meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 31st 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 31 May 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. scdbg Shellcode Analysis; GitHub Auto Patching; Docker Malware and Shodan; Web Packaging

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, May 31st, 2019 edition of the San Antonio Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and I'm recording from San Antonio, Texas.

0:13.9

If you're looking for something to do this weekend, the day has a great introduction into SC debug.

0:20.4

That's a debugger that allows you to analyze Windows

0:24.6

shell code. A couple interesting features that he's going over in his post today. For example,

0:31.8

with SCDBug, you're able to redirect TCP connections and also file accesses.

0:39.3

So this way if you have malware that is trying to connect to an external server, you can set up your own server and then via SCDBug, redirect the connection to your own server.

0:51.3

Today is going through the entire process including how to extract the shell code from a

0:59.0

PowerShell script and how to convert it into a form that's suitable for a CDBug,

1:04.0

and then how to step through the code and use these features like redirecting TCP connections.

1:12.7

GitHub for a while now has offered a security feature

1:16.4

that alerts GitHub repositories, if any dependencies that the repository is using,

1:24.4

have been affected by security vulnerabilities. This has been available for a selected

1:30.4

number of languages I believe Ruby, Python and JavaScript are included at this point.

1:37.9

Now GitHub is expanding this feature at this point in beta with automatic security patches. Now the way this will

1:47.5

work is that if you opt in for this feature which of course requires that you are already

1:55.1

using the dependency craft to figure out what other projects your project depends on then GitHub

2:03.4

will automatically create a poll request whenever there is a security update

2:09.6

for anything that you would depend on so it's not automated in the way that it

2:15.0

will automatically apply these patches you still have to apply the pull request.

2:19.3

That's of course also the safe way of doing it because these changes could of course cause problems for some projects.

2:29.3

In order to minimize the risks, these pull requests will focus on the security fix, so they will

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.