4.9 • 696 Ratings
🗓️ 29 September 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, September 29, 2023 edition of the Santernut Storm Center's Stormcast. |
0:08.6 | My name is Johannes Ulrich. |
0:10.1 | And today I'm recording from Jacksonville, Florida. |
0:14.4 | Got a quick diary by DDA today about decoding IP addresses displayed in Windows event logs, in particular event IDs like, for example, 1002, which is a DHS error. |
0:30.5 | Now, typically, that shouldn't really be all that difficult. |
0:33.8 | The IP address is displayed as an integer, and you would expect this to be your usual network Indian integer. |
0:41.9 | Of course, quite often, actually, I always recommend to developers to represent IP addresses as integers |
0:48.6 | because then you are avoiding a lot of the ambiguities that you have with various string encodings of IP addresses. |
0:55.8 | But turns out that Windows had a little bit different idea. |
1:00.0 | They're actually using the Little Indian format with the most significant byte last. |
1:07.1 | What this means is if you're just straightforward decoding it, |
1:15.3 | you would basically receive the byte values in the opposite order. |
1:20.1 | Well, DDA is showing you how to decode it in CyberCheft. |
1:25.0 | So hopefully this will help you make more sense of these Windows event logs. |
1:31.7 | And Google this week released a new stable channel update for Google Chrome. |
1:37.9 | This update fixes 10 security fixes, and well, one of the reasons, of course, why I'm mentioning this is that one of these vulnerabilities, a heap buffer overflow in VP8 encoding in lip VP CX, is already being exploited. |
1:50.8 | This particular vulnerability has a CVE number of 2023, 5217. As usual, make it a point to at least |
1:59.6 | once a day restart Google Chrome or other web browsers, |
2:04.2 | just to give them a chance to update them. |
2:08.4 | And the Zero Day initiative today published six advisories regarding the email server XM. |
2:17.4 | Now, the big problem here is that there are no patches for any of these six vulnerabilities, |
2:24.2 | despite having notified XM over a year ago back in June of 2022. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.