Gira to store database credentials. |
| 1:22.9 | So that's certainly something if that leaks, that could potentially be a problem. |
| 1:28.5 | And if you see the exploit URLs, well, it's pretty straightforward. |
| 1:33.3 | It's just a simple file name parameter that you have to hit with the right number of dot dots |
| 1:39.4 | to basically end up in the route path. |
| 1:43.3 | Since this particular vulnerability was made public, |
| 1:47.3 | we sort of saw off and on a couple of hits against related URLs. |
| 1:53.9 | However, in the last three days, |
| 1:56.0 | it really sort of has taken off a little bit |
| 1:57.8 | and reached the threshold where our first seen URL feature |
| 2:03.0 | did flag this as something new and of interest. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

