Episode 359: Netflix’s Dark Capacity




TechSNAP show

Summary: <p>Netflix has a few tricks we can learn from, and the story of clever malware that was operating undetected since 2012. </p> <p>Plus we discuss Let's Encrypt’s Wildcard support and explain what ACME v2 is.</p> <p>Then we detail the bad position Samba 4 admins are in, and the real cause of these recent 1.7Tbps DDoS attacks.</p><p>Sponsored By:</p><ul> <li> <a rel="nofollow" href="http://techsnap.ting.com">Ting</a>: <a rel="nofollow" href="http://techsnap.ting.com">Save $25 off a device, or get $25 in service credits!</a> Promo Code: Visit techsnap.ting.com</li> <li> <a rel="nofollow" href="https://do.co/snap">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/snap">Apply our promo snapocean after you create your account, and get a $10 credit.</a> Promo Code: snapocean</li> <li> <a rel="nofollow" href="http://ixsystems.com/techsnap">iXSystems</a>: <a rel="nofollow" href="http://ixsystems.com/techsnap">Get a system purpose built for you.</a> Promo Code: Tell them we sent you!</li> </ul><p>Links:</p><ul> <li> <a title="Hardcoded Password Found in Cisco Software" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/hardcoded-password-found-in-cisco-software/">Hardcoded Password Found in Cisco Software</a> — Cisco says that an attacker could exploit this vulnerability (CVE-2018-0141) by connecting to the affected system via Secure Shell (SSH) using the hardcoded password.</li> <li> <a title="Potent malware that hid for six years spread through routers " rel="nofollow" href="https://arstechnica.com/information-technology/2018/03/potent-malware-that-hid-for-six-years-spread-through-routers/">Potent malware that hid for six years spread through routers </a> — "The malware is highly advanced, solving all sorts of problems from a technical perspective and often in a very elegant way, combining older and newer components in a thoroughly thought-through, long-term operation, something to expect from a top-notch well-resourced actor."</li> <li> <a title="CVE 2018-1057: Authenticated Samba users can change other users' password " rel="nofollow" href="https://www.samba.org/samba/security/CVE-2018-1057.html">CVE 2018-1057: Authenticated Samba users can change other users' password </a> — On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).</li> <li> <a title="CVE-2018-1057 - SambaWiki Workarounds " rel="nofollow" href="https://wiki.samba.org/index.php/CVE-2018-1057#Workarounds">CVE-2018-1057 - SambaWiki Workarounds </a> — Revoke the change passwords right for 'the world' from all user objects (including computers) in the directory, leaving only the right to change a user's own password.</li> <li> <a title="ACME v2 and Wildcard Certificate Support is Live" rel="nofollow" href="https://community.letsencrypt.org/t/acme-v2-and-wildcard-certificate-support-is-live/55579">ACME v2 and Wildcard Certificate Support is Live</a> — We’re pleased to announce that ACMEv2 and wildcard certificate support is live! </li> <li> <a title="It just got much easier to wage record-breaking DDoSes " rel="nofollow" href="https://arstechnica.com/information-technology/2018/03/it-just-got-much-easier-to-wage-record-breaking-ddoses/">It just got much easier to wage record-breaking DDoSes </a> — Within days of the new technique going public, security firms reported it being used in a record-setting 1.3 terabit-per-second DDoS against Github and then, two days later, a record-topping 1.7 Tbps attack against an unnamed US-based service provider.</li> <li> <a title="The real cause of large DDoS " rel="nofollow" href="https://blog.cloudflare.com/the-root-cause-of-large-ddos-ip-spoofing/">The real cause of large DDoS </a> — All the gigantic headline-grabbing attacks are what we call "L3" (Layer 3 OSI[1]). This kind of attack has a common trait - the malicious software sends as many packets as possible onto the network. </li> <li> <a title="Project Nimble – Netflix TechBlog" rel="nofollow" href="https://medium.com/netflix-techblog/project-nimble-region-evacuation-reimagined-d0d0568254d4">Project Nimble – Netflix TechBlog</a> — We set ourselves an aggressive goal of being able to fail over traffic in less than 10 minutes. </li> <li><a title="Follow Up: Alex has a tip for Alex" rel="nofollow" href="https://pastebin.com/g97N8teu">Follow Up: Alex has a tip for Alex</a></li> <li><a title="Question: Oliver asks about a fail2ban replacement " rel="nofollow" href="https://pastebin.com/wrGGUyBp">Question: Oliver asks about a fail2ban replacement </a></li> <li> <a title="S3Scanner" rel="nofollow" href="https://github.com/sa7mon/S3Scanner">S3Scanner</a> — Scan for open S3 buckets and dump </li> <li><a title="Chromium is also a Snap" rel="nofollow" href="https://snapcraft.io/chromium">Chromium is also a Snap</a></li> </ul>