ISC StormCast for Wednesday, March 17th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 March 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, March 17th, 2021 edition of the Santernut Stormsterners Stormcast. My name is Johannes Ulrich. And then I'm recording well from virtual San Diego, at least that's where the conference I'm teaching at this week would have happened. Microsoft today published a new One-Click Microsoft |
| 0:24.9 | Exchange on-premises mitigation tool. This tool is, as Microsoft says, the quickest way and |
| 0:32.9 | easiest way to mitigate the proxy log-on vulnerability on exchange servers. |
| 0:40.7 | Now, first of all, there's one thing the tool does not do. |
| 0:43.6 | It does not apply the patch, but it does implement other mitigation techniques that Microsoft |
| 0:50.6 | outlined before. |
| 0:51.9 | For example, there are some IAS rewrite rules and so that can be |
| 0:56.7 | used to prevent some of the exploits. This tool will also check if your server is already compromised. |
| 1:05.0 | These checks are done based on the type of exploits that Microsoft has seen so far. |
| 1:12.3 | So, for example, the tool will look for existing web shells, and it also includes the |
| 1:19.8 | latest version of Microsoft Safety Scanner. |
| 1:23.7 | Microsoft Safety Scanner, unlike a normal anti-Malver product, is not something that sort of detects a wide range of malware or runs in the background. |
| 1:34.1 | It's a tool that you're running on demand to look for specific threats, like in this case, for exploits and backdoors and the like being left behind by common proxy logon exploits. |
| 1:48.7 | So you definitely should do a manual scan as well after running the tool, but it's a real good |
| 1:54.9 | first tool to run. |
| 1:56.8 | It's quick. |
| 1:57.5 | It's simple. |
| 1:58.0 | And it's likely to find any exploits that were left behind using the proxy log on vulnerability. |
| 2:07.0 | So in short, if you are coming across an exchange server that hasn't been patched yet, run this tool first, make sure it hasn't been compromised, and then still apply the patch. |
| 2:19.1 | And while sticking with Microsoft for another story yesterday, of course, Microsoft had an |
| 2:23.9 | outage of its Azure Active Directory system, and today Microsoft published a pretty nice |
| 2:32.7 | and detailed document explaining what exactly happened. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

