Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
News
Sports
TV & Film
About Us
Contact Us
Copyright
© 2024 PodJoint
Podjoint Logo
US
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts115/v4/91/b3/13/91b31340-a5c8-6d25-c507-f942d747f120/mza_15667677748836834730.jpeg/600x600bb.jpg
HackableYou Podcast
HackableYou
44 episodes
1 day ago
Welcome to the HackableYou Podcast! Join us as we sit down, crack open a beer and delve into the topic of cyber security. With insights into Cyber News, Threat Intelligence, Incident Response and general SOC shenanigans. We aim to inform, educate and entertain all of our listeners whether you are a CISO, Security Engineer/Analyst or are just curious on the topic. All that is left for you to do now is sit back, follow or subscribe and enjoy the HackableYou Podcast!
Show more...
Technology
RSS
All content for HackableYou Podcast is the property of HackableYou and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
Welcome to the HackableYou Podcast! Join us as we sit down, crack open a beer and delve into the topic of cyber security. With insights into Cyber News, Threat Intelligence, Incident Response and general SOC shenanigans. We aim to inform, educate and entertain all of our listeners whether you are a CISO, Security Engineer/Analyst or are just curious on the topic. All that is left for you to do now is sit back, follow or subscribe and enjoy the HackableYou Podcast!
Show more...
Technology
https://d3t3ozftmdmh3i.cloudfront.net/staging/podcast_uploaded_nologo/5811726/949f727563f8a972.jpeg
Exchange Vulns, A Passwordless Future, SOC Stand-ups
HackableYou Podcast
29 minutes 21 seconds
4 years ago
Exchange Vulns, A Passwordless Future, SOC Stand-ups

In this episode of the HackableYou Podcast:

We look at the ex-CEO of SolarWinds blame for the hack on an intern with a weak password, the Malaysia Airlines 9 year-long data breach, and the new critical Microsoft Exchange vulnerability actively being exploited by Chinese hackers.

In Topicpic of The Week, we debate the idea that passwords are not here to stay and what the concept of Passwordless authentication means for the future.

Lastly in our exclusive segment, Secrets from the SOC we discuss the importance of daily and routine standups or huddles when working in high-performing security teams and operations centers. 


Timestamps:

Cyber News: 02:34

Topic of The Week: 13:52

SFTS: 22:54


CVE Details:

CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Exchange that allowed the attacker to send arbitrary HTTP requests and authenticate as the Exchange server.

CVE-2021-26857 is an insecure deserialization vulnerability in the Unified Messaging service. Insecure deserialization is where untrusted user-controllable data is deserialized by a program. Exploiting this vulnerability gave HAFNIUM the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.

CVE-2021-26858 is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

CVE-2021-27065 is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

HackableYou Podcast
Welcome to the HackableYou Podcast! Join us as we sit down, crack open a beer and delve into the topic of cyber security. With insights into Cyber News, Threat Intelligence, Incident Response and general SOC shenanigans. We aim to inform, educate and entertain all of our listeners whether you are a CISO, Security Engineer/Analyst or are just curious on the topic. All that is left for you to do now is sit back, follow or subscribe and enjoy the HackableYou Podcast!