ISC StormCast for Friday, May 28th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 May 2021
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, May 28, 2021 edition of the Sandcent, Center at Storm Center's |
| 0:06.3 | Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida, but virtually |
| 0:12.8 | teaching in London, England. In Diaries today, we got an interesting experiment by Jan. He |
| 0:20.4 | looked at the effectiveness in using |
| 0:23.3 | different encodings in order to evade antivirus. And what he focused on was base encodings. |
| 0:30.8 | Now, you're probably all familiar with base 64, but there are a number of different base encodings, |
| 0:36.8 | like, for example, base 32. |
| 0:38.9 | What they all have in common is that they essentially map all byte values from 0 to 255 |
| 0:45.6 | into a more limited character set, like 64 characters for base 64. |
| 0:52.8 | As a sample, Jan took a meta-sploid payload, which of course should be well-detected, |
| 0:58.4 | and it was well-detected if not obfuscated, and he then compiled it for 32 and for 64 bits. |
| 1:07.6 | A couple interesting results here. First of all, yes, and that's very not surprising that base 64 encoded binaries are not well |
| 1:16.6 | detected, but it didn't really make a difference as to what base encoding was used. |
| 1:22.6 | What probably was more surprising than base 64 encoding not being detected well was that 64-bit binaries |
| 1:30.3 | were detected much less than 32-bit binaries, regardless the encoding. |
| 1:37.3 | With 64-bit CPUs and operating systems now pretty much being the default all over, A lot of malware, of course, is also |
| 1:45.9 | compiled for 64-bit, and you would expect anti-malware tools to do a bit better than what |
| 1:53.7 | they are doing here, according to Jan's experiment. Never mind, of course, that this is only going |
| 1:59.6 | to become worse as we do have sort of a diversification of architectures with Arm, of course, also becoming more and more popular in particular on the mobile side. |
| 2:12.7 | And then we got an interesting proof of concept exploit for all current versions of MacOS and iOS, and that includes |
| 2:21.8 | 14.6 for iOS, as well as MacOS 11.4. The problem here is a vulnerability in WebKit. Of course, |
| 2:32.6 | WebKit is the basic foundation of Safari, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

