meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, October 6th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 6 October 2017

⏱️ 16 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. New Tool: pcap2curl; MacOS High Sierra Patch;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, October 6, 2017 edition of the Sancented Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.6

Published a brief diary and tool earlier today that will take a PCAP file and extract HTTP requests and turn them into curl commands.

0:24.7

Curl, if you're not familiar with it, is a little Unix command line tool that allows you to send

0:29.5

HTTP requests. So what this tool does essentially, it allows you to replay the requests

0:35.8

that were included in that PCAP file.

0:39.2

I ran into the need for such a tool when I was working recently with a web-based API

0:46.2

where I tried to sort of send some requests to it.

0:49.1

And I always like to do it in the browser, but in this particular case, it was really

0:53.7

not that easy in the browser, but in this particular case, it was really not that easy in the

0:54.7

browser to figure out which requests cost what, so that tool came in handy in order to get

1:02.2

all of the requests extracted at the same time, and make it easier to screen through for the ones

1:08.5

that are actually important.

1:11.6

And Apple today released an update for Mac OS High Sierra fixing a rather embarrassing security

1:19.3

flaw.

1:20.3

With MacOS High Sierra, Apple introduced a new file system, the Apple file system. And with that, of course, you can also encrypt your files

1:30.4

as you were able before, but the implementation of the encryption had a pretty interesting bug.

1:37.3

Now, when you set up encryption for a particular drive, you can also set up a password hint. However, it turned out that Apple saved

1:47.1

the password in the password hint, not the actual text that you entered as a password hint.

1:53.2

So whenever you used a password hint, no matter what text you entered there, it would be replaced

2:00.0

with the password. and then when you request

2:03.2

the password hint, what you actually get back is the clear text password. Now, when I saw this

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.