meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, May 23rd 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 23 May 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. OWASP Asking for Top 10 Overhaul Input; Missing MRU Registry Keys

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, May 23rd, 2016 edition of the Santernet Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich, and I am recording from Seattle, Washington.

0:13.8

If you are doing forensics on a system, one question that often needs to be answered is if a particular file, let's say some malware on the system, was opened by the user.

0:26.6

Pascal ran into an interesting issue here if this file is part of a SIP file.

0:32.6

Turns out that WINSIP, when you open the file directly, without first unsipping the

0:39.7

particular archive, does not record that a file was opened and so in an investigation

0:46.3

you may easily miss this particular artifact.

0:50.3

However, depending on the application that's then being used to open the file, for example,

0:55.7

Office or Adobe Agrabat, this application may very well record that the file has been opened,

1:04.6

but that apparently depends somewhat on the application that was used to open the file.

1:11.6

And OVASP is planning to overhaul and update its top 10 vulnerability list.

1:16.6

This is of course a big project, very visible, and they're now asking for input from the community

1:24.6

as to what vulnerabilities you're seeing in your environment.

1:29.3

The deadline for any submissions is July 20th and they tweeted a URL to a survey that you

1:35.7

can use to participate in this project.

1:40.1

The last version of the OVASp Top 10 was released in 2013.

1:44.8

This update may be released this year, but as the call for input points out, may have

1:51.6

to wait until next year.

1:54.3

And Google released version 4 of its safe browsing API.

1:59.1

This is in particular important for developers that integrate these

2:02.5

APIs into their own product. Now the main change here is that it is now possible to get

2:10.2

distinct lists for various device types. So for example, specifically for mobile devices.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.