4.9 • 696 Ratings
🗓️ 21 April 2023
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, April 21st, 2003 edition of the Sansonet Storm Center's Stormcast. |
0:08.9 | My name is Johannes Ulrich and today I'm recording from Augusta, Georgia. |
0:14.5 | Many organizations are moving away from forcing their users to regularly change their passwords, but this doesn't mean |
0:23.9 | that there aren't organizations that still do, and also some compliance regimens that still require. |
0:30.6 | You do implement passport rotation in your organization. If you do still force users to rotate passwords, |
0:39.3 | and of course one of the pain points is that users forget it, |
0:43.3 | their passwords get expired, and then it often involves like a help desk call to unlock accounts. |
0:50.3 | To help with this particular pain point, Rob today in his diary published a PowerShell script |
0:56.2 | that you can use to proactively warn your users with an email that their password is about |
1:02.4 | to expire. |
1:04.0 | Warning users in time also helps them then hopefully come up with a better password than being |
1:10.6 | sort of confronted with the warning |
1:12.2 | that they must change their password now, which of course then just makes them want to get |
1:17.9 | work started and pick the weakest possible password, passing whatever password policy you have. |
1:28.1 | And Mandian published an update to its investigation into the compromise of 3CX. |
1:34.1 | This was the voice over IP company that was compromised. |
1:37.9 | And as part of the compromised, its customers received malicious software embedded into its voiceover IP client. |
1:47.2 | The interesting part is that the initial infection of 3CX actually derived from another |
1:55.0 | supply chain compromise. Apparently one user at 3CX downloaded a package known as X-Trader, online trading software |
2:05.1 | that is overall legitimate, that was, however, discontinued in 2020 and as of late 2022, |
2:14.1 | still available for download from the original company's website. |
2:19.5 | However, it turns out that the particular version downloaded by this user was itself compromised, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.