ISC StormCast for Wednesday, September 20th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 September 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, September 20th, 2017 edition of the Sandton and Storm Center's |
| 0:07.6 | Stormcast. My name is Johannes Ulrich, I'm recording from Jacksonville, Florida. |
| 0:14.2 | Forensics investigations often involve the collections of file access and modification time and the probably go-to tool for |
| 0:25.0 | this in the open source world is Mac robber. Now Mac here doesn't stand for Macintosh |
| 0:31.5 | instead it's short for modification, access and creation which are the three basic timestamps that you usually find |
| 0:40.0 | associated with files. |
| 0:42.7 | Now, Jim ran into a case where this tool didn't work for him, so he rewrote it in Python |
| 0:49.6 | with a couple of changes. |
| 0:52.7 | That's sort of a typical open source thing, of course, that tools like this get redeveloped. |
| 0:59.0 | And, well, a Mac robber itself actually started out as Grave robber and was then later, for |
| 1:06.0 | similar reasons, rewritten as Mac robber. |
| 1:09.4 | And now you have a Python version that will work on various |
| 1:13.4 | operating systems more seamless than the old version. A link to the GitHub repository for |
| 1:20.7 | this tool can be found in Jim's diary. And Apache released an update for Tomcat that does fix two vulnerabilities. |
| 1:31.0 | The first one is a remote code execution vulnerability that is enabled if you are enabling |
| 1:38.6 | the HTTP put method. |
| 1:41.2 | Now HTTP put allows someone to upload files to a system. In this particular case, |
| 1:47.6 | of course, if they're downloading JSP scripts, these scripts may be executed. The second vulnerability |
| 1:55.1 | does take advantage of the virtual dear context in order to view source code. |
| 2:02.0 | So no remote code execution here, but still something you probably do want to fix. |
| 2:09.0 | Overall, these vulnerabilities do only affect these specific configurations. |
| 2:13.8 | They're not quite as severe as these recent struts vulnerabilities, but certainly |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

