meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 6th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 February 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Malware on #Pastebin; McAfee ePO Patch #sqlinj ; #Whatsapp used to spread malware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, February 6th, 2017 edition of the Sands and its Storm Center's Stormcast.

0:07.1

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.1

Xavier found a number of base 64 encoded malvers samples on pastebin. Typically, these type of posts are

0:20.3

then downloaded to infected systems. Pastebin as

0:24.1

source is usually not considered malicious and the basics the bays64 encoded samples are unlikely

0:30.6

to trigger anti-malrass signatures, making that sort of a very overt, covert channel. This is in particular problematic if the download that initiates the infection and decodes

0:45.3

the malware is not detected by anti-mailware.

0:49.4

If you had this happen before, we're sort of simple JavaScript downloaders and such,

0:53.9

were not detected. So this could then be

0:57.7

made worse by downloading from a well-known and semi-trusted site like a pastebin.

1:04.6

Xavier couldn't identify any specific malware sample associated with the pastebin post that he found, but there are likely

1:13.5

many samples using this technique and not all paste bin posts like these are actively used

1:21.2

at any time.

1:23.2

Cisco's Maraki product line of wireless access points suffer from an interesting problem. A clock component

1:30.0

inside these access points will fail causing the access point to crash and become unbootable

1:36.8

again. This is a hardware problem. This is not something you can fix with a software update.

1:43.4

Cisco initiated a recall and it is important that you get in line to have your device replaced

1:50.5

before it is affected by this bug because in that moment it will just die.

1:57.1

According to Cisco, replacements will be prioritized to replace all the units first, which of course will hit this particular bug first.

2:05.6

And Intel released a hot fix for the McGaffy E Policy Orchestrator.

2:10.6

The hot fix patches a blind sequel injection vulnerability to exploit the vulnerability and attacker would send a crafted

2:18.2

HTTP request to the policy orchestrator and the attacker would then be able to

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.