meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, April 3rd 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 3 April 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. More LastPass Patches;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, April 3rd, 2017 edition of the Santernet Snowlander's Stormcast.

0:07.5

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:12.1

Today we'll start with attacks against the password managers. Of course, I've mentioned a few in the

0:18.4

past. And let's start with LastPass again.

0:21.9

Google's project, Zero of course, has spent a lot of time with LastPass recently and found

0:27.5

a couple of vulnerabilities already.

0:29.6

The latest vulnerability is kind of interesting because it affected more than just one specific

0:36.5

piece of code.

0:38.2

The problem here was how LastPass used JavaScript.

0:42.1

Now in order to find password forms, LastPass does inject JavaScript into webpages that

0:49.2

are being loaded in the browser.

0:51.8

And Google's Project Zero here of course looked at the Chrome extension

0:56.0

for LastPass. This JavaScript is typically safe, it's isolated from the page itself, but it also

1:04.8

has special privileges. It can, for example, execute code on the host. The problem here with LastPass was that they didn't initialize all the variables that

1:16.6

are used in their privileged JavaScript, which then can lead to these variables being defined

1:22.6

by the page, not by this privileged world or this privileged JavaScript.

1:29.1

Now, LastPass was very fast in the releasing a patch for this particular problem and the patch

1:35.9

is available.

1:37.5

So you should download this as soon as possible.

1:42.0

The next issue is with key pass and that's really not all that severe.

1:49.0

It's really a nice presentation that was presented at B-Sides New Orleans and goes over various ways how KeyPass can be attacked.

1:59.0

Now, of course, like any one of these systems, you can

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.