4.9 • 696 Ratings
🗓️ 15 February 2019
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, February 15th, 2019 edition of the Santernut Storm Center's |
0:06.3 | Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:13.0 | You probably have heard in the past about problems with PDFs that are embedding links to SMB |
0:20.8 | file shares. |
0:21.6 | Don't see him really a lot, but it is actually a pretty easy exploit in the sense that |
0:28.6 | then the user will try to connect outbound to the SMB file share, of course, download the document |
0:35.6 | and in some circumstances even pass along hashes of credentials |
0:41.2 | in order to attempt to essentially authenticate against this remote file share. |
0:46.8 | More or less anywhere where you would have added a HTTP URL, you could also insert |
0:52.8 | an SMB URL. Now often of course this ability has been disabled |
0:58.1 | in recent years, but PDFs are still one of these spots where it is sometimes possible |
1:05.2 | and where this trick works. Xavi ran into one such document and took a closer look at it, so if you want to see how it works. Xavier ran into one such document and took a closer look at it. So if you want to see |
1:14.5 | how it worked in this particular case, how to analyze documents like this. Well, take a look. |
1:21.8 | If you're running a QNAP appliance, these are these storage devices. You may want to take a look at the host file on the QNAP appliance, these are these storage devices. |
1:27.8 | You may want to take a look at the host file on the QNAP device and check it for any odd |
1:34.2 | entries. |
1:35.2 | There has been some so far really undefined malware going around, which apparently does |
1:40.8 | manifest itself by additional entries in your Etsy hosts file. |
1:46.2 | Now if you have one of these devices, you also should definitely update the version of the |
1:52.1 | operating system of the device, also update all installed applications, and manually update |
1:59.7 | the malware remover that is included with this device. |
2:04.8 | Apparently, another sort of side effect of the malware that's being spotted by QNAP users |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.