ISC StormCast for Wednesday, March 7th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 March 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, March 7th, 2018 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:12.6 | About a month ago, Critical War on Ability was patched in the Exim Mail Server. |
| 0:18.4 | This is not often the default mail server in my experience, but it is available |
| 0:24.6 | for many different distributions as a simple install from packages. A quick look at Shodan shows |
| 0:34.0 | about 6.3 million exposed installs. And of course, mail servers, you want them to be exposed |
| 0:41.7 | to the internet. Now, when this patch was originally released, it wasn't really given a lot of |
| 0:48.8 | attention given that it was only a one-byte buffer overflow. So the attack already here only has one byte to play with, but it isn't unheard-off to actually |
| 0:59.5 | use a one-byte buffer overflow to actually then execute meaningful malicious code. |
| 1:07.1 | Well, and what changed today is, and the reason I'm mentioning this is that there is now |
| 1:12.9 | a detailed blog post showing you how to write and exploit for this specific vulnerability. |
| 1:20.4 | So with that, it's pretty much open season on unpatched XIM servers. |
| 1:26.3 | Make sure that you address this flaw. Again if you install |
| 1:30.7 | from packages it should already be part of your distribution and it should be a |
| 1:36.7 | pretty straightforward update. Other mitigation techniques are tricky here. The |
| 1:41.7 | flaw is in the base 64 decode function and well an awful lot of |
| 1:47.6 | different data is base 64 encoded in email. So this is exploitable via a wide range of commonly used |
| 1:57.2 | SMTP functions like for example e-Hello mail mail from, receipt to and off. And if following the |
| 2:04.9 | February patched use the updates from Microsoft, you had some problems with USB devices. In particular, |
| 2:10.7 | the ones that are sort of built in to your system like laptop cameras, then Microsoft has another patch for you. |
| 2:19.9 | Apparently the problem here is that the Windows update skips installing the newer version |
| 2:27.1 | of some critical drivers according to Microsoft and that causes then these devices to fail. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

