Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: SANS Daily Network Security Podcast (Stormcast) for Tuesday, November 10th 2015 - SANS Internet Storm Center SANS Daily Network Security Podcast (Stormcast) for Tuesday, November 10th 2015


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

ISC StormCast for Tuesday, November 10th 2015

SANS Daily Network Security Podcast (Stormcast) for Tuesday, November 10th 2015
00:00

My Next Class

Intrusion Detection In-DepthLondonSep 23rd - Sep 28th 2019
Intrusion Detection In-DepthChicagoOct 9th - Oct 14th 2019

… more classes

Java Deserialization Vulnerability in commons-collections Framework
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#thefix

Crypto Ransomware For Linux
https://news.drweb.com/show/?i=9686&lng=en&c=14

Comodo Revoking Certificates for "Internal" Hostnames
https://cabforum.org/pipermail/public/2015-November/006226.html Get a free ISC sticker (login required):
https://isc.sans.edu/sticker.html
Spotify spotify logo

Discussion

From Dr Web's article it is unclear whether a) the Linux Crypto Ransomware uses a single AES keys or multiple ones and b) it runs only with administrative privileges (which seems to be the case). Anyone knows? The good practice to run with limited privileges and only assign ownership/rights to the running daemon user when/if needed would prevent this malware in the first place. On a side note, Krebs reports that the decryption process of Linux.Encoder.1 left few bogus characters behind on some files.
Posted by Enos on Tue Nov 10 2015, 04:33

New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form

Intrusion Detection In-DepthLondonSep 23rd - Sep 28th 2019
Intrusion Detection In-DepthChicagoOct 9th - Oct 14th 2019
Intrusion Detection In-DepthSanta MonicaOct 21st - Oct 26th 2019
Defending Web Applications Security EssentialsSan FranciscoDec 2nd - Dec 7th 2019
Defending Web Applications Security EssentialsSan FranciscoMar 16th - Mar 21st 2020
Defending Web Applications Security EssentialsAmsterdamMay 11th - May 16th 2020