ISC StormCast for Friday, September 9th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 September 2022
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, September 9, 2020 edition of the Sands Inn at Storm Center's Stormcast. |
| 0:09.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.7 | Cyber Chef is one of those deceptively simple tools that is a joy to use, in my opinion, |
| 0:19.7 | and probably took an army of JavaScript |
| 0:22.0 | geniuses to create in order to make it so simple. Well, actually, maybe it was an army |
| 0:27.5 | given that it came out of the British GCHQ. But today, DDA wrote a nice example showing |
| 0:36.4 | how to analyze obfuscated visual basic script with nothing but CyberChef. |
| 0:43.4 | The DA assemble's recipe in Cyber Chef starting with UTF6 decoding, the hex dump pulled from the malware, |
| 0:51.7 | and after filtering some empty lines and some visual basic |
| 0:57.0 | code becomes evident. But that was pretty straightforward. Did he then goes further and shows how |
| 1:04.7 | the actual obfuscated strings within the visual basics code can further be de-offuscated using Cyber Chef and |
| 1:14.0 | how in the end you'll end up with the URL the next stage of the malware was downloaded |
| 1:19.8 | from. A full link to the recipe is shared by DDE as well. |
| 1:26.6 | Now earlier this week I saw a vulnerability announced in PF Census, PF Blocker, NCHN, |
| 1:32.3 | and honestly just forgot to cover it. |
| 1:35.0 | So thanks to Joe from Sands for reminding me earlier today. |
| 1:39.1 | I know there are a number of IAC readers who use this tool. |
| 1:44.0 | PF Blocker NG is a plug-in for the open-source firewall PFSense. |
| 1:49.0 | I'm not really sure if it's also available in OpenSense, |
| 1:52.9 | but the problem here is that it does allow for arbitrary code execution. |
| 2:00.8 | The plugin itself does not validate the host header correctly. |
| 2:05.9 | And of course, the host header is supplied by the user. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

