ISC StormCast for Monday, September 18th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 September 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, September 18th, 2017 edition of the Sandinand, Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Las Vegas, Nevada. |
| 0:12.5 | Checkpoint last week tried to make some waves by announcing a new vulnerability that checkpoint called Bashfare. This vulnerability attempts to take advantage of |
| 0:24.7 | the Windows subsystem for Linux or short WSL, which recently left the beta stage and should be included |
| 0:34.9 | in the fall creator update for Windows 10. |
| 0:39.7 | The basic issue that Checkpoint is pointing out here is that binaries running within this Linux sub-system |
| 0:48.3 | aren't necessarily properly inspected by anti-malware. |
| 0:54.1 | However, in order to actually execute these binaries, |
| 0:58.9 | it does take a number of dependencies. The Windows subsystem for Linux is not enabled and |
| 1:05.7 | installed by default, so an attacker would have to install it in older versions of a Windows 10 or if it's |
| 1:14.3 | already installed the attacker would have to enable it requiring the attacker to modify |
| 1:19.9 | registry entries which typically requires that the attacker already has |
| 1:25.2 | administrative access to the system. |
| 1:28.8 | So what this really comes down to is if an attacker is already an administrator on the system, |
| 1:35.0 | then yes, they can bypass some security features, |
| 1:39.9 | which at this point probably isn't really all that relevant anymore. |
| 1:45.2 | Of course, still like any feature, if you don't need it, |
| 1:48.4 | you may be better of disabling it in order to reduce the attack surface on your system. |
| 1:55.4 | So if you don't need WSL, then just don't install it. |
| 2:08.6 | And ESET is reporting that they found JavaScript cryptocurrency miners being distributed via malicious advertisements. |
| 2:09.6 | JavaScript is of course able to use a number of different hashing and crypto functions, |
| 2:16.6 | recent versions of JavaScript even include specific |
| 2:20.7 | APIs to do so. The advertisements that ESET is pointing out here did not actually mine |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

