4.9 • 696 Ratings
🗓️ 26 August 2018
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, August 27th, 2018 edition of the Sandcent Storm Center at Storm Center's Stormcast. |
0:07.7 | My name is Johannes Ulrich, and I'm recording from Frankfurt, Germany. |
0:12.8 | Just a quick update on the Apache Struts vulnerability that I talked about on Friday. |
0:19.5 | There is now on GitHub a public available exploit |
0:23.3 | for this vulnerability. So if you still have any unpatched systems out there, any systems |
0:30.3 | where you didn't mitigate this vulnerability well using some form of web application firewall |
0:36.2 | or whatever, don't just blindly patch these systems at this |
0:40.2 | point, but go over them with a fine comb trying to figure out if they haven't already been |
0:46.4 | exploited yet. And Xavier took a look at some malware that was delivered as a malicious publisher file. Yes, Microsoft |
0:57.5 | publisher hasn't really been used much lately, I believe, but apparently it's still part |
1:04.3 | of the default install in many office setups. It is, for example, part of the Office 365 business premium setup |
1:14.2 | which a lot of businesses subscribe to and if you select to install the respective |
1:19.8 | applications on your system then publisher will be installed as well and of course |
1:25.3 | these dot pub files will automatically be opened by publisher. |
1:30.2 | Probably the goal here is to evade some basic blacklisting techniques where you're only looking |
1:37.2 | for macros and alike in Word or Excel documents and never really bothered to also inspect |
1:43.8 | publisher documents. |
1:45.9 | So Xavier in his post will explain how to analyze this kind of malware and a reader actually |
1:51.9 | left a comment telling you how to add dot pub files to the exchange online protection. |
2:00.9 | Well, and if you never heard of publisher, then you probably also have never really heard of |
2:08.4 | AT commands. |
2:09.9 | In a good old Dial-up modem days, you tended to use AT commands, which is short for attention, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.