meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, July 12th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 July 2019

⏱️ 13 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. AZORult Sample; Zoom Followup; Apple Watch eavesdropping; PXE Windows Bug; @sans_edu

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, July 12th, 2019 edition of the Sands and the Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich, and today I'm recording from London, England.

0:12.7

While I'm here in London, teaching the Security 503 intrusion detection in-depth class,

0:19.3

and students always ask in this class where they can find more packet captures in order to practice their skills.

0:28.6

One resource I always redirect them to is Pratt Duncan's Diaries on our Internet Storm Center page, and he today published yet another one of his

0:40.9

famous malware walkthroughs. The latest one deals with the Azo Ralt Malware and in this case he was

0:49.3

actually able based on a tweet to discover an open directory on a web server that did contain some of this malware.

1:00.2

In this case, the malware took the form of an ISO file.

1:05.5

Now, he has talked about ISO files before.

1:08.3

There are, of course, nice vehicles in order to deliver malicious files.

1:13.6

In this case an executable is contained inside the ISO that then executed and launches the malware.

1:23.6

As usual Brad makes available the packet capture as well as malware samples, so that's

1:31.3

great for you to practice with and hone your packet analysis skills.

1:38.3

Let me get an update on the Zoom software for Mac OS.

1:46.6

Now there is a patch available for this software now,

1:50.1

and Apple actually collaborated with Zoom in order to also delete this buggy web server

1:57.9

that earlier versions of Zoom installed from Macs. Apple did this using

2:03.7

their antivirus engine that's built into Mac OS by essentially instructing it that this

2:10.8

particular web server is malicious and giving it instructions to remove this web server.

2:18.3

If you're running the updated version of Zoom, you should recognize that it will prompt you before it's being started.

2:28.3

One reason that the older version of Zoom did rely on this somewhat suspect web server was in order to avoid this

2:38.4

prompt. And one of the features added in the latest version of watchOS was the walkie-talkie

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.