ISC StormCast for Monday, October 16th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 October 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, October 16th, 2017 edition of the Sands Internet Storm Center's Stormcast. |
| 0:08.5 | My name is Johannes Ulrich, and today I'm recording from Singapore. |
| 0:12.7 | Of course, malware still frequently arrives as an email, which often requires that you extract it out of an Outlook message file. Well, Did he took a look today |
| 0:23.7 | at Outlook Message files to explain how they are exactly composed and how to extract these |
| 0:30.6 | malicious attachments directly out of the message file. And he shows how to use O Oli Dump in order to accomplish this task. |
| 0:40.3 | Well, if your users don't receive Malra via email, they probably will do so via a website. |
| 0:48.3 | And last week we had yet another case where abandoned domains and included content in a website did cause |
| 0:57.0 | problems. This time it was already battered Equifax but also a number of other sites |
| 1:04.0 | including the Equifax competitor TransUnion who were exposed to this particular flaw. |
| 1:11.3 | The root cause here was a tool called FireClick that was installed on the affected websites. |
| 1:17.8 | FireClick is one of these user analytics tools. |
| 1:21.9 | It has been discontinued by its parent company Digital River for a while now. |
| 1:27.2 | And when discontinuing the tool, |
| 1:29.7 | they actually didn't renew an associated domain name, which was now picked up by some |
| 1:37.0 | advertising firm that used it to push fake Flash Player Update ads. |
| 1:43.5 | One problem I often find with websites is that they include numerous tracking and user analytics |
| 1:52.6 | tools, often with redundant functionality, which kind of indicates that probably these tools |
| 1:59.0 | get always added and old tools never get removed |
| 2:02.9 | once they're actually no longer useful and this opens these websites up to these kind of compromises. |
| 2:11.3 | If you are running a website that does use these third-party tools, then please occasionally do go over all of these |
| 2:20.1 | tools, make sure they're still serving a purpose and they're still being supported. |
| 2:25.8 | And apparently a number of Windows 10 and 2016 server machines refuse to reboot after applying |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

