ISC StormCast for Wednesday, March 29th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 March 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, March 29th, 2017 edition of the Sands and its Storm Center's |
| 0:06.3 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.2 | First, the correction about one story yesterday, I mentioned the webdaf exploit against IIS 6. |
| 0:19.8 | It has to run on Windows 2003. I guess I mentioned |
| 0:24.9 | 2013. There is of course no Windows 2013. It has to be Windows 2003. Yes, very old versions. |
| 0:34.7 | The part you should be concerned about is old forgotten SharePoint servers. |
| 0:40.3 | The Apache Struts 2 vulnerability is still actively being exploited, so hopefully if you didn't manage to update your servers, |
| 0:50.3 | you deployed some form of mitigating controls maybe a web application firewall or an |
| 0:56.5 | IPS rule there is a real great blog post that came out yesterday that discusses this vulnerability |
| 1:05.0 | in detail it however also offers an alternative exploit vector that may not get detected by your current |
| 1:15.6 | rules. |
| 1:16.6 | So take a look at it and make sure that you are protected from this variant of the exploit, |
| 1:24.7 | because it can be as damaging as the original exploit. |
| 1:29.8 | The original exploit used the content type header in the request. |
| 1:34.2 | The new variant actually uses a multi-part request and then in the second part it does use the |
| 1:42.7 | content disposition header essentially to do the same |
| 1:46.5 | trick. |
| 1:47.6 | So fundamentally the same exploit, exploiting the same vulnerability, but a different form of |
| 1:53.5 | the exploit that may not get detected because you don't have the content type header |
| 1:59.9 | as you had in the original exploit. |
| 2:02.3 | The blog post also shows you what you will find in your logs. |
| 2:07.0 | If you are being hit by this exploit, you will see an exception being locked. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

