ISC StormCast for Monday, July 10th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 July 2023
⏱️ 4 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, July 10, 2020, |
| 0:05.0 | edition of the Sansonet Storm Center's Stormcast. |
| 0:09.4 | My name is Johannes Ulrich, |
| 0:11.3 | and today I'm recording from Washington, D.C. |
| 0:14.7 | arrived earlier today here for Sands Fire, of course. |
| 0:19.7 | I frequently talk on this podcast about DDA's malware analysis tools. |
| 0:25.7 | They're famously effective, for example, if you are attempting to analyze malicious office |
| 0:33.2 | documents, but also a number of hand utilities that are part of DDA's tool suite. |
| 0:40.5 | Well, it can be a little bit tricky to get them all installed and such, so Xavier did publish |
| 0:47.3 | a Docker container with all of DDA's tools pre-installed, and just this weekend announced that he updated it with the |
| 0:56.0 | very latest version, also fixing some issues that the Docker container had. So this is probably |
| 1:03.3 | your simplest way to get started with all of these tools if you have not yet installed them |
| 1:09.0 | directly on your system. And in addition, if you are analyzing yet installed them directly on your system. |
| 1:11.4 | And in addition, if you are analyzing Malware, |
| 1:14.6 | having the analysis happening in a container, of course, |
| 1:17.8 | gives you a neat additional level of isolation. |
| 1:22.8 | And I told you to keep watching out for new Movit vulnerabilities. |
| 1:28.2 | Well, progress software, the company behind Moved, |
| 1:31.6 | released a service pack fixing yet another critical sequel injection vulnerability. |
| 1:39.0 | Exploiting of the vulnerability does not require authentication, |
| 1:43.9 | and with that, the attacker could modify the data |
| 1:48.8 | or retrieve data from the database. It doesn't mention anything here about remote code execution. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

