ISC StormCast for Monday, January 23rd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 January 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 23rd, 2017 edition of the Sandsenet Storm Center. |
| 0:07.1 | Stormcast, my name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:13.4 | Brad wrote up a nice piece about new ransomware that he was running across, and it identifies itself as Sage 2.0. |
| 0:24.9 | The emails distributing the ransomware are done pretty simple, no subject line, so should be easy |
| 0:31.5 | to spot, but it makes it more likely that the victim opens the attachment by naming the attachment using |
| 0:40.3 | the victim's name. |
| 0:42.3 | Once opened, the Malware downloader then uses the usual tricks to get the victim to enable |
| 0:48.3 | macros by stating that either the Word document was created an earlier version of Word and to view it, |
| 0:55.7 | the victim has to enable editing. And in another version, it uses the rules where the document |
| 1:03.3 | claims to be encrypted. And again, enabling editing is supposedly then going to help you read |
| 1:09.0 | the document. Content security policy or CSP for |
| 1:15.2 | short is one way how websites can make exploiting cross-site scripting flaws a lot more difficult. |
| 1:25.3 | But deploying a meaningful content security policy is difficult. GitHub has been |
| 1:31.3 | publishing some blog posts about its CSP implementation and just published another one with some of the |
| 1:41.0 | CSP features they are using now to prevent actually also bypassing of CSP, |
| 1:48.3 | at least to prevent some of the more common techniques, how this is done. |
| 1:52.9 | So if you're interested in deploying CSP, I would highly recommend this blog post, |
| 1:58.6 | but also some of the earlier ones that GitHub published, |
| 2:05.8 | because they really go into some detail what features they're sort of using in CSP, |
| 2:11.7 | in particular for a large website like GitHub, of course. They had to be a little bit carefully in how they implemented. And for example, they do include some of the content |
| 2:17.2 | from their own Amazon cloud servers and such. |
| 2:21.4 | And so how they made that a little bit easier to filter with CSP. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

