SANS Stormcast Monday, September 22nd, 2025: Odd HTTP Reuqest; GoAnywhere MFT Bug; EDR Freeze
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 September 2025
⏱️ 9 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, September 22nd, 2025 edition of the Sands Internet Storm Sunners, Stormcast. |
| 0:12.4 | My name is Johannes Ulrich, recording today from Las Vegas, Nevada. |
| 0:17.7 | And this episode is brought you by the Sands.edu bachelor's degree program in Applied Cybersecurity. |
| 0:25.8 | This weekend I tried a little bit something different with my diary, something that we have done in the past, and I think I haven't really done as much recently as we should. |
| 0:36.1 | And that's well, really just post an observation |
| 0:39.1 | where I have no idea what it's about. And hopefully someone here in the audience or someone who |
| 0:45.3 | read it in a storm center will be able to fill in some of the gaps here. The problem is |
| 0:52.0 | an sort of interesting request that our honeypots |
| 0:56.4 | have been seen lately. |
| 0:58.0 | And of course, honeypots typically are |
| 1:00.0 | being hit by sort of malicious |
| 1:02.2 | requests. And that's why I suspect that this is some kind |
| 1:06.0 | of maybe recon scan or whatever. |
| 1:08.5 | The HTTP header that sort of made this request stick out is the X-forwarded app header. |
| 1:16.6 | When you're dealing with proxies, they're usually like the X-forwarded host, X-forward IP address, |
| 1:21.1 | and the headers like that being used to indicate if a request went through a proxy and, well, what the original |
| 1:29.4 | client IP address was. This looks like something similar, and quite often headers like this |
| 1:37.4 | with proxies are being used to potentially bypass authentication, bypass access control, because, well, then the recipient |
| 1:47.0 | believes that this is actually an already authenticated request that was authenticated by |
| 1:53.0 | some proxy. That's my guess at this point. Now, the string, the value being provided with |
| 1:59.1 | this app header is somewhat random. |
| 2:02.1 | It's always app dot. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

