meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, October 14th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 14 October 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Mount Docker Filesystems; Globalsign Messes Up CA; DXXD Ransomware; LockyDump

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, October 14th, 2016 edition of the Sands and the Storm Center's

0:07.2

Stormcast. My name is Johannes Ulrich, Enderam recording from Jacksonville, Florida.

0:13.5

Jim released today a great free tool that he wrote, a Dockermount.p.y. It's a Python script that allows you to mount Docker file systems

0:25.1

in read-only mode for forensics analysis. Pretty neat script and probably is going to save you

0:32.8

some time if you have to analyze a compromise of a Docker instance.

0:38.3

Now it doesn't handle every possible storage driver that Docker can use,

0:44.3

but it does deal with AUFS and overlay 2,

0:49.3

which are some of the more popular ones,

0:53.3

even though, well, AUFS may be more to the fault on older

0:57.6

systems.

0:58.6

And if you visited a website on Thursday and got a bad certificate warning, it may be due to

1:06.6

a mess up at GlobalSign.

1:09.0

GlobalSign is one of the large certificate authorities and apparently

1:12.6

they did revoke a cross certificate between two root certificates and with that actually

1:22.6

by mistake essentially invalidated one of the signing certificates for some browsers.

1:30.3

Now this originally was done via certificate revocation list and that worked all well,

1:36.3

but today they started also doing that via OCSP, the online certificate status protocol,

1:42.3

and apparently that messed up some browsers and then resulted

1:48.5

in this invalid certificate warning because the signing certificate was no longer trusted.

1:55.0

Now I have a link to Global Science statement in the show notes but when I just clicked on it before recording

2:02.4

this to make sure the link was working, I actually got a certificate warning myself from

2:08.7

the downloads.globalsign.com website. So don't be surprised if that happens. Maybe someone

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.