Podcast Detail

SANS Stormcast Tuesday, October 6th, 2026: cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10124.mp3

Podcast Logo
cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Tuesday, October 6, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Bachelor's Degree Program in Applied
 Cybersecurity. And in today's diary, Guy is taking a look at
 the Kaori TTY Logs. So these TTY Logs essentially capture
 the interaction of the attacker with the honeypot.
 And Kaori comes with some neat tools to, for example, play
 them back. That's one of the tools, at least when I first
 started working with Kaori, I thought was real neat and
 helpful. But if you have a lot of logs, as you tend to have,
 if you're running the honeypot for a while, then you probably
 want to query them a little more efficiently in
 summarizing them. And that's what Guy is going over here.
 Now Guy is creating and maintaining this scene that's
 sort of part of our honeypot. It uses Elasticsearch, so we
 can use Elasticsearch queries to basically figure out what
 is happening. One type of command that attackers really
 like is playing and manipulating the cron tab. So
 what that's usually used for is, first of all, to figure
 out if there are any cron jobs already running for particular
 users. That could indicate a prior compromise or could be
 abused, but also to gain persistence on a system.
 Attackers love to schedule cron jobs. So that's sort of
 one of the things that Guy is looking at. And then also some
 of the other events that were created in the TTY Logs, like,
 for example, attackers fingerprinting honeypots or
 changing the environment to suit their purposes. Also,
 another very common thing that's being done by attackers
 is trying to remove competing scripts from prior
 compromises. It's also a repeating pattern in these TTY
 Logs. So if you're running Cowry, if you're interested in
 what Guy is doing here with Elasticsearch and such, well,
 take a look at the diary from today. And following with our
 motto for the last few episodes that every day is
 zero day, it's Netscaler's turn again. Yes, I double
 -checked. It's a new vulnerability in Netscaler.
 This time only denial of service. It's not a remote
 code execution or an authentication bypass issue,
 even though it does affect SAML. So if you have Citrix
 Netscaler configured as a SAML identity provider or as a
 relying party, you may be vulnerable. And yes, it's
 already exploited. It doesn't state so in the advisory, but
 Citrix did publish a separate blog post with a couple of
 additional details. It is a buffer overflow, but then
 again, not all buffer overflows are exploitable for
 an actual remote code execution, but often then lead
 to a denial of service. So this does make sense. Anyway,
 double-check and yes, patch Netscaler again. And Microsoft
 on Friday published another update for Exchange. They call
 this the September 2026 version 2 update, and it does
 patch one more vulnerability that didn't get covered in the
 September patch Tuesday update. Now, there's one
 vulnerability again that's being addressed here. This
 vulnerability is a privilege escalation vulnerability that
 is being addressed. It's not yet exploited, but it states
 in the notes about this vulnerability that
 exploitation or exploitability is more likely for this
 vulnerability. So it's not that terribly difficult to
 exploit it. Definitely get taken care of this. Of course,
 patching Exchange can always be a little bit tricky. They
 also mention, I think, some issues with calendar files
 that this update introduces. So there's some known issues
 here that you should review before applying the update.
 And then last week, we also got a Debian Linux update, and
 I didn't cover it back then. I usually don't cover these
 updates, but I want to give it at least of an honorable
 mention because a couple of listeners have asked about
 this. I think it's 1,300 -something vulnerabilities
 being updated with this particular patch. A lot of
 these are basically Linux kernel patches that they are
 porting now into the Debian distribution. They also
 announced, I think it was a little bit longer, that
 they're going to release more frequent kernel updates,
 which, of course, may require more frequent system reboots.
 So keep that in mind as you're applying these updates. Well,
 and that's it for today. So thanks again for listening.
 Thanks for liking. Thanks for subscribing. And special
 thanks for everybody who is leaving comments about this
 podcast in your favorite podcast platform. Don't
 forget, we are available on YouTube if you like the video
 format. And also like Amazon Alexa and a couple other
 outlets. Still working on the Google Music podcast. They
 have some issues because there's also a YouTube channel
 associated with it. So still trying to work this out.
 Thanks and talk to you again tomorrow. Bye. Bye.
 Bye. Bye.