meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 20th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 20 April 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. More About #Excel Macros; Bose SpyPhones; Own/NextCloud Buggy Bugreports

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, April 20th, 2017 edition of the Santonet Storms and Stormcast. My name is Johannes Ulrich and the I'm recording from Jacksonville, Florida.

0:13.0

Xavier today looked again at malicious Excel files. That's probably one of the most common ways that you will find at hackers trying to sneak

0:22.6

malicious code into your network.

0:25.6

Now filtering these Excel files and analyzing them is of course quite important and Xavier's

0:32.6

taking a look at them, in particular those Excel files that store, for example, the URL that's being

0:39.2

used to download additional data in hidden columns and cells within the Excel file.

0:46.4

And of course, as we are used to from Xavi, he also provides us with the Python scripts to do

0:51.8

this all ourselves. So all you have to do is run his Python script

0:56.6

and you get the content back of these cells.

1:00.7

He also has a little Python script

1:03.2

that will then extract binaries

1:05.4

that may come as part of the Excel spreadsheet.

1:10.5

And if you used some recent Bose wireless headphones,

1:15.2

you may have noticed that they come with a little app that you can install on your smartphone.

1:21.0

Well, it turns out according to a complaint filed in court yesterday that this app will also report back to Bose what you are

1:31.6

listening to. Now, the court document doesn't specify how it was discovered that this is what the

1:37.6

app was doing, but the complaint is specific enough in saying that segment.io, which is a marketing analysis company,

1:47.2

was actually at the receiving end of this data, transmitted very serial number of the headphone,

1:54.4

and then what kind of music or podcast or the like the listener was listening to.

2:01.6

It'll be interesting to see what comes out of this.

2:04.6

You can still use your headphones without the Bose Connect app,

2:09.6

but part of the selling point of these headsets is that you can control them with this app.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.