SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 April 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, April 8, |
| 0:07.6 | 2006 edition of the Sands Internet Storms Centers. |
| 0:11.6 | Stormcast, my name is Johannes Ulrich, recording you today from Jacksonville, Florida. |
| 0:17.6 | And this episode is brought you by the Sands.edu graduate certificate program in cyber defense operations. |
| 0:25.0 | Now, today I did as the title of today's diary states a little bit of pivoting, looking for web shells. |
| 0:32.4 | I noticed four distinct IP addresses all associated interestingly with Microsoft's cloud |
| 0:38.9 | services that scanned our sensors for a specific web shell, turkshell.php. |
| 0:46.1 | Nothing that sort of fancy or special about this particular webshell, but web shells are sort |
| 0:51.5 | of the backdoor, the type of persistent mechanisms being deployed against vulnerable web applications, either with remote code execution or with an arbitrary file upload vulnerability. |
| 1:05.0 | And then they're not just used by the original attacker, but they're also parasitic attackers. |
| 1:10.2 | And that's apparently |
| 1:10.8 | what we have here that are looking for pre-installed web shells and are trying to exploit them, |
| 1:16.7 | because attackers often don't pick strong passwords either. And that's what I then looked in. |
| 1:23.3 | Further looked at those four IP addresses and what other URLs they were scanning and turned |
| 1:30.4 | out, well, it was over 200 different URLs they looked for. All of them apparently associated |
| 1:37.9 | with web shells. There were a couple in there where I think they looked for war on abilities |
| 1:42.6 | or really just did some fingerprinting |
| 1:44.9 | on the site to see maybe what particular web shell may be present. |
| 1:50.2 | One of the things here, one of the themes in the file names was also that many of them |
| 1:55.5 | tried to sort of fit in with WordPress websites. |
| 1:59.9 | And well, that's no surprise with all the WordPress vulnerabilities around these days. |
| 2:05.1 | And of course, that being sort of a favorite attacker target. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

