meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, December 8th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 8 December 2016

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. AV Exclusion Abused by Targeted Attacks; Android Update; Firefox SVG XDomain Cookies

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, December 8th, 2016 edition of the Sansonet Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.5

And today I'm recording from Jacksonville, Florida.

0:12.9

False positives in antivirus systems is sort of an ongoing issue that doesn't seem to be going away.

0:19.3

Now, some software vendors are taking the

0:22.9

step of publishing antivirus exclusion lists where they essentially tell you how to configure

0:28.7

your antivirus in order to minimize the risk of false positive disrupting their software.

0:36.2

This usually includes that you should exclude from your antivirus certain directories,

0:42.0

certain file types, and the like.

0:44.3

And apparently the bad guys are listening as well, and they're reading these exclusion lists,

0:50.5

and in some cases in particular, in targeted attacks attacks are tailoring their malware to match patterns that this particular software vendor, and there's more than one doing it, recommended to exclude.

1:05.0

The sad part, of course, is that there isn't a simple rule that you could follow how to apply these exclusion lists securely

1:12.4

or whether or not to apply them at all. If you do not follow the software vendor's advice

1:19.2

and you leave your antivirus wide open, then of course you are at risk of running into a false

1:26.1

positive which may disrupt and even render unusable that

1:31.1

particular piece of software. And then, of course, if you do follow that vendor's advice,

1:36.5

then, well, you leave the door open for malicious software. Now, of course, it doesn't always have

1:42.7

to be all that terribly targeted. One of the

1:45.5

examples list in the article is Citrix, which publishes a quite extensive exclusion list. Well,

1:52.8

most large enterprises use Citrix in some capacity, so it would be a pretty safe bet to assume

2:00.1

that that particular guidance is implemented.

2:03.6

And Google released the monthly update for Android.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.