Artwork

Content provided by Tenable Network Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Tenable Network Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Tenable Network Security Podcast - Episode 197

 
Share
 

Archived series ("Inactive feed" status)

When? This feed was archived on September 23, 2018 01:22 (5+ y ago). Last successful fetch was on October 12, 2017 15:13 (6+ y ago)

Why? Inactive feed status. Our servers were unable to retrieve a valid podcast feed for a sustained period.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 189345741 series 1644749
Content provided by Tenable Network Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Tenable Network Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Telephony DoS - I read an interesting article that detailed an attack that used a combination of social engineering and a DoS attack against your phone system. The attacker calls the victim and asks about up paid debt. Whether you have debt or not, the attacker insists on payment. If you refuse, a DoS attack is launched against your phone systems using combination of cheap labor and VoIP phones. Interesting how one defends against this attack.

MediaWiki Vulnerability - There are actually two vulnerabilities in MediaWiki versions < 1.19.11 / 1.21.5 / 1.22.2. Yikes, this is widely deployed software, according to the reports from Checkpoint "Wikipedia.org is the sixth most-visited web site in the world, with over 94 million unique visitors per month and almost 2 million sites linking to it. " This is a vulnerability to seek out and patch in your own environment, who knows who may have installed this software and forgotten about it, giving attackers a foothold in your network. The two features that suffer from the vulnerability are not enabled by default, though I am unclear exactly which features these relate to. I've run MediaWiki for about 5 years, done several upgrades, and they are pretty painless.

  continue reading

210 episodes

Artwork
iconShare
 

Archived series ("Inactive feed" status)

When? This feed was archived on September 23, 2018 01:22 (5+ y ago). Last successful fetch was on October 12, 2017 15:13 (6+ y ago)

Why? Inactive feed status. Our servers were unable to retrieve a valid podcast feed for a sustained period.

What now? You might be able to find a more up-to-date version using the search function. This series will no longer be checked for updates. If you believe this to be in error, please check if the publisher's feed link below is valid and contact support to request the feed be restored or if you have any other concerns about this.

Manage episode 189345741 series 1644749
Content provided by Tenable Network Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Tenable Network Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Telephony DoS - I read an interesting article that detailed an attack that used a combination of social engineering and a DoS attack against your phone system. The attacker calls the victim and asks about up paid debt. Whether you have debt or not, the attacker insists on payment. If you refuse, a DoS attack is launched against your phone systems using combination of cheap labor and VoIP phones. Interesting how one defends against this attack.

MediaWiki Vulnerability - There are actually two vulnerabilities in MediaWiki versions < 1.19.11 / 1.21.5 / 1.22.2. Yikes, this is widely deployed software, according to the reports from Checkpoint "Wikipedia.org is the sixth most-visited web site in the world, with over 94 million unique visitors per month and almost 2 million sites linking to it. " This is a vulnerability to seek out and patch in your own environment, who knows who may have installed this software and forgotten about it, giving attackers a foothold in your network. The two features that suffer from the vulnerability are not enabled by default, though I am unclear exactly which features these relate to. I've run MediaWiki for about 5 years, done several upgrades, and they are pretty painless.

  continue reading

210 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide