meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, September 4th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 4 September 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. LNK File Trickbot; Supermicro Vritual USB BMC Vuln; Facebook Free Basics Key

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, September 4, 2019 edition of the Sandstorm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and today I'm recording from Brussels, Belgium.

0:14.1

You've got another guest diary today from Jan Kopriva who wrote about an interesting variant of trickbot that he came across.

0:24.5

The interesting part here is the link file that's used to spread this variant of trickbot.

0:31.3

Link files usually will link to other files, but they also can contain content themselves and in this case in addition

0:40.9

to the link file itself there is data being appended to the link file at its end.

0:49.4

Windows pretty much ignores data being appended to a link file that's otherwise properly formed and in

0:55.6

this case the script within the link file will extract the next stage of the payload

1:03.4

from this additional data appended to the link file the code once extracted

1:10.4

from the link file will then download additional stages,

1:15.5

which turns out, as I mentioned earlier, to be yet another variant of Trickbot.

1:23.2

Security company Eclipseum released details regarding regarding vulnerability in some super micro

1:31.7

motherboard BMC or baseboard management controllers.

1:37.1

One of the features implemented by these controllers is virtual USB devices.

1:43.3

These virtual USB devices are essentially USB drives that can be connected to the server across the

1:52.7

internet.

1:53.4

You can use that, for example, to remotely reboot a server to a different operating system.

1:59.5

For example, to install a new operating system,

2:02.0

apply patches, or repair an existing operating system install, a feature that is quite useful

2:09.2

sometimes in particular if you're trying to rescue boot down server. But apparently,

2:16.6

authentication to connect these USB devices isn't implemented correctly

2:22.6

in some of Supermicros BMCs and as a result an attacker can connect their own USB device

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.