ISC StormCast for Monday, October 30th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 October 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, October 30th, 2017 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich and the Am recording from Berlin, Germany. |
| 0:12.7 | Oracle released an interesting security bulletin and patch for Oracle's identity manager. |
| 0:19.1 | The identity manager is part of Oracle's Fusion middle Manager. The Identity Manager is part of Oracle's Fusion Middleware. The update hasn't |
| 0:25.5 | gotten a lot of press being released on Friday, but the vulnerability has a CVSS score of 10, |
| 0:33.8 | indicating that it can be exploited remotely without authentication and successful exploitation |
| 0:40.4 | will lead to a complete system compromise. All current supported versions up to 12.2.1.3 are affected. |
| 0:52.3 | Oracle's last critical patch update was released in October 17th. |
| 0:57.7 | This issue with a CVE number of 2017-10-151 |
| 1:04.3 | was not addressed in the Critical Patch Update. |
| 1:10.3 | And Renato came across yet another malicious Google Chrome extension. |
| 1:16.2 | This particular extension is advertised via spam that claims to contain a WhatsApp message. |
| 1:24.3 | And it tricks the user into downloading and installing the malware by |
| 1:28.6 | camouflaging it as a flash update of course flash update we have seen a lot |
| 1:34.9 | one interesting trick employed by this malware is that it intentionally |
| 1:40.3 | floats its size to evade antivirus the The download itself, a zip file, is a bit less |
| 1:47.5 | than 10 megabytes in size, but it uncompresses to 200 megabytes of executable code. Most of the |
| 1:56.3 | executable is no-ops, but due to the size of this binary, some anti-malware products may just not scan it. |
| 2:06.5 | Only about 3% of the binary, so only about 6 megabytes, which is actually less than the compressed |
| 2:14.2 | size, are actual executable code once the no-ops are removed. |
| 2:20.3 | The executable will then, if executed, disable the Windows firewall. |
| 2:27.5 | It will crash Chrome and then install itself as a Chrome extension. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

