ISC StormCast for Wednesday, May 1st, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 May 2024
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, May 1st, 2020, 4 edition of the Sands and at Storm Center's |
| 0:07.5 | Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Came across yet another attack against NAS devices today. This time the target is Sychcel NAS 326. Interesting that this is a little bit |
| 0:25.9 | an older vulnerability. It was first described, including a proof of concept. Late last year, |
| 0:33.0 | I think it was November. And I haven't really seen any exploit attempts for this vulnerability so far, |
| 0:39.6 | but yes, we are seeing exploit attempts now. |
| 0:43.5 | So far just from one IP address and it's attempting to download then a script and run it. |
| 0:51.1 | Sadly, haven't been able yet to recover this particular script that is being |
| 0:56.5 | attempted to be uploaded here. |
| 0:59.0 | Could be that they only really make it accessible to IP addresses to which they just |
| 1:04.3 | attempted to upload the script too. |
| 1:06.5 | So there could be some firewall blocking going on there, or maybe we are a little bit too late here |
| 1:11.7 | since this started a couple days ago, and this malicious second stage was already removed. |
| 1:18.7 | And again, there's an older vulnerability, so hopefully you got their systems already patched |
| 1:24.0 | for this particular problem, actually. Two different problems that sort of contribute here to it. |
| 1:29.3 | The reason it sort of stuck out to me a little bit when I saw it was the odd URL |
| 1:34.6 | format, where it's slash CMD comma, and then the remainder of the URL. |
| 1:41.0 | It's a post request, and then the actual the actual payload looks like it's sort of trying to |
| 1:46.4 | install some kind of package here and then passing the standard command injection this |
| 1:53.4 | additional payload parameter. And if you ever talk to a data scientist, a lot of their work, in particular when it comes |
| 2:02.5 | to machine learning, of course these days AI, well, that is often done using the language |
| 2:09.9 | R. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

