SANS Stormcast Thursday, March 19th, 2026: Adminer Scans; Apple WebKit Patch; another telnetd vuln; screenconnect vuln
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 March 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, March 19th, |
| 0:07.3 | 2006 edition of the Sands and the Storms Center's Stormcast. |
| 0:11.9 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:16.7 | And this episode is brought you by the Science.edu graduate certificate program in penetration |
| 0:21.8 | testing and ethical hacking. In diaries today, I wrote up scans that we're seeing against our |
| 0:28.9 | honeypots against Adminor. Adminor is a PhD script that allows you to administer your database. |
| 0:36.1 | It works for MySQL and Postgres, I believe. |
| 0:40.1 | And it's similar in its approach, kind of, to PHP My Admin. |
| 0:44.3 | If you're familiar with PHP My admin, |
| 0:47.2 | it's one of the big targets out there, |
| 0:50.1 | had a very rich history of vulnerabilities. |
| 0:53.7 | And it's sort of not the first and original web-based database admin tool. |
| 1:00.1 | Adminer takes a different approach and so far that it's just one PHP file. |
| 1:06.0 | It's very feature-rich and has actually a pretty good security history. |
| 1:10.6 | There have been a couple of vulnerabilities, but far less and the far lower in severity than what |
| 1:16.4 | we have with PHP My Admin. |
| 1:18.7 | So why are attackers scanning for it? |
| 1:21.4 | Well, the weakness that we still have is passwords. |
| 1:24.7 | Now, Adminer does not really have the user, usually set up passwords for the tool |
| 1:30.4 | itself. Instead, it just uses the databases access control system, and that actually makes |
| 1:36.8 | quite a bit of sense. It even offers an optional module that allows you to have some two-factor |
| 1:43.1 | authentication, and that's something you should definitely consider, even though it deviates module that allows you to have some two-factor authentication. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

