Johannes Ullrich, Ph.D.
banner
jullrich.bsky.social
Johannes Ullrich, Ph.D.
@jullrich.bsky.social
Collector of logs, packets, and malware. Dean of Research at SANS.edu. Go Sentinels!
SharePoint exploitation has entered the parasitic phase. We are seeing hits to >100 distinct possible web shell URLs. Some of them may just be guesses.
Sample:
spininstall[0-9].aspx,spinstallx.aspx,Error404.1.aspx,info3.aspx,error.aspx

spinstall0.thank_you_defeners_for_rapid_response.aspx :)
July 24, 2025 at 2:10 PM
My presentation in San Diego tonight will be streamed online: sans.org/webcasts/dev...

Developers, Developers, Developers: Three Ways How Your Software Supply Chain is Attacked
SANS Security West 2025: SANS@Night - Developers, Developers, Developers: Three Ways How Your Software Supply Chain is Attacked | SANS Institute
Several attacks are explicitly targeting developers. In this presentation, you will learn how developers are exposed to these attacks and why it is difficult to recognize and prevent them.
sans.org
May 6, 2025 at 10:43 PM
To whoever uses the username "/usr/share/wordlists/logins.txt" to attempt to log in to our honeypots: You are using your brute forcing tool wrong! :) [at least use a file in your home directory so we can see your username... probably root?]
April 6, 2025 at 7:26 PM
Happy 50th Birthday, Microsoft, and thanks for all the vulnerabilities over the years that have helped me pay many of my bills!
April 4, 2025 at 5:47 PM
Reposted by Johannes Ullrich, Ph.D.
March 14, 2025 at 6:33 PM
Some spam just makes you shake your head... what are they selling? IoT parenting solutions? There is an "Infant Industry"??
February 25, 2025 at 5:21 PM
Scanning my news feed: Buffer overflows are a thing, Mirai is attacking routers, and SSL VPN gateway flaws are attacked. Come on: give me something to work with, give me hope! Can I get at a cool SSRF vuln? A Unicode encoding mistake? An IPv6 problem? SOMETHING TO PROVE THAT THAT ANYBODY CARES!!
February 12, 2025 at 5:12 PM
16 years ago, I started the daily SANS Internet Storm Center Stormcast. Over 16 years, I recorded about 3,900 episodes and 26,000 minutes of content (sounds more impressive than 16 days :) ).

Subscribe to it wherever you find podcasts. (or Alexa Flash Briefings, YouTube)

isc.sans.edu/podcast.html
February 10, 2025 at 2:02 PM
Just noted this fun memorabilia in my GIAC certification history. Who remembers Track 1 ? Also got a Track 2 (Firewalls) ;-)
February 4, 2025 at 6:48 PM
First time seeing this, one day before the expected TikTok shut down. Final attempts to monetize soon to be obsolete scripts? Anything else behind these obvious scams?
January 16, 2025 at 2:05 PM
The vulnerability Yee Ching wrote about in today's diary may be 12 years old. But Norton AnitVirus still can't distinguish an article about an attack from the attack itself. If your AV alerts are on isc.sans.edu, the site is safe. I promise :)
SANS.edu Internet Storm Center - SANS Internet Storm Center
SANS.edu Internet Storm Center. Today's Top Story: The Curious Case of a 12-Year-Old Netgear Router Vulnerability;
isc.sans.edu
January 15, 2025 at 12:36 PM
I'm doing a 24-year DShield anniversary special sticker giveaway for a week. Free stickers... there will be a limited number each day. You need to log in, and you will need to use the code BLUESKY . isc.sans.edu/sticker.html
Order Stickers - SANS Internet Storm Center
SANS Internet Storm Center - A global cooperative cyber threat / internet security monitor and alert system. Featuring daily handler diaries with summarizing and analyzing new threats to networks and ...
isc.sans.edu
November 28, 2024 at 4:33 PM
Is anybody else getting spam like this from "academia.com"? The reason I call it spam is that (a) I probably didn't mention myself on a platform I am not using (b) the only way to see what I said about myself requires $5.

I am aware of similar platforms like Researchgate and am using them.
November 22, 2023 at 4:03 PM
Clicking on "details" isn't exactly helpful in MSFT Defender
November 16, 2023 at 4:22 PM
When your AI sales pitch falls flat..
October 23, 2023 at 2:59 PM
First test post… and well, just trying to setup this 5G access point as Comcast is down … only one small issue with the default password
October 20, 2023 at 2:09 PM