4.9 • 696 Ratings
🗓️ 20 September 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, September 20th, |
0:03.6 | 2000, 23 edition of the Sands and at Storms owners Stormcast. |
0:08.4 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
0:14.0 | So an interesting URL worked its way up in our first scene list. |
0:19.4 | This is a list of URLs that were detected by our honeypots, |
0:24.7 | but not seen before in this particular form. What it looks like is that someone is looking for |
0:32.9 | Adobe Experience Manager. This is a content management system. It had in the past numerous vulnerabilities |
0:40.6 | that also have been exploited. Now, this is one of those big enterprise systems, and it actually |
0:46.8 | comes with, well, what it calls dispatcher, which is a load balancer and also a web application |
0:52.3 | firewall. If you read on exploitation of these Adobe |
0:56.9 | Experience Manager vulnerabilities, they usually talk somewhat about how to bypass this particular |
1:02.8 | filter. This latest URL that we have seen looks like a variation of an older vulnerability |
1:10.0 | they're trying to find here. Nothing new and super current older vulnerability they're trying to find here. |
1:11.7 | Nothing new and super current. |
1:13.8 | But they're trying to do a little bit a directory traversal style evasion, I believe. |
1:20.3 | That's sort of the point really of these scans to get past some of these filters. |
1:26.7 | If anybody's more familiar with Adobe Experience Manager, |
1:30.6 | wouldn't mind any insight into what exact vulnerability they're trying to exploit here. |
1:36.1 | And if this is something that would actually work. |
1:39.8 | Sometimes, of course, attackers are trying these things, |
1:42.9 | and the attack themselves may not necessarily have any effect. |
1:48.0 | Regardless, if you're using Adobe Experience Manager, double check that you're up to date. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.