4.9 • 696 Ratings
🗓️ 26 March 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, March 26th, 2025 edition of the Sands Internet Storm Center's Stormcast. |
0:08.9 | My name is Johannes Ulrich, and today I am recording from Jacksonville, Florida. |
0:14.8 | Well, today in Diaries we do have an interesting one, a billy that I saw being exploited. |
0:20.9 | It affects ex-Wiki. |
0:23.6 | Wikis, of course, are always dangerous. |
0:26.4 | However, the vulnerability being exported here is not in a feature that's commonly |
0:31.9 | associated with dangerous like uploading files or allowing users to edit a page. |
0:39.9 | It's in the search feature. |
0:42.8 | And in this case, actually, the search feature is open to remote code execution. |
0:50.0 | The problem is that this particular wiki, and again, we're talking about XWiki here, is written in Java, and it does allow for output rendering transformations. |
1:01.6 | The idea behind this is that part of the wiki code is essentially these templates, and then as they're being sent to the user, well, they're being parsed. |
1:12.2 | That's how these rendering transformations are being applied. |
1:15.9 | But in the search feature, the search string also was subject to these rendering transformations. |
1:22.9 | So if you searched for a crewvy in this case, code snippet, well, that code was actually then |
1:30.1 | parsed as the data was returned to the user, and that led to the remote code execution. |
1:37.4 | The vulnerability is about a year old. |
1:41.8 | I haven't seen a lot of exploitation against it. |
1:44.5 | Just sort of now sort of bubbled to the top. |
1:48.0 | Early expectations were like about in June, |
1:51.3 | but only sort of individual hits against our honeypots, |
1:55.8 | which sort of didn't make it to our threshold |
1:58.7 | where we sort of consider it something new and noteworthy. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.