ISC StormCast for Friday, February 7th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 February 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, February 7th, 2020 edition of the Sansand-Stormsanders Stormcast. |
| 0:07.4 | My name is Johannes Ulrich. |
| 0:08.9 | I'm recording from Jacksonville, Florida. |
| 0:12.9 | Yesterday, I talked about the Android updates, in particular CVE 2020, CIRSR 22. |
| 0:20.7 | This was the vulnerability that was critical on Android 8 and 9, |
| 0:26.4 | not on Android 10. I noted that Google's advisory was a little bit vague, that it really just |
| 0:33.3 | talked about data transmissions that could trigger this vulnerability. Didn't really specify a lot |
| 0:39.5 | what kind of data transmissions could be used. Now, we have a little bit more detail now from |
| 0:47.1 | the incinerator blog and it talks that, well, the vector here is Bluetooth. |
| 0:59.6 | Not enough details here in this blog to really tell us what the vulnerability is all about. |
| 1:05.0 | So they'll probably take reverse engineering some of the patches. |
| 1:13.6 | But they do state that on Android 8 and 9, an remote attacker could trigger this vulnerability, could execute arbitrary code without any user interaction as long as, first of all, Bluetooth is enabled, |
| 1:21.7 | and the attacker knows the Mac address of the Bluetooth device. |
| 1:28.1 | The easiest way, of course, to protect yourself is just to turn off Bluetooth, but Bluetooth |
| 1:32.0 | has become sort of one of those very critical features in many mobile devices with |
| 1:37.0 | headphones and such, of course, requiring that you are using it. |
| 1:40.9 | It helps a bit if your device is not discoverable and most devices are not discoverable |
| 1:48.3 | by default unless you're sort of within the Bluetooth scanning menu. Now this helps with keeping the |
| 1:57.4 | Mac more ahead but as the blog post points out on some phones well the Bluetooth |
| 2:04.9 | Mac is related to the Wi-Fi Mac so once you know the Wi-Fi Mac which of |
| 2:10.4 | course is more difficult to hide you may be able to then guess the Bluetooth Mac. |
| 2:16.7 | If you are creative professional if you like to draw with your computer you may be able to then guess the Bluetooth map. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

