ISC StormCast for Thursday, July 23rd 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 July 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, July 23, 2020 edition of the Sandstone Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.3 | And today I'm recording from Jacksonville, Florida. A little bit of a wrap-up about the F-5 vulnerability. That was CVE 2020-902 from Rick today. Now, Rick spots still some exploitation |
| 0:25.0 | against this vulnerability and noticed one binary in particular being downloaded from |
| 0:32.8 | an IP address that he's sharing in this diary. In addition, we also got some user comments. |
| 0:39.2 | And yes, it's something I observed too where attackers are adding users to the system. |
| 0:45.3 | So double check your Etsy password and also your Cron tab. |
| 0:49.9 | That's typically what we have seen in the last few days, how attackers are taking advantage |
| 0:56.0 | of this vulnerability. |
| 0:58.0 | And then we got a new set actually of vulnerabilities, including proof of concept code that |
| 1:06.0 | does show how signed PDF documents may be modified without it actually being visible |
| 1:13.9 | in common viewers. So the idea of a signed document is that you add a digital signature, |
| 1:21.4 | encrypted hash, and that it does protect the entire document. Now, in many variations of this, |
| 1:29.7 | only a certain part of the document is protected, |
| 1:33.4 | and it has been tricky to then properly communicate |
| 1:37.9 | which part of the document is actually protected |
| 1:42.1 | and which one isn't. |
| 1:44.0 | And that apparently is sort of a little bit the root cause here of some of these vulnerabilities. |
| 1:49.3 | Now, the first vulnerability, they're talking the universal signature forgery. |
| 1:54.0 | That's a little bit simpler. |
| 1:55.5 | All you do is you essentially modify the signature so it is corrupt. |
| 2:00.3 | This will sometimes, and that depends on the viewer, prevent validation of the signature so it is corrupt. This will sometimes, and that depends on the viewer, |
| 2:03.3 | prevent validation of the signature, but the signature will still be displayed. The scenario I initially |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

