ISC StormCast for Wednesday, November 25th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 November 2020
⏱️ 11 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, November 25th, 2020 edition of the San Santernet Storm Center's Stormcast. |
| 0:07.6 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.4 | Quick diary today with a couple just quick notes about TCP resets. |
| 0:18.4 | For example, why you may see TCP resets without sequence number, |
| 0:22.6 | a sequence number of zero, or YMAC TCP resets with payload. |
| 0:27.6 | So for the packet nerds here, something to read up on. |
| 0:33.6 | And VMware this week did release a bulletin announcing a critical vulnerability with a CVSS score of 9.1, affecting a number of their products. |
| 0:47.5 | VMware Workspace 1 Access, Access Connector, Identity Manager and Identity Manager connector. |
| 0:55.0 | The problem is there is no patch available. |
| 0:58.0 | Instead, VMware did publish some workarounds that essentially involve moving configuration file. |
| 1:07.0 | So if you're running these products, take a look at the bulletin. |
| 1:11.3 | At this point, no exploits have been cited in the wild. |
| 1:15.6 | The vulnerability was reported privately. |
| 1:20.6 | An attacker also needs to have access to the administrative console on port 8443, |
| 1:26.9 | and they do need to have some credentials to actually |
| 1:32.0 | execute the commands. Okay, well, we have a long weekend here ahead of us and I'm a strict believer |
| 1:40.1 | and not starting Christmas stuff till after Thanksgiving, but a little exception here for |
| 1:47.5 | special guest at Scotus to talk about his latest encounters with Mr. Kringle. |
| 1:57.2 | Hey, Johannes, thank you. I do appreciate you're making that exception. It's great to talk with you again. |
| 2:02.6 | Yeah, so Kregelcon coming up again and the Holiday Hack Challenge. Can you tell us a little bit about what we should expect this year? |
| 2:11.1 | Oh, sure. So remember, this is something that Sands does for the community every year. It's completely free. And it'll launch the second |
| 2:19.6 | week of December, but people can register for it now. But the idea is it's super high quality |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

