4.9 • 696 Ratings
🗓️ 20 March 2025
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, March 20th, |
0:03.1 | 2000-25 edition of the Sands and a Stormontas Stormcast. |
0:08.4 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:12.8 | Well, today I took a look at some Cisco smart licensing utility vulnerabilities. |
0:19.0 | There are two vulnerabilities that were patched September |
0:22.6 | last year. Now, shortly after the patch was released, there was also an exploit released. |
0:28.6 | And the exploit is pretty straightforward for this vulnerability. It was yet another of these |
0:35.9 | static credential vulnerabilities. |
0:38.7 | So really all you need to know in order to exploit the vulnerability is, well, what these |
0:43.4 | static credentials were. |
0:45.3 | And that's what a blog post that was published a couple days after the patch came out, |
0:52.2 | well, revealed. |
0:53.5 | Haven't really seen much exploitation of this vulnerability so far. |
0:58.9 | However, today I noticed that we got some significant scanning for this vulnerability, |
1:05.8 | for the particular URL being used. |
1:07.7 | And then when I looked at the complete request, they indeed used an authorization |
1:12.8 | header with these static credentials. This is part of what looks like some kind of botnet. |
1:20.4 | They're scanning for a number of other vulnerabilities. Some of these vulnerabilities are, |
1:26.3 | it's just looking for credentials, like things |
1:28.6 | like ENB files and such being leaked, but they're also looking interestingly for another |
1:35.5 | little bit odd sort of video recorder vulnerability, one of these security camera |
1:42.2 | recorders, also static credentials. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.