ISC StormCast for Monday, May 3rd, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 May 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, May 3, 2021 edition of the Sandcent Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.0 | Nice little diary on Friday by Remko about quilling, at least. |
| 0:18.6 | That's how I think you pronounce this. |
| 0:23.1 | It's a framework that's, |
| 0:29.3 | well, I would say somewhere between sort of virtualization and debugger, but what it does allow you is it essentially allows you to run binaries across different operating systems and different |
| 0:36.3 | architecture in sort of a debugger-like environment. |
| 0:40.7 | Now, since the framework, it's very extensible and very customizable. |
| 0:46.0 | You can essentially a hot patch, some binaries that you're working on to, for example, bypass |
| 0:52.2 | certain functions that would otherwise lock you out or, for example, |
| 0:56.9 | detect that you are running in a debugger. |
| 1:00.0 | Sounds like a real useful tool for anybody doing serious reverse engineering. |
| 1:05.9 | And I hope Remko's post will cut the learning time a little bit short. |
| 1:11.9 | It's not the easiest tool to get started with, but he walks you sort of through the basic |
| 1:17.8 | functionality. |
| 1:20.0 | And it looks like the Python standard lip IP address is also suffering from an improper |
| 1:26.9 | input validation problem that we had in other languages |
| 1:31.5 | about a month ago or so I think I mentioned that. |
| 1:35.0 | The root cause here is that the library does not consider the octal format, which is valid |
| 1:41.2 | and used by libraries that usually set up the connection. |
| 1:46.0 | So for example, you're restricting your users to connecting to 10.d. addresses. |
| 1:52.0 | These libraries, like IP address in Python standard lip, will consider 010 as 10 and that'll pass. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

