ISC StormCast for Monday, January 9th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 January 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 9th, 2017 edition of the Sands and the Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.7 | We got a couple of stories related to security tools to start out with. |
| 0:17.8 | First, John posted about how he found various cookie databases that appear |
| 0:23.4 | to originate from browsers in Virus Total. VirusTotal as a paid service offers subscribers to |
| 0:31.2 | search through all submitted files, even those that do not lead to any hits when inspected by virus totals, malware scanners. |
| 0:41.0 | John, for example, has some Yara rules that he is using to search for domain names that he |
| 0:46.5 | owns to see if they show up in any malware. |
| 0:49.5 | And of course, malware that wouldn't be detected by standard end of virus engines would be |
| 0:53.9 | particularly interesting here. These files are often... Of course, malware that wouldn't be detected by standard in the virus engines would be particularly |
| 0:54.5 | interesting here. |
| 0:56.2 | These files are often of specific interests to researchers as a result. |
| 1:02.8 | But some security tools submit all unknown files they encounter to virus total for inspection. |
| 1:10.7 | As a result, confidential data often then ends up in |
| 1:13.8 | virus total like these cookie files and then can be downloaded by anybody with a paid |
| 1:19.3 | virus total subscription. So be careful when submitting data to sites like virus total. Often, all you |
| 1:26.9 | really have to do is submit a hash of the file. |
| 1:29.5 | And of course, you don't reveal the content of the file. There are also, for example, |
| 1:34.1 | email gateways that submit all attachments to VirusTotal. Particularly often homemade solutions |
| 1:40.3 | do that. Don't do it. You're really exposing all of your confidential data that way. |
| 1:47.0 | Secondly, Xavier reminds us that security tools often run with elevated privileges and if compromised, |
| 1:54.0 | these privileges can be leveraged by NetHacker to further compromise network. For example, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

