4.9 • 696 Ratings
🗓️ 31 January 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, January 31st, 2021, 2025 edition of the Sandton and at Storm Center's Stormcast. |
0:08.9 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:13.7 | In today's diaries, we have a deep dive by David Watson, one of our undergraduate interns, into an older netgear vulnerability, good old |
0:23.9 | DGN-2200 V1 and DGN 1,000 versions. These routers are no longer supported, but what's always |
0:34.3 | surprising is how many attacks we're seeing for these particular vulnerabilities. |
0:39.3 | So David took a closer look and actually did a real nice deep dive into these vulnerabilities, |
0:46.3 | how they exactly work and how they are being exploited. |
0:51.3 | Real neat here, even though the vulnerability itself, of course, is well known. |
0:56.5 | Still, it's out there. |
0:58.0 | And a good reminder, keep patching your routers. |
1:01.7 | As I always say, once a month. |
1:03.8 | Put a note in your calendar. |
1:05.4 | Check if your router firmware is up to date. |
1:09.0 | And yes, the real big problem here is that some of these devices |
1:13.7 | are end of life. And that's sometimes actually real difficult to detect or even realize that |
1:20.7 | your device no longer receives any updates. That's hopefully one of the things that this new |
1:26.7 | cybersecurity label that's supposed to come out is going to fix because it's part of that specification. |
1:33.7 | Routers are supposed to provide basically some kind of end-of-life date and indicator when the router will no longer be updated. |
1:43.4 | And VMware patched five different vulnerabilities in VMware area operations as well as area |
1:51.1 | operations for logs. |
1:53.8 | The CVE numbers of some of them may be a little bit on the low side, in particular, one that's a broken access control vulnerability, |
2:03.6 | that does allow a normal user to execute commands as an administrator, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.