Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
ISC StormCast for Tuesday, November 10th 2015
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/4739.mp3
My Next Class
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
Java Deserialization Vulnerability in commons-collections Framework
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#thefix
Crypto Ransomware For Linux
https://news.drweb.com/show/?i=9686&lng=en&c=14
Comodo Revoking Certificates for "Internal" Hostnames
https://cabforum.org/pipermail/public/2015-November/006226.html
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#thefix
Crypto Ransomware For Linux
https://news.drweb.com/show/?i=9686&lng=en&c=14
Comodo Revoking Certificates for "Internal" Hostnames
https://cabforum.org/pipermail/public/2015-November/006226.html
Discussion
From Dr Web's article it is unclear whether a) the Linux Crypto Ransomware uses a single AES keys or multiple ones and b) it runs only with administrative privileges (which seems to be the case). Anyone knows? The good practice to run with limited privileges and only assign ownership/rights to the running daemon user when/if needed would prevent this malware in the first place. On a side note, Krebs reports that the decryption process of Linux.Encoder.1 left few bogus characters behind on some files.
Posted by Enos on Tue Nov 10 2015, 04:33
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Network Monitoring and Threat Detection In-Depth | Baltimore | Mar 3rd - Mar 8th 2025 |
Application Security: Securing Web Apps, APIs, and Microservices | Orlando | Apr 13th - Apr 18th 2025 |