ISC StormCast for Wednesday, July 8th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 July 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, July 8, 2020 edition of the Sansonet Storms on as Stormcast. |
| 0:07.2 | My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:13.4 | So today I was kind of hoping we could wrap up the F5 Big IP vulnerability issue. |
| 0:20.5 | After all, we do have to work around for a week now. |
| 0:24.1 | We do have patches available. |
| 0:28.1 | And, well, the exploitation traffic we have seen is still there. |
| 0:32.1 | It's still ongoing. |
| 0:32.9 | But if anything, slowing down a little bit. |
| 0:36.2 | And earlier today, I did the special webcast talking about how this exploit works and |
| 0:42.0 | how the workaround such blocks it. |
| 0:45.8 | Well, it turns out there is a different version of this exploit out there. |
| 0:51.9 | The NCC group tweeted about this just earlier today |
| 0:58.0 | that they found a different exploit method being used |
| 1:02.0 | to gain again code execution on F5 big IP devices. |
| 1:08.0 | And again, this is something they have seen being used in the wild, and it's not |
| 1:13.7 | blocked by the simple workaround that F5 published that basically just blocks the dot-dot |
| 1:20.9 | in the URL. We'll see how this will develop, but looks like that you still need to patch quickly, |
| 1:29.5 | and definitely please make sure that you isolate the admin interface from the public. |
| 1:38.5 | But since these last couple weeks, all the Citrix ADC admin sort of laid back and watched the F5 Big IP admins sweat. |
| 1:49.5 | Well, today Citrix came up with updates for Citrix ADC and Citrix Gateway, fixing 11 different |
| 1:58.5 | vulnerabilities. Nothing here outrageously bad. There is one kind of interesting |
| 2:05.6 | vulnerability CVE 2020, 8194. It does allow code injection as an unauthenticated user, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

