ISC StormCast for Monday, March 2nd 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 March 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, March 2nd, 2020 edition of the Sansonet Storms on us Stormcast. |
| 0:06.9 | My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:12.2 | A couple interesting diaries from this weekend. |
| 0:15.9 | First, Xavier took a closer look at the Windows clipboard. |
| 0:20.4 | What inspired him here was a vulnerability was discussed last week, |
| 0:25.1 | and I think I mentioned it here in the podcast as well, |
| 0:28.2 | that on iOS applications have access to the global clipboard. |
| 0:33.6 | So if you're copying some text in one application, |
| 0:37.3 | other applications may read that text from the clipboard. |
| 0:42.2 | Well, in Windows, of course, we don't even expect kind of any separation like this. |
| 0:47.3 | So very logical that, yes, any application can read the global clipboard. |
| 0:54.3 | And what Xavier here did as an experiment is a little PowerShell script that will essentially |
| 0:59.4 | monitor the clipboard every 0.1 seconds and then display whatever text it finds. |
| 1:05.4 | A couple more sort of interesting items that he ran across here was virtual machines. |
| 1:09.9 | If you do integrate the virtual machine |
| 1:13.0 | with the host, then the virtual machine does have access to the host. Clipboard, that's |
| 1:18.9 | part of that copy-paste functionality into the clipboard. Of course, this could become a problem |
| 1:24.2 | if you're using that virtual machine to analyze malware. But for malware analysis, |
| 1:29.3 | you definitely want to keep those virtual machines isolated. Secondly, also iOS devices clipboard |
| 1:36.1 | was visible on his machine. The trick here is iCloud. ICloud has this feature where it does help |
| 1:42.7 | you synchronize clipboards. So again, that leads to content |
| 1:47.6 | that you copied on the iPhone or iOS device to show up on your desktop. It doesn't really |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

