meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, April 30th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 30 April 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. From Python to .Net; PHP Composer; BadAlloc and RTOS;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, April 30th, 2021 edition of the Sandcent Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.0

And Python as a programming language is certainly gaining followers rapidly over the last few years, but also, well, for malicious

0:24.0

purposes, it is being used more and more, in particular on the Windows platform, which

0:31.2

of course traditionally hasn't really been using Python that much. Python tended to be more sort of of a Unix tool.

0:41.5

So Xavier came across a malicious Python script that actually interacted with the dotnet framework.

0:49.0

So very Windows specific. It used the Python.net library. and with that was able to do some of the more

0:57.1

lower-level things using dot net instead of having to resort to native Python in order

1:05.4

to accomplish them.

1:06.7

Now one way that this script that Xavier found uses.net is the assembly create instance method.

1:14.3

That particular dot net method is used in order to inject code into the Windows services.

1:22.8

However, Xavi was sadly not able to fully decrypt the code because the encryption key or decryption key is supposed to be provided on the command line and given that Xavi had just a sample, didn't know what command line argument it was used with.

1:41.2

Well, he wasn't able to decrypt that.

1:43.4

If anybody has any ideas, I'm sure KSavie would love to hear.

1:49.7

And then we got yet another vulnerability in a critical tool used by software developers

1:55.6

to manage dependencies.

1:57.9

This time, no, it's not NPM and Node.js. This time it is

2:04.1

PHP and Composer. Composer is a tool to automatically resolve dependencies and install

2:11.3

related packages. And now at the core of Composer is Packages, a website that essentially contains an index of

2:20.6

all of the packages being offered via Composer, but you can also run your own instance of

2:28.2

packages if you should prefer to do so. As Composer resolves dependencies and downloads additional code, it will, for

2:37.8

example, call utilities like Git in order to retrieve the code, and of course it will provide

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.