ISC StormCast for Monday, September 14th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 September 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, September 14th, 2020 edition of the Sansonet Storm Center's |
| 0:07.4 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.3 | In diaries from this weekend, we got an interesting one by Rob about pillaging the clipboard. Of course, a lot of users are copy-pasting strings, |
| 0:24.9 | in particular hard-to-type ones like complex passwords. So Malware certainly has caught onto this |
| 0:33.0 | for a while now and tends to monitor the clipboard and then steal certain strings from the clipboard. |
| 0:42.1 | They have also been some cases where malware was looking for example for Bitcoin addresses, |
| 0:48.5 | which is another string that's often copy-pasted. |
| 0:51.4 | In this case, the goal wasn't so much to steal the address. That's the |
| 0:57.0 | public part, but instead modifying the address. So then the victim would inadvertently |
| 1:06.0 | send Bitcoins to the wrong account. From a defensive point of view, there isn't really that much |
| 1:12.6 | a user can do about all of this other than, well, not getting infected with Malver in the first |
| 1:20.0 | place. On the other hand, a lot of password managers, for example, try to keep the data on |
| 1:27.3 | the clipboard limited. I know the one password |
| 1:30.8 | manager I'm using. Now, that's on macOS. They'll automatically delete a password after |
| 1:37.3 | it's being pasted. Also delete them after a certain amount of seconds have been passed. |
| 1:45.8 | Now, Rob talks a little bit about this in Windows and states that this is not necessarily |
| 1:49.8 | always working as intended. |
| 1:53.0 | In particular, if you enable the clipboard history. |
| 1:56.2 | In this case, when software tries to override, meaning delete the clipboard, they're actually adding a new |
| 2:04.7 | empty entry to the clipboard history, which in some ways is sort of the intention behind this feature |
| 2:12.7 | in Windows. Also, a couple good user comments about this particular diary by Rob. And just one comment |
| 2:22.5 | from me, the fact that you can steal the clipboard if you have malware running on the system, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

