Podcast Detail

SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10018.mp3

Podcast Logo
Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Wednesday July 22nd, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Bachelor's degree program in Applied
 Cybersecurity. Well today I figured let's move away from
 WordPress if you are running it if you aren't patched that
 you're compromised and well with that move on to something
 well less threat related and that's how different operating
 systems do detect if they are behind a captive portal.
 Anybody who has ever used any kind of public Wi-Fi network
 probably has observed these captive portals some kind of
 login screen that you have to go through in order to connect
 to the internet. So to support this very common practice
 operating systems and browsers have implemented a couple
 different methods how they are detected if they are behind
 such a captive portal and then of course also how to direct
 the user to the correct URL in order to sign in. This traffic
 sometimes shows up sort of as odd and unexplained traffic in
 the network because users don't really consciously visit
 these URLs. It's also HTTP traffic because for the
 captive portal to then redirect the user well can't
 be HTTPS because then the certificate check would fail.
 So summarized here a couple of the URLs being used by the
 major operating systems as well as Firefox and Chrome who
 do sort of their own little trick in order to figure out
 if they are behind such a captive portal. And then we
 got an interesting update from SolarWinds for their Serv-U
 product. This update does fix 16 different vulnerabilities.
 15 of them so all but one are rated critical with a CVSS
 score of 9.1. The one vulnerability that I think is
 particularly interesting is 2026 28304. It's an arbitrary
 code execution vulnerability. And for all the other
 vulnerability it states that the user must be like
 administrator access or must have a domain account or like
 well nothing like this in this particular vulnerability. So I
 assume it's unauthenticated and it allows execution of
 code remotely as root. They're saying the impact is lower for
 Windows deployments. I'm not really that familiar with Serv-U
 to know what the difference here is. Obviously
 there is no root user on Windows. Maybe they have a
 little bit more privilege separation or such to not
 become an administrator on Windows. But definitely you
 must apply this update if you have SolarWinds Serv-U
 exposed given how quickly attackers are these days
 developing new exploits. An open source webmail project
 Zimbra did release a new update to its product. This
 update fixes a number of interesting security
 vulnerabilities. The most critical one here is a command
 injection vulnerability in the SNMP monitoring component. Now
 in order to be vulnerable you have to actually enable SNMP
 notifications and this was already disclosed like back in
 June but now is rolled into this update. I hope you don't
 allow SNMP in and out of your network but well I've seen
 worse things happening in the past. So that's I think the
 first thing you should check and then definitely apply this
 update. The other updates are a number of cross-site
 scripting issues which are always interesting and
 exploitable often for these kind of webmail systems. In
 particular if the export can be delivered via an email. The
 other vulnerabilities I don't really consider that
 extraordinary dangerous because many of them or all
 the others really require some kind of authenticated access.
 And a couple of weeks ago I did mention that Apple's Hide
 My Email system had a vulnerability that leaked the
 actual user's email address if an oversized email was sent to
 the Hide My Email address. Well a 404 media who
 originally reported about this vulnerability now states that
 the vulnerability has been fixed. Apparently it has
 already been fixed a couple weeks ago there was no
 official announcement about this from Apple but 404 media
 now was able to confirm it's fixed. Well and this is it for
 today so thanks for listening, thanks for liking, thanks for
 subscribing and sharing to this podcast and as always
 talk to you again tomorrow. Bye!