meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, December 16th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 16 December 2016

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Domaincops Malware; FileVault2 Vulnerability; DNS Changer is Back

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, December 16th, 2016 edition of the Sands and its Storm Center's

0:06.5

Stormcast. My name is Johannes Ulrich, and I'm recording from Washington, D.C.

0:12.1

I think it was about a week ago I wrote about the malicious email ad hatchments I received from

0:17.6

DomainCorp. Today, Brad analyzed one of these emails in depth.

0:24.7

He ended up with the Kerber Ransomware after looking at the attachment in more detail.

0:31.9

He also discovered the two additional domains that were related to this particular wave of attacks.

0:40.2

In addition to domaincop.org, he saw Domaincop 247.com as well as ccnotice.netnet.

0:51.7

I'm not sure how successful this particular attack was, but I guess if we see some

0:57.0

similar domains being registered in the future, it probably means that it worked for them.

1:02.4

Well, and if you need more reasons to apply Apple's patches for OS10, here's one. It turns out

1:09.6

that the patches released earlier this week. Do fix a vulnerability

1:14.4

that allows access to the FileWalt password via Thunderbolt. Now, first of all, file vault,

1:21.3

like all, disk encryption, is supposed to protect a system if an attacker has physical access to the system.

1:29.1

And this is exactly what is required in order to break the file vault to password using access to Thunderbolt.

1:37.9

What's happening is that if an OS10 system reboots, it does allow for a short time access via Thunderbolt to memory via DMA,

1:50.0

and as a result, an attacker can read the filebalt password before it is being deleted during the reboot process.

1:59.0

This particular attack, of course, requires special hardware in order to access the thunderbolt port,

2:05.6

but that's pretty straightforward to acquire and it has been tested with multiple thunderbolt two laptops.

2:14.6

Has not been tested yet with the newer USB C laptops,

2:18.3

but there is really no reason why it shouldn't work with those laptops.

2:23.3

So Apple patched a problem and this time window

2:27.3

during which you can access memory no longer exists.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.