4.9 • 696 Ratings
🗓️ 12 July 2017
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, July 13th, 2017 edition of the Sands and the Storm Center's Stormcast. My name is Johannes Ulrich and I am recording from Stockholm, Germany. |
0:12.8 | File integrity management is always a hot topic and, of course, important for security to make sure if files got changed and why they got changed. |
0:23.7 | Now, the first part, the if is actually not that hard usually, and Xavier has another trick |
0:30.1 | here to do this using backup files, given that backups are usually pretty good in identifying |
0:36.4 | files that changed in order to create incremental |
0:39.5 | backups. He mentions R-Sync as a tool to do that with. Our sync actually can use things |
0:46.8 | like checksums to compare files, so it doesn't just rely on the file date, for example, or the size of the file. |
0:56.2 | So this is, in my opinion, actually, the easy part of file integrity management. |
1:00.9 | The hard part is then to always go through these reports and figure out which files are |
1:06.5 | supposed to change. |
1:08.1 | For example, libraries may be updated by automatic update processes. |
1:14.2 | Change control really has to tie into this as well. Otherwise, you will very quickly get overwhelmed |
1:20.9 | by these reports. Ethereum is a new and up-and-coming cryptocurrency that in many ways even surpasses the |
1:30.0 | mindshare of Bitcoin at this point. |
1:34.4 | It's not quite as big yet, but has been rising very steadily until recently. |
1:40.9 | So no big surprise that criminals are turning from Bitcoin to Ethereum to find new victims. |
1:49.7 | In particular, a wallet service called My Ether wallet appears to be a target here of these scams. |
1:58.3 | Now, these scams don't really use traditional fishing via email. Instead, they're |
2:03.3 | using new media like Slack and Reddit in order to impersonate official My Ether wallet chatbots. |
2:13.1 | Over the last six days, it appears that these attacks did steal around $700,000 worth of |
2:22.0 | crypto coins from various users. |
2:25.8 | Now, this attack is not a breach in My Ether wallet. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.