meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, July 25th, 2025: ficheck.py; Mital and SonicWall Patches

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 25 July 2025

⏱️ 5 minutes

🧾️ Download transcript

Summary


New File Integrity Tool: ficheck.py
Jim created a new tool, ficheck.py, that can be used to verify file integrity. It is a drop-in replacement for an older tool, fcheck, which was written in Perl and no longer functions well on modern Linux distributions.
https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136
Mitel Vulnerability
Mitel released a patch for a vulnerability in its MX-ONE product. The authentication bypass could provide an attacker with user or even admin privileges.
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009
SonicWall SMA 100 Vulnerability
SonicWall fixed an arbitrary file upload issue in its SMA 100 series firewalls. But exploitation will require credentials.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, July 25th, 2025 edition of the Sands.

0:05.8

And then at Storm Center's Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:12.4

And this episode is brought to you by the Sands.edu undercredit certificate program in cybersecurity fundamentals.

0:20.2

Jim's diary today is about a new tool that he wrote.

0:23.2

Well, it's really sort of a rewrite of an older tool.

0:25.7

There used to be a tool and while it's still around, F-check.

0:28.7

It's a simple file integrity check tool.

0:31.6

The only problem with it is, well, it's old, but it's also written in Pearl.

0:36.4

And sadly, Pearl is fading away a little bit,

0:40.0

and this tool did no longer run well in modern Linux distributions. Now, instead of spending

0:47.0

the time on fixing the older tool, which again relies on Pearl, Jim decided to take a more modern approach and rewrite the tool in Python.

0:59.7

It works fast, it performs well, and it still uses the old configuration file, so it should be a pretty

1:07.9

simple drop-in replacement. File integrity checking, of course, is always an important part of incident response and also

1:15.1

of detection.

1:16.7

There are lots of other tools.

1:18.0

Tripwire is one of the original commercial tools here.

1:21.9

Eight is in a lot of Linux distributions, OSEC, and with that, tools like Vazu also do file integrity checks,

1:29.9

but sometimes nice to have sort of a little Python script like this to just drop it on a system,

1:36.4

do some quick investigation, maybe excluding some files during an investigation by determining

1:42.5

that they have not been altered if you have a good configuration file for that particular system.

1:49.9

Well, and then a quick update on SharePoint, nothing really fundamentally new or different here.

1:57.0

The one thing that's happening now that we're seeing in our honeypots is that more and more

...

Transcript will be available on the free plan in 3 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.