meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, July 30th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 30 July 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Archive.org Malware; PyPI Security Analysis; Malware via Template Injection;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, July 30th, 2021 edition of the Sansonet Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.5

And I'm recording from Jacksonville, Florida.

0:13.3

Most malware will download additional components after installing itself or after being installed by a user.

0:22.6

And that's often the weak point for this malware and gives an opportunity for a defender to detect the malware.

0:31.6

If, for example, it uses an odd domain name or an unusual URL to download the particular second stage or additional stages

0:42.1

from.

0:42.8

So attackers are always looking for benign websites to add their malicious content to.

0:49.8

And Xavier came across an interesting example where an attacker used Archive.org, the wayback machine,

0:57.2

as it's also known as, to deposit malicious scripts. And of course, the attacker is expecting

1:03.2

that a defender won't really be too suspicious about a user visiting archive.org. This particular attacker did upload a large number of files

1:15.6

to archive.org, so likely multiple campaigns or maybe different attempts in how to exactly do it.

1:23.4

Now, with this, there's also a little bit information that's being deposited about the attacker

1:28.8

on Archive.org, like for example an email address for the account that the attacker set up

1:36.0

to be able to upload files.

1:38.7

But what is what he tells you is there are no safe or unsafe websites.

1:43.9

Any website that allows average average user just by signing up for a free account to upload files

1:52.0

can easily be abused to distribute matter.

1:57.0

And researchers from the University of Turku in Finland did run a static code analysis tool that they call banded against the Python package index or Pi Pi. In total, they looked at 197,000 packages and then looked at, well, what vulnerabilities their static code analysis tool

2:19.1

would uncover. Static code analysis, of course, is not perfect, but should give you a

2:25.2

reasonable idea as to the code quality. I actually think it wasn't really that bad. About

2:31.5

half of the packages had no vulnerabilities and only about 12 or so percent

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.