meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, July 21st, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 21 July 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Python Ducky; Apple Patches; Zyxel Vuln; DNS over HTTP/3; Atlasian Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, July 21st, 2020 edition of the Sansanet Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich.

0:09.6

And today I'm recording from Jacksonville, Florida.

0:13.5

Xavier wrote about an interesting, malicious Python script.

0:18.2

He compares it to rubber ducky.

0:20.8

If you're not familiar to rubber ducky.

0:26.0

If you're not familiar with Robert Ducky, it's a USB stick that simulates a keyboard.

0:33.5

Robert Ducky can be programmed to send keystrokes to a victim's system and then executing malicious script.

0:37.9

So you would plug it in claiming it to be a memory stick,

0:41.9

but it will actually then execute malicious code.

0:47.2

Similarly, this Python script uses an auto-Gui library intent to automate interactions with graphical user interfaces.

0:51.7

The script Xavier found uses this module to simulate the command

0:57.6

R keystroke to launch command.exe, terminal, and will then send keystrokes for a PowerShe

1:05.6

one-liner to command.exe to connect to a server, awaiting additional commands.

1:13.1

Of course, this works, and question always is,

1:15.3

why would an attacker go through trouble to write a script like this?

1:20.6

Most likely they're trying to obfuscate the code,

1:23.7

so it's not really going to get detected by anti-malver

1:27.2

and the low virus total

1:29.9

score that this script has appears to validate that decision so far.

1:36.9

And Apple today released its usual surprise update for all of its operating systems. Apple, of course,

1:43.3

doesn't have a scheduled patch day and also

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.