ISC StormCast for Wednesday, September 30th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 September 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, September 30th, 2020 edition of the Sandstone Storm Center's |
| 0:07.6 | Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:15.0 | Yesterday, I mentioned the reports that we had about a bomb-garg line being installed on a system that used to be |
| 0:23.6 | maintained by Tyler Technology. Of course, that company was the victim of a ransomware attack |
| 0:32.3 | and apparently some credentials they used to log to customer systems may have been leaked. |
| 0:39.4 | In response, Xavier today published a quick diary with a couple points to consider if you |
| 0:46.6 | are hiring some company to manage systems for you. |
| 0:52.2 | Now, a couple comments we got here from readers, one in particular regarding |
| 0:57.0 | the Baumgarjump client, again purchased by Beyond Trust and known under that name. |
| 1:05.0 | Readers are reporting that they have seen employees of a service provider install legitimately discline, and it is useful |
| 1:15.5 | and good piece of software, but then they forgot to remove it after they were done with a system. |
| 1:23.2 | So certainly worthwhile to look over their shoulder, double check what they're doing. |
| 1:29.2 | And Xavier has a number of good points in his diary that you should consider if you are engaging |
| 1:37.1 | a company like this. |
| 1:38.4 | And well, many of us have to do this, of course. |
| 1:42.2 | This gets even more tricky, of course, if that company is also doing |
| 1:45.7 | your security monitoring, then it sort of comes down to who is watching the watchers and how much |
| 1:52.6 | effort you're still able to put behind actually monitoring their activities. And of course, |
| 2:00.7 | these last couple weeks, we talked quite a bit about the zero logon |
| 2:05.8 | vulnerability. |
| 2:07.5 | And essentially what this comes down to is an insecure RPC authentication from a |
| 2:13.1 | client to a domain controller. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

