meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, June 6th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 6 June 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Post Exploit Script; Zip Slip Vulnerability; Redis Exploits; Drupalgeddon 2 Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, June 6, 2018 edition of the Sandcent Storm Centers.

0:06.5

Stormcast, my name is Johannes Ulrich, and you're an recording from Augusta, Georgia.

0:11.9

Xavier went hunting again on virus total and came across an interesting script that apparently was used in order to further compromise a system.

0:23.3

So this is not the actual exploit per se, but a script that would be installed by the initial

0:29.3

exploit, or as Xavier points out, a malicious user who already has access to the system.

0:37.2

In part, what's sort of interesting about this script

0:39.4

is that it's very modular, so it loads, for example, individual components from GitHub

0:45.5

and then has also a build-in update mechanism that can be used to update the script itself. It uses

0:53.2

only command line utilities, so with that it

0:56.2

presents sort of a simple text-based user interface that you can use to select and execute

1:03.0

individual components. One disadvantage, of course, of the virus total hunting approach is that

1:10.0

we don't really have a lot of sort of context

1:12.2

around the script so not really sure who used it how it is possibly being used in the wild if

1:18.3

it's being used in the wild and then of course what the initial exploit was that was used to

1:24.7

install this script on an affected host.

1:28.3

And researchers at SNCC security, a company that specializes in enumerating and securing dependencies

1:35.3

in open source projects, did find interesting vulnerability in many projects that deal with SIP files. Now, they sort of focus here on SIP files, but the vulnerability certainly applies to other archive file formats.

1:52.0

The problem is that SIP and other archives may include file names, and if you unsip the file, you may

2:00.0

blindly use the file names that are located

2:03.5

inside the file these file names may also include directory names and that in turn

2:10.2

can then lead to directory traversal or the overriding of existing files

2:16.6

which then of course could be executed.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.