ISC StormCast for Monday, February 13th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 February 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, February 13th, 2017 edition of the Sands and its Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.4 | Google's Project Zero is looking at security software again, and it released details about six different privilege escalation flaws in Samsung's |
| 0:23.3 | NOx protection for Android. |
| 0:26.2 | Knox includes a component known as real-time kernel protection, also RKP, and it is supposed |
| 0:33.8 | to protect the kernel of Android. |
| 0:37.3 | Now, Google Project, Sarah found a number of laws |
| 0:40.2 | in this component that can be used to bypass real-time kernel protection. Google's write-up is |
| 0:47.7 | not just interesting because, well, it talks about these vulnerabilities, but it really goes |
| 0:52.1 | into quite a bit in depth how sort of these |
| 0:54.8 | hypervisor-based kernel protection systems work and how the bypass methods that Google |
| 1:02.6 | found actually worked in this particular case and could help bypass protections that are |
| 1:09.8 | supposed to prevent the kernel from getting compromised. |
| 1:14.2 | Of course, these vulnerabilities only matter if there are actual vulnerabilities in Android |
| 1:19.2 | that can be used to reach route, but of course, there are typically plenty of them, |
| 1:25.5 | so it's good that Samsung released a patch for the problem |
| 1:29.6 | a few weeks ago. If you are relying on Samsung Knox to protect your Android phones, |
| 1:36.5 | it's time to update. If you're running MongoDB and if you are listening to this podcast |
| 1:42.4 | regular, you're probably aware of all the exploits |
| 1:45.3 | that are being used in the wild to attack vulnerable MongoDB configurations. |
| 1:50.5 | A new tool was just released to GitHub by Aran Sanchez de Petro that assists MongoDB administrators |
| 1:58.9 | in scanning instances of MongoDB for configuration issues |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

