In Episode 367, Ben and Scott kick off 2024 with a discussion of Azure Files. They start out reviewing a customer scenario Ben encountered and how they would approach it, breaking down the options available with Azure Files, hosting traditional SMB shares in Azure, and how a hybrid deployment can Read More
Interesting large and small malspam attachments from 2023 https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524 Orange Spain RIPE Account Compromise https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/ Bitwarden Heist https://blog.redteam-pentesting.de/2024/bitwarden-heist/ Apple iOS PoC Exploits https://github.com/felix-pb/kfd/blob/main/writeups/smith.md https://github.com/felix-pb/kfd/blob/main/writeups/landa.md
Fingerprinting SSH Identification Strings https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520 Google OAUTH2 Exploited by Malware https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking TsuKing DNS Amplification https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf
Shall We Play a Game https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510 Mailtrap.io Exfiltration https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512 Pi Hole Docker https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/ Mirai Update https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514 Barracuda 0-Day Vulnerability https://www.barracuda.com/company/legal/esg-vulnerability Apache OFBiz 0-Day Exploited against Atlassian (and possibly others) https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/
In this episode, Ben and Scott touched on some updates on their social media presence due to some recent happenings in the social media services space. As they transition into the Microsoft cloud world, they discuss updates to cloud computing software and user experience design. They also provided some insight Read More
Securing Web Servers https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504 Chrome 0-Day (last one for the year?) https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html Note that there will be no daily stormcast for the rest of the year. Returning January 2nd SANS Cloud Defender 2024 https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/
In Episode 365, Ben and Scott break away from tech news to talk about some of their favorite gadget purchases in the past year. If you (or a geek in your life) are looking for ways to spend those Christmas gift cards or you need some last-minute ideas, give them Read More
Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518) https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502 Fake F5 BigIP Update https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/ Google OAUTH Problems https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/ Remembering Adrien de Beaupre https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php
What are they looking for? Scans for OpenID Connect Configuration https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498 Terrapin Attack Against SSH https://terrapin-attack.com/TerrapinAttack.pdf ALPHV/Blackcat Ransomware Disrupted and Decryptor Available https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant
An Example of a RocketMQ Exploit Scanner https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492 C# Payload Phoning to a Cobalt Strike Server https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490 3CX SQL Injection Vulnerability https://www.3cx.com/blog/news/sql-database-integration/ QNAP Viostor 0-Day Vulnerablity https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched PFSense Vulnerability https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/ SANS Holiday Hack Challenge https://sans.org/holidayhack
T-shooting Terraform for DShield Honeypot in Azure https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484 Ubiquity Unifi Cameras Visible in Wrong Account https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7 Zoom Vulnerabilities and VISS https://viss.zoom.com/specifications https://www.zoom.com/en/trust/security-bulletin/ Squid Denial of Service Vulnerability https://github.com/squid-cache/squid/security/advisories/GHSA-wgq4-4cfg-c4x3
In Episode 364, Ben and Scott discuss the recently announced Microsoft Designer, cover a handful of updates to Azure including Azure Automation and Azure Container Storage. Then they close out with some updates to the licensing model for Enterprise IoT Security. It’s also the season of giving and we’re raising Read More
What is Sitemap.xml and Why a Pentester Should Care https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472 Apple Patches Everything https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/ Android Password Manager Auto Spill https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf
5G Vulnerabilities https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462 Revealing the hidden Risks of QR Codes https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458 Window 10 End of Support https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414 Apache Struts 2 Vulnerability CVE-2023-50164 https://cwiki.apache.org/confluence/display/WW/S2-066
In Episode 363, Ben and Scott talk through some new hibernation capabilities coming to an Azure VM near you and the announced retirement of SharePoint Add-Ins. It’s also the season of giving and we’re raising money for Girls Who Code. Donate today at https://give.girlswhocode.com/msclouditpro! Like what you hear and want Read More