meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, November 30th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 November 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Telekom Router's Not TR-069 Vulnerable; Software Only Defenses Against #Rowhammer

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, November 30th, 2016 edition of the Santernet Storm Center's Stormcast.

0:07.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:11.8

Let's start with a quick update on the Merai Botnet at hacking DSL modems.

0:18.6

Interesting piece of news here from Com Securis, a security company that took

0:24.4

apart one of the Deutsche Telecom Speedport modems that kept falling over over the weekend.

0:33.2

Well, it turns out that this particular modem is actually not vulnerable to this TR-69 vulnerability.

0:42.4

Instead, what they're assuming is that the modem itself essentially just locked up because all of the

0:50.1

connections that the Mira botnet established with it. A lot of consumer level network

0:56.8

equipment of course tends to fall over even under moderate loads so that wouldn't

1:02.4

be a big surprise if a modem like this would just lock up if too many connections

1:08.3

are established to it and the rate of connections typically doesn't

1:12.4

really have to be all that high and that's really what Comsacurus is testing here in their blog.

1:19.9

Well other than that, the scanning is still happening. We still see plenty of scans for this vulnerability.

1:25.5

The URL for the Mal malware download keeps changing,

1:29.4

they keep modifying this as one domain name is removed, another domain name is being used

1:36.5

in order to obtain the final malware.

1:40.1

If you're interested in looking at some of the malware more closely, I did post some of the samples that I collected.

1:48.4

You'll find a link to it in the latest version of the post that I put up today.

1:54.7

And then we got neat and kind of interesting, but maybe not terribly severe vulnerability in Windows 10 that may provide NetHacker access to a bitlocker encrypted drive during a system upgrade.

2:09.5

This only happens during a major upgrade.

2:12.0

So, for example, if you're upgrading to the anniversary update.

2:15.9

And what happens during the upgrade is that the BitLocker Trive, of course, is unlocked because

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.