4.9 • 696 Ratings
🗓️ 1 October 2025
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, October 1st, 2025 edition of the Sands Internet Storms Centers. |
| 0:11.8 | Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:18.2 | And this episode is brought you by the sands.edu graduate certificate program in |
| 0:22.8 | Purple Team Operations. When teaching our defensive web application security class, SAC |
| 0:29.4 | 522, one of the things, of course, that always comes up is mistakes in off-occation |
| 0:35.5 | and access controls. And one of the examples that is always mentioned here are, well, simple cookies like |
| 0:42.2 | user equals admin. |
| 0:44.7 | So wanted to put this to the test to see how relevant this issue still is and looked at |
| 0:50.7 | some of our honeypots and what kind of cookies like this we are seeing in the honeypot |
| 0:56.4 | and well how often they're exploited certainly exploited quite a bit and the exploits or the |
| 1:04.1 | vulnerabilities being associated with these particular cookies are actually not that super old. |
| 1:12.8 | Like the first one here, UID equals 1, |
| 1:15.6 | goes with DVR vulnerability that was originally described about a year ago. |
| 1:22.7 | You also have this user equals admin a little bit older. |
| 1:27.3 | Many of these, of course, are IoT style vulnerabilities, so DVRs and |
| 1:33.5 | wireless access points, routers, and the like. |
| 1:36.9 | There are a couple interesting ones. |
| 1:38.5 | Like, there is the admin ID equals one GW admin ticket equals one, |
| 1:46.2 | I believe that one was from a Chinese VPN |
| 1:49.6 | that apparently can be administered using this particular cookie. |
| 1:55.4 | And then we also have the CMX saved ID cookies. |
| 2:00.4 | These are actually apparently associated with a biometric security system. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.