ISC StormCast for Wednesday, October 21st 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 October 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 21st, 2020 edition of the Santernut Storm Storners Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, the day I'm recording from Jacksonville, Florida. |
| 0:13.0 | So we found an interesting Python script that actually looks like it sort of is trying to re-implement the MiriBot in Python. Not really sure sort of why, |
| 0:24.2 | but it's really more or less just a wrapper around C-Map. And yes, for sure, there are still plenty |
| 0:32.0 | of devices out there that are exposing Telnet and either haven't been actually exploited yet. |
| 0:39.3 | And I also found quite a number of devices that of course have been exploited for quite a while. |
| 0:47.3 | For example, by the Pricker bot that has been a couple years old or so and a simple reboot would probably fix some of these |
| 0:56.7 | devices. |
| 0:58.8 | And Google released an update to Chrome that fixes for high and one medium severity vulnerability. |
| 1:06.1 | And now one vulnerability that makes this update more interesting and probably also more urgent |
| 1:12.3 | is CBE 2020 1599. |
| 1:17.0 | It's a heap buffer overflow in free type and apparently this one has already been exploited |
| 1:25.3 | in the wild. Of course the zero log on vulnerability has kept Windows administrators kind of busy lately, |
| 1:34.3 | but don't forget in certain cases the Linux Samba implementation may also be affected of this vulnerability. QNAP now released an updated version of its |
| 1:48.8 | firmware QTS for its devices, for its network storage devices that addresses this vulnerability. |
| 1:58.4 | Now you're really only vulnerable if you are configuring the device as |
| 2:04.4 | a domain controller. Not really sure how common this configuration is, but anyway, please |
| 2:11.9 | apply this update. And just to emphasize that this is a Linux problem or Samba problem, |
| 2:17.2 | not a QNAP problem per se. |
| 2:20.0 | So if you do run a Network Act storage device that is Linux based, which many of them are, |
| 2:27.3 | and you are using it as a domain controller, then you're probably vulnerable unless you did patch this vulnerability. |
| 2:36.0 | And Kaspersky is reporting that the gravity rat matter is apparently mutating. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

