4.9 • 696 Ratings
🗓️ 23 December 2021
⏱️ 4 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, December 23rd, 2021 edition of the Sansonet Storms, Stormcast. My name is Johannes Ulrich. |
0:10.0 | And today I'm recording from Jacksonville, Florida. |
0:13.8 | It's a brief podcast today. And, well, first of all, we do have a solution to our December Forensics Challenge, Brad Post's solution, and congratulations to our lucky winner who has been notified. |
0:30.1 | And of course, thanks to everybody who participated in this challenge. |
0:35.0 | And if you participated and wondered if you got it right, well, just |
0:38.7 | check Brad's solution that he posted. And remember back in September, one of the Microsoft |
0:47.8 | patch Tuesday patches that got us excited was, well, CVE 2021, 44444. It had a CVSS score of 8.8 and it was a remote code |
1:00.0 | execution flaw in MSHtml. This particular vulnerability has been heavily exploited and it relied on |
1:09.0 | the use of Microsoft cabinet or dot cap files. However, since then, |
1:15.0 | turns out that there is a bypass for the patch if a specifically crafted RAR file is delivered |
1:23.5 | instead and apparently this is now being exploited. |
1:28.3 | Apparently it's being used as part of a forum book, Malware campaign and well, that's |
1:33.3 | sort of a somewhat run-of-the-mill kind of Malware campaign. |
1:37.3 | So given that they're using it, the more sophisticated attackers have certainly taken notice. |
1:43.3 | However, they only apparently used it |
1:45.8 | for a short amount of time. And one problem with this modified RAR format may be that older |
1:53.9 | versions of the WynRRR utility are actually not able to open these files. So if you're still running old Winner Are, |
2:02.8 | then of course the attack will not work. |
2:06.6 | In particular, of course, these type of attacks |
2:08.8 | that go sort of after mass users, |
2:12.8 | they usually rely on old software running on systems |
2:17.4 | and are less successful and probably not |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.