Podcast Detail

SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10032.mp3

Podcast Logo
Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Friday, July 31st, 2026
 edition of the SANS and at Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Master's Degree Program in Information
 Security Engineering. Today we have yet another diary from
 one of our undergraduate interns. These bachelor's
 degree students are working with our honeypots to look for
 new, exciting, interesting events. And well, in this
 case, Adam Kahn has found kind of an interesting event and
 that's a little bit more advanced hardware
 fingerprinting of the honeypot after it was compromised using
 a weak SSH password. Now typically these honeypots, if
 the attacker finds them valuable, are often used for
 crypto coin mining. And that may be the intent of this
 particular attack as well. A couple of interesting things
 here. It's looking very carefully at different
 hardware properties. So, for example, it's looking for an
 Nvidia video card. Maybe we'll soon see some of these attacks
 trying to use honeypots for AI training instead of crypto
 coin mining. It's also looking whether it has more than one
 gigabyte of RAM and whether the user it's connecting as
 can actually escalate privileges to root via sudo.
 So, this is a little bit more detailed fingerprinting than
 we saw in the past. We have seen sometimes crypto coin
 miners being deployed on very inadequate systems that didn't
 really mine any crypto coins. And maybe attackers are
 getting a little bit more discriminating here just to
 also attract less attention by hacking multiple devices and
 building these large botnet fleets that really don't
 provide any value. Now, these honeypot attacks, they often
 take advantage of well-known default passwords that are
 commonly associated with more low-end devices like DVRs and
 the like. And that's why they are a little bit more
 discriminating here, trying to find better hardware. Well,
 maybe they should be going after Cisco equipment. Cisco
 did patch Warner building their firewall management
 center. They call it a static user credential that they
 patched. Others call it a back door. Luckily, it only
 provides access to a low -privileged user account. But
 still, it's your firewall management center. So,
 basically, the software that you are trusting to manage all
 your firewalls. I'm sure the account is low-level enough
 where there's absolutely no possibility that any of the
 about dozen or so Unix and Linux approach escalation
 flaws apply to the particular operating system here. Cisco
 has released a patch for this vulnerability, but the
 vulnerability is also already being exploited in the wild.
 So, as usual, assume compromise. In particular, if
 access to the firewall management center is connected
 to the internet. And a paper going to be presented by
 several Austrian researchers at an upcoming USENIX security
 symposium is going to reveal some interesting
 vulnerabilities in end-to-end encrypted chat systems when it
 comes to group messages. Now, this is for a change, not a
 paper that talks about decrypting the messages or
 anything like that, but instead about how different
 participants in a group chat may intentionally be served
 different content. So, the threat is here that a
 malicious participant in the group chat is, for example,
 putting up some item for vote and is sending sort of
 different proposals to different participants in the
 group chat. And then, of course, everybody agrees to
 the proposal, but they don't realize that they agreed to
 very different things. So, the way this works is that there
 are two ways how group chats work. One is where the message
 is being sent to a server and then the server distributes
 these messages to individuals within the group chat. The
 problem with this, of course, is with end-to-end encryption
 that sort of puts the server here in a machine in the
 middle position. So, instead, some chat systems offer the
 option to send messages to each user individually from
 the sender. And then, of course, the sender has the
 option to send different messages to different
 recipients. As long as the message ID, so the message
 sequence essentially, is the same, this usually goes
 undetected according to the paper. Now, the full paper is
 not public yet. I'll link to the Usenix abstract and also
 to an article by Heise that does discuss this paper in
 more detail. Well, and that's it for today. Just the two
 small items here. There are updates for IBM WebSphere that
 you probably should take a look at. And then yet another
 flaw in NGINX, this time in HTTP 3. So, keep an eye for
 patches for either of these two products. And that's it
 for today. Thanks for listening. Thanks for
 subscribing. Thanks for liking this podcast and doing
 whatever you do in order to get us a couple more
 listeners. And talk to you again on Monday. Bye. Bye.
 Bye. Bye. Bye. Thank you.