ISC StormCast for Friday, May 11th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 May 2018
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, May 11th, 2018 edition of the Sandcent Storms, Stormcast. |
| 0:08.0 | My name is Johannes Ulrich and I am recording from Indianapolis, Indiana. |
| 0:13.0 | Just this week again when I'm teaching intrusion detection, I always demonstrate how easy it is to exfiltrate data with DNS using simple bash scripts. |
| 0:23.6 | Now in Windows, that's not quite as easy, but Boyan has an interesting script that he |
| 0:30.6 | posted today that allows the exfiltration of data using just standard Windows commands and only the standard Windows shell. |
| 0:41.2 | So no fancy PowerShell for this particular script. |
| 0:46.1 | One problem, for example, you have to solve is to convert binary files into something |
| 0:51.8 | that can be converted into a DNS host name. |
| 0:56.3 | Now in Unix, I always use the handy tool XXD to accomplish that in Windows, |
| 1:03.4 | Boyan here is using SERTutil. |
| 1:07.0 | Sertutil has the interesting feature where it can base 64 in code data, which gets you close enough to something that can then easily be exfiltrated via DNS. |
| 1:19.6 | So a neat little trick for the pen testers. |
| 1:21.6 | Now, from a defensive point of view, what I always recommend is to look at the volume of DNS queries. In particular, |
| 1:28.6 | these more isolated hosts tend to issue less DNS queries than your average hosts, so you |
| 1:35.7 | should be able to see anomalous spikes in activity. And criminals apparently have managed to |
| 1:43.2 | create a copycat application for the very popular |
| 1:47.2 | Bitcoin wallet Electrum. Now, Electrum is usually distributed at Electrum.org. And the Copycat |
| 1:56.6 | Wallet Electrum Pro, as it calls itself, can be found at Electrum.com. |
| 2:02.8 | Now, creating yet another Bitcoin wallet isn't really the problem here. |
| 2:06.9 | The problem is that the fake version of this wallet does exfiltrate the seat that's being |
| 2:12.7 | used to create the user's private key. |
| 2:16.2 | And with that, the people behind this fake wallet will be able |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

