ISC StormCast for Wednesday, June 19th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 June 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, June 19th, 2019 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich. |
| 0:09.4 | And today I'm recording from Washington, D.C. |
| 0:13.4 | Quick update on the TCP selective acknowledgement of vulnerability patches should be available now for all the major Linux distributions. |
| 0:23.6 | I'm just finishing up a diary post with some more details. |
| 0:28.6 | Should be made live early on Wednesday tomorrow. |
| 0:32.6 | If you can't apply the patch, then probably do want to make sure that selective |
| 0:39.3 | acknowledgments are disabled on your Linux machines. This is also in part |
| 0:45.2 | triggered by TCP segment offloading in network cards, which is another feature |
| 0:51.4 | that you could consider turning off. Now, when you turned off selective |
| 0:56.3 | acknowledgement on your system, make sure it is actually turned off. So take some packet |
| 1:02.3 | captures and make sure that in the Syn and Synx, you don't see the Selective Acknowledgement |
| 1:08.5 | okay option from the system. I've run into a couple systems |
| 1:13.3 | so far that actually needed to be rebooted in order for this change to become effective. |
| 1:19.0 | At this point, I have not seen any code actually exploiting this vulnerability, so we probably |
| 1:26.4 | still have a little bit time left. |
| 1:29.9 | But talking about vulnerabilities that are currently being exploited, Firefox released a critical |
| 1:36.7 | patch to Firefox 67.0.3 or 60.7.1. This fixes CVE 2019 11707, type confusion in array. Pop. By manipulating JavaScript objects, according to Firefox, this can be used to exploit Firefox. Now Firefox will crash if it runs into |
| 2:04.5 | this vulnerability but apparently this particular issue has already been used in attacks in the |
| 2:11.8 | wild so make sure you are updating Firefox today if you are using this browser. |
| 2:20.5 | And in a win for the good guys, Bit Defender released a decryptor for all versions of Gant |
| 2:27.7 | Crab. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

