ISC StormCast for Wednesday, September 6th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 September 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, September 6th, 2017 edition of the Santonet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:12.8 | It was sort of a year ago that we really saw Mirai take off, so I put together a little summary of where we are today with Mirai. Last week, of course, |
| 0:23.6 | I set up that DVR torture chamber. So I want to see how many infected hosts are still out there. |
| 0:30.3 | Well, it looks like we're talking about 100,000 hosts that are infected with some form of Mirai or similar malware. We do actually see |
| 0:41.9 | less scanning on Port 2323, which was one of the hallmarks of the original Mirai variant |
| 0:50.1 | that we observed. But these days, that has actually died down quite a bit. |
| 0:57.0 | Overall, we do see a half-life of infected Mirai hosts of about 150 days now, |
| 1:03.0 | so Mirai is certainly going to stick around with us for quite a while, |
| 1:08.0 | in particular since there are still new systems being discovered with |
| 1:12.6 | new default passwords, so they're going to be just added to the list. |
| 1:18.6 | And if you're using Apache struts for your web applications or web services, it's time to update. |
| 1:26.6 | A new critical vulnerability was identified in struts that has been patched in 2.5.13. |
| 1:36.3 | The vulnerability does affect the Rest plugin, so if you're not using Rest, you should be able |
| 1:42.3 | to turn that off and secure your site that way. |
| 1:46.0 | I would still recommend that you update just in case that it gets enabled by mistake. |
| 1:52.0 | Now the problem here as before was with the deserialization of untrusted data. |
| 1:59.0 | There is no exploit available at this point, but an exploit shouldn't |
| 2:03.6 | really be all that difficult to come by. So definitely update this week if you can at all, |
| 2:11.6 | or at least check if there's any kind of web application firewall ruler so that you may be able to use to protect |
| 2:20.1 | yourself. |
| 2:21.0 | If you don't see an exploit by the time you're listening to this podcast, you should definitely |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

