meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 20th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 20 February 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Backing up Router/Switch Config; #Windows #EMF #0Day

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, February 20th, 2017 edition of the Sands and its Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Scottsdale, Arizona.

0:12.7

On Friday, Rob published a nice script that helps you back up the configurations for your switches and routers.

0:21.7

It does support quite a range of different manufacturers,

0:25.7

and all you need to do is run the script and have a little configuration file

0:29.7

that lists the IP addresses and the maker of the switch that you're trying to back up.

0:36.1

Yes, there are other tools like this out there.

0:38.4

The nice thing about this tool is that it's very simple.

0:40.9

It's just a PowerShell script, so you don't need to install anything.

0:44.6

You just run it on your Windows systems.

0:47.2

For large enterprise network, you probably want to stick with your larger systems to backup

0:53.4

router and switch configurations.

0:56.5

And Google released a new Cerer Day vulnerability in Windows.

1:01.5

This one is affecting EMF images.

1:04.9

Now, EMF images are sort of a more modern version of the famous WMF format.

1:12.2

If you remember, there was like this big vulnerability back in 2006, I think. And in this case, EMF does not allow remote code execution,

1:21.3

but it may leak memory content. What's happening here is that an attacker can specify images with essentially

1:29.3

bad size parameters for certain image areas and then not provide enough data to actually fill in that area.

1:36.3

So what the system will do, it will fill in a random memory content.

1:42.3

Explorability for this is of course a little bit tricky. So an attacker

1:45.3

would first of all have to trick you into opening an EMF image. Now that's probably easy

1:51.0

part because these images can be embedded in all kinds of other documents. It doesn't have to be

1:57.4

just an EMF image by itself. Then secondly, of course, the attacker has to get a hold of the image that's being

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.