ISC StormCast for Monday, July 27th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 July 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, July 27th, 2020 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:13.0 | So a lot of modern desktop applications are actually using technologies that are typically more associated with web applications like, |
| 0:23.3 | for example, JavaScript. |
| 0:25.9 | Now, from a security point of view, this is not necessarily versed and sort of the existing |
| 0:30.4 | compiled applications, but does make it a little bit easier for NetHacker to modify the code after it has been downloaded |
| 0:40.3 | to the user's system. |
| 0:42.3 | We've got the interesting example here from Xavier who looked at a recent piece of malware |
| 0:49.3 | that abuses the Discord client. |
| 0:52.3 | Now Discord, of course, the online chat software that's quite popular these days. |
| 0:57.0 | And in this case, the ad hacker did inject additional JavaScript into the code after Discord |
| 1:04.0 | client to then exfiltrate user data. |
| 1:08.0 | And well, interestingly and probably even conveniently here with Discord, it used |
| 1:13.0 | Discord itself to exfiltrate the data. So the reason this is easier is that the attacker |
| 1:18.9 | does not have to recompile the application. They can just swap individual files that make up |
| 1:25.3 | the code for the application on the user's system. |
| 1:28.7 | This is not a vulnerability necessarily in the application other than the fact that it tends to be |
| 1:34.2 | quite difficult for these applications to ensure the integrity of the application as it is |
| 1:40.7 | put together from numerous different libraries and individual files that are then loaded |
| 1:47.5 | at runtime. As a user, there isn't really a lot you can do beyond, well, make sure where you |
| 1:53.1 | download extensions and such for this software from. And of course, Xavier has a walkthrough |
| 2:00.0 | how he analyzed this particular piece of malware. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

