meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, April 17th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 17 April 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Applocker vs LOTL; Netlink GPON 0Day; Windows Security Crash; Bad Gems; vCenter Exploit

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, April 17th, 2020 edition of the Santernat Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and I am recording from Jacksonville, Florida.

0:13.2

In the past on Fridays, I often had SDI students here for an interview about their recent research projects. Well, I tried

0:23.8

something different today. David Brown, he is an SDI student that recently finished a really neat

0:31.3

paper that talks about how to use App Locker to successfully defend against living off

0:37.4

the land attacks.

0:39.0

Well, instead of having him here for an interview, we actually did record a little video

0:44.9

where he gets to demonstrate how his improved app locker rules work.

0:50.4

The basic trick here is that he made the app locker rules user specific. So

0:56.7

users, regular users, are even more restricted into what they can execute versus an administrator.

1:04.3

By default, app locker does allow all the standard Windows software to operate,

1:15.0

which of course is exactly what sort of living off the land attacks are all about.

1:19.9

But David's rules make that quite a bit more difficult.

1:21.5

So check it out.

1:26.6

Links will be in the show notes and also on the Internet Storm Center website.

1:30.4

If you go to Thursday's Diary diary you'll see the video and a link to his paper and chihoo 360 is reporting about uh seraday currently being used

1:40.7

to build a botnet using netlink Gipon routers.

1:46.0

Gpon stands for gigabit passive optical networks, often used sort of in home installations

1:53.0

and some of these fiber to the home setups.

1:56.8

And in order to use the exploit, you actually need two stages or two different exploits that

2:03.0

have to be executed.

2:04.8

The second one of these exploits is already public, but it doesn't really work without the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.