meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, April 30th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 30 April 2018

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Sample #Drupal Exploits; Triggering SMB Connections from PDFs; Win7/10 NTFS Crash DoS; Azucar Azure

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, April 30th, 2018 edition of the Santonet Stormsendors Stormcast. My name is Johannes Ulrich,

0:09.1

and I am recording from Jacksonville, Florida. I mentioned Tom was working on some exploits against the new

0:15.9

triple vulnerability. He published his post on Friday. Now, sort of interesting here that while they're using this brand new

0:24.6

Truple exploit, it's sort of a little bit of flashback here in the sense that they're defacing the site,

0:32.6

using Kurdish propaganda, and then they're actually registering themselves with Soan H. I didn't even know

0:39.8

that Zone H was still around. Soan H is a defacement mirror. That's where hackers take credit

0:46.1

for defacing websites. It was a big thing when I got started in Infosec, but of course,

0:52.1

not so much these last few years. And Checkpoint published a blog post

0:57.6

showing how PDFs can be used to steal Windows NTLM credentials. The problem with NTLM credentials is that

1:07.0

whenever a client connects to an SMB server, it automatically tries to authenticate.

1:14.0

So the trick that's usually being used in order to extract these credentials is I'm sending

1:19.9

you a document that contains content that appears to be located on an SMB share.

1:26.3

So as the user opens the PDF, PDF reader tries to connect

1:30.2

to the SMB share, and with that it transmits the user's credentials. Now, they're hash, but we all

1:37.4

know hashes can be brute forced. Now, don't wait for Adobe to fix this. Adobe is actually

1:43.1

referring to Microsoft and Microsoft's

1:45.5

guidance is to disable NTLM single sign-on authentication for public resources, which should

1:52.3

limit the impact of this problem.

1:55.4

And well, I've mentioned it multiple times before you should block all outbound SMB connections.

2:01.7

This is just one of many ways how NetHacker could possibly trick you into sending

2:07.3

credentials to a malicious SMB share.

2:10.5

And talking about Microsoft and bugs that won't be fixed anytime soon,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.