meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, July 6th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 6 July 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Apache Fixes Critical HTTP/2 TLS Authentication Flaw

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, July 6th, 2016 edition of the Sansanet StormSanus Stormcast.

0:07.2

My name is Johannes Ulrich and I'm recording from Jackson, Florida.

0:11.1

If you're using Apache with the HTTP 2 module enabled, you may want to check out the patch that was released today. It fixes a serious problem if you're

0:24.7

also relying on SSL certificates for authentication. This will only affect you if you are doing

0:33.1

two things at the same time, using HTTP2 and using client certificates to authenticate

0:41.1

your users for these HTTP2 connections.

0:46.2

Apparently Apache in recent versions didn't validate the ASL certificate correctly in those

0:53.1

cases, allowing essentially anybody to log in

0:57.2

site.

0:58.5

This issue only shows up in versions of Apache 2.418 and later, and only again if you

1:07.5

do have these two conditions fulfilled. The HAP2 module is not enabled by default.

1:15.5

And if you are not sure what HAP2 versions you're actually using in your network,

1:20.6

I posted a little T-Shark script that you can use to check for HEP connections.

1:35.3

If you are supporting HDP2, you should expect that all recent browsers will use HTTP2 if they're connecting to a web server via HTTP.

1:39.3

And yesterday I mentioned the exploit that was released against the ThinkPad UEFI vulnerability and

1:47.2

I mentioned that other systems may be affected as well.

1:51.7

Well, we got at least two more now.

1:55.0

Some HP systems are affected according to an update published by the original author as well as some

2:02.7

Gigabyte motherboards. So this is probably just sort of the tip of the iceberg

2:07.9

here and I expect more of them to be released shortly. I'm going to link to the author's

2:14.8

Twitter feed very typically posts updates like that and has links to updates

2:21.3

in his exploit GitHub website. And over the last couple years, several countries did investigate

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.