ISC StormCast for Friday, December 2nd 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 December 2016
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday December 2, 2016 edition of the Sansonet Stormsendors. |
| 0:06.8 | Stormcast, my name is Johannes Ulrich, and I am recording from Jacksonville, Florida. |
| 0:12.5 | Most operating systems will implicitly trust USB devices being plugged into the system. |
| 0:19.7 | This has been a long known problem for mass storage |
| 0:23.5 | device, of course, but it can also be an issue with keyboards and lately network adapters |
| 0:30.2 | that are being plugged in and then initialized automatically. Windows users now at least |
| 0:36.6 | have a way to defend themselves using an open source |
| 0:40.7 | tool called BeamGun. BeamGun intercepts the messages that are created by Windows whenever a new |
| 0:48.4 | USB device is plugged in and then essentially it just sends the disconnect command to the USB device unmounting it |
| 0:57.5 | and preventing any damage. Interesting little tool and yes it's open source but also only for |
| 1:06.3 | Windows right now. The basic problem exists on OS10 and yes on Linux as well. A few years ago, |
| 1:15.9 | Malvern known as Shemu made headlines for raising thousands of systems at Saudi Arabia's |
| 1:23.6 | government-owned oil company Saudi Ramco. |
| 1:34.2 | Now, in that attack, apparently, a phishing email was sort of the original tricker for spreading the malware, and it made big headlines because it took quite a while for Saudi Ramco to |
| 1:40.9 | recover all these systems. |
| 1:42.9 | It appears that last week, a follow-on to this attack was |
| 1:46.9 | launched against the Saudi Civil Aviation Authority and a number of additional targets |
| 1:53.3 | in Saudi Arabia. Again, thousands of systems were erased. This malware will essentially just |
| 1:59.2 | destructively erase, not encrypt the affected systems. |
| 2:04.5 | And what was different in this particular case was that multiple targets were hit at the same |
| 2:10.6 | time. However, at this point, only the Civil Aviation Authority is known as one of those targets. |
| 2:19.5 | And British ISP KCOM did suffer a major outage over this weekend. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

