ISC StormCast for Friday, January 25th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 January 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 25th, 2019 edition of the Sansonet Storms and a Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.7 | November last year, GoScript released version 9.26, and today Travis Armandy with Google did release advisory detailing some |
| 0:26.4 | remote code execution vulnerabilities in GoScript. Now, if you're not familiar with GoScript, |
| 0:31.4 | GoScript is an open-sourced postscript interpreter and well-post script is a fairly complex language. |
| 0:39.2 | Actually, Travis's post goes into some detail in how, for example, functions are being defined |
| 0:45.9 | in this language. |
| 0:47.3 | And this latest version of GoScript doesn't protect this correctly. |
| 0:53.0 | So this is how remote code execution can happen. Travis did also |
| 0:57.2 | offer proof of concept code and it could be exploited via various tools that are commonly used to |
| 1:04.6 | look at PostScript documents. Then you may say, hey, I don't use PostScript and I don't use |
| 1:09.2 | GoScript. Well, the problem is that |
| 1:11.8 | GoScript is one of those basic libraries that's used to parse these documents, often also |
| 1:17.9 | used by security tools and such. So I wouldn't count it out, even if you are not really familiar |
| 1:23.6 | with GoScript, you may be using it as part of some third-party tool and this |
| 1:30.0 | third-party tool may expose you to these exploits. |
| 1:34.3 | A patch hasn't been made public yet, but Travis did offer some pull requests to the Ghost |
| 1:39.7 | script project that should fix these vulnerabilities. And Dutch researcher, Durkian Molima, did come up with an |
| 1:49.8 | interesting way to combine three known vulnerabilities to actually leverage access to Microsoft |
| 1:55.8 | Exchange to get full domain admin control. Like I said, it's really sort of three problems that are being used here, but probably |
| 2:04.6 | the most critical part is that exchange does actually use quite high privileges in its |
| 2:12.5 | active directory domain. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

