ISC StormCast for Friday, August 25th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 August 2017
⏱️ 12 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, August 25th, 2017 edition of the Sands Internet Storm Center's |
| 0:07.6 | Stormcast. My name is Johannes Ulrich and that I'm recording from Virginia Beach, Virginia. |
| 0:14.2 | HP Enterprises integrated lights out cards are certainly not a stranger to critical vulnerabilities, and we have yet another |
| 0:23.0 | critical vulnerability that you should patch as soon as possible. It does allow for authentication |
| 0:30.1 | bypass as well as for arbitrary code execution on the card. These are the cards that you typically use to remotely manage servers semi out of band, |
| 0:42.9 | which sometimes means that these cards are actually exposed to regain access to systems, |
| 0:49.6 | which turn out to be otherwise unreachable. |
| 0:53.0 | And Kasperska is reporting about malicious Facebook messages that are advertising websites |
| 1:01.1 | that will spread malware. |
| 1:04.0 | Now, the way this starts out is that you will receive a message from a friend of yours |
| 1:09.5 | via Facebook that contains a link to what looks like a movie. |
| 1:14.6 | Now when you click on that link it actually will pop up something movie-like and it sort of |
| 1:20.6 | almost makes it look like it's part of the Facebook page. |
| 1:24.6 | You probably have seen it where a video essentially takes up the entire |
| 1:30.3 | page and puts the actual Facebook page in the background. The only twist here is that |
| 1:37.3 | then a pop-up will instruct you to download a video player or an update for your flash player. That of course then turns out to be |
| 1:47.0 | malicious. Now this is done pretty well even to the point where they are displaying different |
| 1:53.1 | messages for Windows versus Mac users in order to cover different operating systems. Many of the |
| 2:00.7 | links that Kaspersky observed just lead to spam, |
| 2:03.6 | so actually the monetization here, maybe we are just selling spam ad impressions. |
| 2:11.6 | And the researcher at Mobile Security Company Simperium did release an exploit for a vulnerability that was |
| 2:19.7 | patched in May with iOS 10.3.2. So this particular exploit will work for 10.3.1 and |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

