4.9 • 696 Ratings
🗓️ 4 May 2020
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, May 4th, 2020 edition of the Sandcent Storm Center's Stormcast. |
0:07.4 | My name is Johannes Ulrich. |
0:09.1 | And today I'm recording from Jacksonville, Florida. |
0:13.0 | Last week I mentioned a post by Dede about Malware Bazaar, the site where you can download malicious samples now. |
0:22.7 | They, of course, encrypt those samples before you download them in order to not trip any kind of anti-malware, |
0:30.0 | but also to sort of protect the innocent here. |
0:32.6 | A little problem with the format of encryption they used. |
0:36.8 | The SIP encrypted files that they're |
0:39.1 | offering are encrypted using the AES algorithm. Nothing really special about AES, the advanced |
0:46.0 | encryption standard, very well established and good encryption algorithm. But what it means is |
0:51.9 | that in Python, the normal SIP file module is not able to decrypt them. |
0:58.5 | And that affected a lot of DDA's tools, so he's now switching over to Psipper, another |
1:05.8 | SIP library for Python, and that one is able to deal with AES encrypted files. |
1:14.3 | And Friday, I mentioned a vulnerability in the infrastructure automation suite salt stack. |
1:21.7 | Well, I also mentioned that it's probably not that hard to come up with an exploit for this vulnerability. |
1:28.1 | And sadly, well, I probably underestimated the severity here somewhat because over the weekend, |
1:33.9 | a number of sites very hit using this vulnerability. One of the most famous examples on a link |
1:42.1 | to their status page is the ghost blogging platform. |
1:47.2 | But a number of organizations are reporting active exploitation of this vulnerability and |
1:52.7 | at least scans for vulnerable systems. |
1:56.2 | So if you haven't upgraded yet, this is something that you really have to do today |
2:02.0 | if your salt server is exposed to the Internet. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.