Episode 375: Surprise Root Access




TechSNAP show

Summary: <p>Google's Cloud Platform suffers an outage, and iPhones in India get owned after a very specific attack.</p> <p>Plus how a malware author built a massive 18,000 strong Botnet in one day, and Cisco finds more "undocumented" root passwords.</p><p>Sponsored By:</p><ul> <li> <a rel="nofollow" href="http://techsnap.ting.com">Ting</a>: <a rel="nofollow" href="http://techsnap.ting.com">Save $25 off a device, or get $25 in service credits!</a> Promo Code: Visit techsnap.ting.com</li> <li> <a rel="nofollow" href="http://ixsystems.com/techsnap">iXSystems</a>: <a rel="nofollow" href="http://ixsystems.com/techsnap">Get a system purpose built for you.</a> Promo Code: Tell them we sent you!</li> <li> <a rel="nofollow" href="https://do.co/snap">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/snap">Apply our promo snapocean after you create your account, and get a $10 credit.</a> Promo Code: snapocean</li> </ul><p>Links:</p><ul> <li><a title="Cisco Removes Undocumented Root Password From Bandwidth Monitoring Software" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/cisco-removes-undocumented-root-password-from-bandwidth-monitoring-software/">Cisco Removes Undocumented Root Password From Bandwidth Monitoring Software</a></li> <li><a title="Google Cloud Platform reports issues; Snapchat and other popular apps affected" rel="nofollow" href="https://www.cnbc.com/2018/07/13/google-cloud-platform-reports-issues-snap-and-other-popular-apps-affe.html">Google Cloud Platform reports issues; Snapchat and other popular apps affected</a></li> <li><a title="Google Cloud Status Dashboard" rel="nofollow" href="https://status.cloud.google.com/incident/cloud-networking/18012?m=1">Google Cloud Status Dashboard</a></li> <li><a title="Bogus Mobile Device Management system used to hack iPhones in India • The Register" rel="nofollow" href="https://www.theregister.co.uk/2018/07/13/bogus_mdm_iphone_snooping_india/">Bogus Mobile Device Management system used to hack iPhones in India • The Register</a></li> <li><a title="A major election software maker allowed remote access on its systems for years - The Verge" rel="nofollow" href="https://www.theverge.com/2018/7/17/17582818/election-software-maker-remote-access-voting-machine">A major election software maker allowed remote access on its systems for years - The Verge</a></li> <li><a title="Router Crapfest: Malware Author Builds 18,000-Strong Botnet in a Day" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/router-crapfest-malware-author-builds-18-000-strong-botnet-in-a-day/">Router Crapfest: Malware Author Builds 18,000-Strong Botnet in a Day</a></li> <li><a title="Anian wants to lean better backup" rel="nofollow" href="https://pastebin.com/JKCVLWwA">Anian wants to lean better backup</a></li> <li><a title="How To Choose an Effective Backup Strategy for your VPS | DigitalOcean" rel="nofollow" href="https://www.digitalocean.com/community/tutorials/how-to-choose-an-effective-backup-strategy-for-your-vps">How To Choose an Effective Backup Strategy for your VPS | DigitalOcean</a></li> <li><a title="Tarsnap - Online backups for the truly paranoid" rel="nofollow" href="http://www.tarsnap.com/">Tarsnap - Online backups for the truly paranoid</a></li> <li><a title="Borg Documentation — Borg - Deduplicating Archiver 1.1.6 documentation" rel="nofollow" href="https://borgbackup.readthedocs.io/en/stable/">Borg Documentation — Borg - Deduplicating Archiver 1.1.6 documentation</a></li> <li><a title="borgmatic" rel="nofollow" href="https://torsion.org/borgmatic/">borgmatic</a></li> <li><a title="duplicity: Main" rel="nofollow" href="http://duplicity.nongnu.org/">duplicity: Main</a></li> <li><a title="restic · Backups done right!" rel="nofollow" href="https://restic.net/">restic · Backups done right!</a></li> </ul>