meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, November 3rd, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 3 November 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. BrakTooth Update; XSS to Root; Pentaho Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, November 3, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:15.0

We Ching did post an update on Braggtooth. If you're not familiar with Braggtooth, that's a set of vulnerabilities

0:23.0

that was released two months ago that affects a large range of Bluetooth devices.

0:30.5

As typical for these kind of vulnerabilities, multiple chipsets are affected by these vulnerabilities,

0:40.7

and of course, these chipsets then end up in all kinds of different devices and end user brands. So it's sometimes hard to tell whether or not

0:48.1

a particular Bluetooth device is using a particular chipset and whether or not it's vulnerable, making patching pretty

0:57.2

difficult for these type of vulnerabilities, because you also need updated firmware to start

1:02.8

out with.

1:03.8

In this diary that we're being published, we do have a table with all the different chipsets and what the current status is, depending

1:13.4

whether or not vulnerable or whether there is a fix available.

1:18.4

The tool that was used to find these vulnerabilities and the proof of concept exploit has

1:24.7

also been released as of this weekend.

1:29.2

So exploitation of these vulnerabilities may become more real, which of course puts additional

1:36.0

pressure on actually getting these vulnerabilities patched.

1:40.9

For an end user, often you find these patches being included in operating system updates,

1:45.5

so just make sure best you can that the operating system of your devices and such is up to date.

1:55.5

And researchers at Grimm took a closer look at Nagios, the network monitoring tool, and found about a dozen

2:04.6

different vulnerabilities ranging from cross-site scripting all the way up to remote code

2:11.6

execution and even privilege escalation.

2:14.6

The problem with network monitoring servers is that first of all, every

2:19.2

network has one, and then the server itself often does run with elevated privileges or

2:26.4

has even the ability to reach out to other systems on the network using elevated privileges.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.