meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, December 18th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 December 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VBA Macro Obfuscation; Large Scale BGP Attack; HSTS/key pinning weakness

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, December 18th, 2017 edition of the Science Internet Storm Center's Stormcast.

0:07.6

My name is Johannes Ulrich, and I'm recording from Washington, D.C.

0:12.0

Microsoft Office macros have long been stable when it comes to malicious code that users are receiving.

0:20.8

Now, Xavier came across an interesting new technique. to malicious code that users are receiving.

0:27.8

Now, Xavier came across an interesting new technique being used by malicious documents in order to obfuscate the nature of these macros.

0:33.1

Macros or Microsoft documents are coming with metadata describing the document.

0:38.4

In this particular case, the content status property was used to actually store a string

0:45.2

that's then later referenced within the macro in order to assemble the URLs from which

0:52.3

the malicious content is being loaded.

0:56.0

So the intent here is to full a cursory inspection of the macro that only considers the macro code itself and not the entire document.

1:07.0

In this case you wouldn't actually see this document property and as a result wouldn't be able to actually extract the URL that's then being used in the second stage.

1:18.9

Last week, an ISP in Russia announced routes for 80 net blocks that were actually owned by big internet players like Apple, Google,

1:30.1

Facebook and Microsoft.

1:32.9

This attack took advantage of insecurities in the BGP protocol, and essentially what happened

1:39.2

here is that this ISP did make fairly specific announcements for slash 24 networks that were more

1:46.8

specific announcements than the ones that were made by these respective companies.

1:53.2

Sadly, these attacks are still possible.

1:56.3

There are some workaround, some extensions to the BGP protocol that should have prevented these

2:02.7

attacks, but these extensions haven't really been widely implemented yet.

2:09.0

Attacks like this are actually somewhat calm and often affecting financial institutions.

2:15.5

Now, what was a little bit different here was the large number of net blocks being

2:20.2

announced and also the large number of companies being affected. Not really clear why they were doing

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.