SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 January 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, January 27th, 2006 edition of the Sands International Stormers. |
| 0:12.2 | Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:18.1 | And this episode is brought you by the sands.edu underwright certificate program |
| 0:22.9 | in Applied Cybersecurity. In Diaries today, we do have a new scanning pattern that apparently |
| 0:30.5 | is being used by a couple of IP addresses to scan our web honeypots. The trick here is that they're |
| 0:37.2 | adding PWD, the output of the commandpots. The trick here is that they're adding PWD, |
| 0:39.3 | the output of the command, actually, |
| 0:41.2 | the way it is being written here, |
| 0:43.2 | so not just the environment variable. |
| 0:46.6 | And the goal here is likely |
| 0:48.1 | that they are trying to make sort of dynamically |
| 0:50.5 | the path the web server is running in, |
| 0:53.5 | part of the URL. |
| 0:55.0 | I'm not to ensure how well this will actually work because that's usually the absolute path in the operating system, |
| 1:02.0 | while of course the path that are using as part URL is then mapped to specific like web route directories |
| 1:10.0 | inside the operating system systems directory structure. |
| 1:14.5 | So not sure if it will work, but, well, attackers always try new tricks. |
| 1:19.2 | And maybe there are some configurations where this will help the attacker find various |
| 1:26.0 | vulnerabilities or data leakage in files. |
| 1:29.8 | They're using this with a large number of different URLs, |
| 1:33.7 | but a lot of them are sort of these standard environment files and configuration files |
| 1:37.9 | that we have seen a lot over the last few years. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

