4.9 • 696 Ratings
🗓️ 17 March 2025
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, March 17th, 2020-5 edition of the Sands Internet Storm Center's Stormcast. |
0:09.6 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:14.7 | First I want to start out today with a quick congratulations to our Sands.edu graduates. |
0:20.2 | We had our commencement in D.C. on Saturday. |
0:25.5 | And, well, at this class, the class of 2024, we did graduate almost 500 students, |
0:33.5 | quite a ways from the early days where we had maybe two, three, five, I think, at some of the |
0:40.0 | first years. In Diaries this weekend, nothing really earth-shattering, some kind of interesting |
0:47.3 | scans for Trey Tech Vigr routers. These routers have been attacked for quite a few years now. Actually, |
0:56.1 | 2024. There was a new set of vulnerability of us being released, but pretty much ever |
1:01.6 | sort of since 2020, they have been attacked, have been scanned for. What's a little bit different |
1:06.6 | here for these attacks is that they're quite a bit more aggressive than some of the earlier ones. |
1:12.1 | Looks like some Mirai variant picked up on this. And well, as far as I can tell, they're |
1:18.1 | actually malformed and don't work. Remember, attackers don't have SLAs. If they throw 100 |
1:24.9 | exploits at you, one of them sticks, |
1:28.9 | and that's really all they need. |
1:33.5 | So I think they never really noticed that this particular exploit, |
1:37.4 | they added here recently, doesn't actually do anything. |
1:39.6 | At least that's my opinion here on it. |
1:42.5 | In the CGI dash bin part of the URL, |
1:45.7 | they omitted the dash, so it's just CGI bin. |
1:49.3 | I don't think that'll work for vulnerable routers. |
1:55.6 | I may be wrong, please tell me if there is some other exploit or so they're trying to take advantage of here. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.