meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, January 26th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 26 January 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. More Cisco WebEx News; Malicious #SVG Files; W2 Scams Are Back

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, January 26, 2017 edition of the Sandsenet Storm Centers, Stormcast. My

0:07.9

name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. It looks like the Cisco

0:14.1

WebEx plugin issue will stick with us for a little bit longer. First of all, Cisco released an updated bulletin, including

0:23.6

Firefox and an explorer in the list of vulnerable browsers. So it's not just Google Chrome.

0:30.6

Some of expected, given the nature of the flaw, it wasn't specific really to Chrome, but more to the way that this plugin works.

0:40.2

Second, Travis Ormandy from Google, did state that they found additional remote code execution

0:46.8

vulnerabilities in the plugin. Now, there are no details known yet about these vulnerabilities.

0:53.3

They have reported them to Cisco, so hopefully

0:56.0

Cisco will release updates soon. If you are relying on WebEx and if that's your remote

1:03.8

communication suite of choice, you probably use it several times a day. There isn't really much

1:09.6

you can do at this point other than

1:12.6

possibly disabling the plugin if you're not actively using it that may help here

1:19.6

or just use one browser with the plugin installed for your video conferencing needs

1:26.6

and then set up a second browser for all of your

1:30.9

other browsing. But just to be clear, the big deal here was that there was an exploit available

1:36.1

for this vulnerability. That vulnerability has been fixed. The other vulnerabilities, there

1:41.1

is at least no public exploit at this point, so you may have a little bit

1:46.4

time to wait for Cisco to come up with a patch. And Xavier wrote up a malicious SVG file that he

1:55.6

found in the wild. Now SVG are images that distinguish themselves by being vector-based. So this way they

2:04.0

nicely scale SVG stands for scalable vector graphic. In addition to just having sort of expressions

2:11.8

for lines and circles and alike, you may also embed JavaScript in these images in order to modify these SVG images

2:22.1

on the fly. Of course, this can be abused, and that's what these malicious files took advantage

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.