meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, July 21st, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 21 July 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Windows #summerofsam Vuln; HP Driver Vuln; Linux Priv Escalation; Fortinet Vulns

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, July 21st, 2021 edition of the Sandcent Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich.

0:09.0

And today I'm recording from Jacksonville, Florida.

0:13.0

Sometimes vulnerabilities are so simple that you kind of wonder why nobody came across them earlier.

0:19.0

Well, maybe someone saw it, but didn't speak up.

0:23.6

The problem here is what has been referred to as the summer of Sam Warnaby.

0:30.2

Sam and System Hives are typically only readable by the administrator in Windows, but starting with Windows 10, 1809, which was the

0:40.6

2018 version of Windows 10, these registry hives became readable by any user. Now, you

0:48.3

couldn't read them directly. There was still some additional security here that prevented reading them directly, but

0:56.8

the volume shadow copy of these hypes that was readable by any user, and that's sort of how

1:06.0

an attacker could gain access to these registry hives, which means an attacker will have access to

1:13.3

hashed passwords, which then, of course, could easily be brute-forced.

1:18.7

Volume shadow copy, well, it's a great feature. It sort of automatically creates backups.

1:23.5

That's basically what the problem is here, and it's enabled automatically if your system

1:29.3

disk is greater than 120 gigabytes, which is pretty much any modern system.

1:36.3

Probably the simplest fix here is to disable the volume shadow copy service, which will prevent

1:41.3

these copies from being created. Of course, you have to delete

1:45.6

existing copies. Be aware that this, of course, removes that safety layer from your systems.

1:52.6

You better trust your other backups that they will be sufficiently granular, but if you mess up

1:59.4

a configuration, you could easily undo this.

2:03.0

And server versions of Windows do not appear to be affected by this problem at all.

2:08.7

At this point, I haven't seen anything official from Microsoft regarding this problem,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.