ISC StormCast for Friday, January 17th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 January 2020
⏱️ 14 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 17th, 2020 edition of the Sandton and Storm Center's |
| 0:07.0 | Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida. |
| 0:13.5 | So we've got a couple new developments to talk about with respect to the CVE 2020601 vulnerability1 vulnerability, that's the crypto API vulnerability, has also |
| 0:25.7 | sort of become known now as either let's decrypt or curveball. |
| 0:30.1 | Well, we do have actually now some tests available for you, a website curveballttest.com that you can use to check if your |
| 0:41.0 | browser is vulnerable. On that website, you will also find a download for a simple binary |
| 0:46.5 | that's signed with a valid certificate, so you can see if that gets noticed. Now, while we're |
| 0:52.7 | experimenting with this, one thing we noticed is that browsers and various endpoint protection software |
| 0:59.0 | really is sort of now detecting some of these invalid certificates. |
| 1:03.0 | For example, Chrome just released an update |
| 1:07.0 | that will block any invalid sites, |
| 1:10.0 | even though Chrome itself on Windows 10 is vulnerable. |
| 1:13.4 | It uses the crypto API, but they added some additional checks to the browser itself to block it. |
| 1:21.0 | Also, Firefox, of course, never really was vulnerable. |
| 1:25.7 | And the Windows Defender also notes for example binaries with the bad |
| 1:30.8 | signatures. All of these endpoint protection parts are a little bit hit and miss depending on |
| 1:36.1 | whether or not your signatures are all up to date. So even if you didn't patch, which still |
| 1:42.1 | you should, it's still highly recommended that you patched. These other protection mechanisms will at least soften the impact of any exploit |
| 1:50.7 | being directed at you. And we got a smaller but significant update for the Citrix ADC vulnerability. |
| 1:59.5 | It turns out that the workaround actually doesn't work on certain |
| 2:04.6 | builds of version 12.1 of the uplines. Now, if you're running one of these affected versions, |
| 2:12.6 | you should, according to the Dutch Cybersecurity Center, just turn off the device and wait for a patch |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

