Light

Episode #806 Quiz

C.O.M.B.
Date: 2021-02-16 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Oldsmar’s water SCADA used shared Windows 7/TeamViewer remote access on exposed Internet systems, enabling unauthorized sodium hydroxide changes; mitigations include firewalls, VPNs, MFA, patching, and one-way monitoring. Microsoft patched critical Windows RCEs in TCP/IP, Fax, DNS, codecs, and more. SHAREit, WordPress plugins, web shells, and leaked credentials amplified attack surface.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the Massachusetts Department of Environmental Protection advisory discussed in the episode, which remote-access practice did it recommend for monitoring SCADA systems without allowing control changes?
Question 2: What did the Oldsmar incident report say about when plant personnel acted relative to the SCADA software's own alarm?
Question 3: Which Windows TCP/IP flaw did Steve identify as involving an attack via deliberately malformed IP packets carrying a certain old protocol feature?
Question 4: What was the key exploitation path described for the Responsive Menu WordPress plugin vulnerabilities?
Question 5: When discussing the COMB leak, what was Steve's practical advice about old online accounts and their passwords?
Cancel