meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 13th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 June 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More SandboxEscaper; Bypassing NTML Message Signing; macOS Keysteal Details @simakov_marina @LinusHenze

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 13th, 2019 edition of the Sansanet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and then I'm recording from Neptune, New Jersey.

0:14.1

So one of the highlights of yesterday's Microsoft Patch Tuesday was the patch for the four vulnerabilities that Sandbox Escaper published

0:25.6

in May. However, it looks like there may be a fifth vulnerability that Sandbox Escaper wrote about in the GitHub repository.

0:34.6

This is the polar bear repo repository and apparently

0:39.8

this particular version of the Vulnerably has not been patched it. It appears to be another

0:46.2

bypass of CVE 2019, 0841, at least according to the comments published with the proof of concept exploits.

0:56.8

Now, since then, the GitHub repository polar bear repo has been deleted.

1:03.3

There's still an archive available and I'll link to the respective archive in the show notes.

1:10.0

It's also not clear whether or not this particular repo was removed by GitHub

1:15.6

or if Sandbox Escaper was the one who removed it.

1:19.6

As other vulnerabilities published by Sandboxescaper,

1:23.6

it is a privilege escalation vulnerability,

1:25.6

so it would require that the attacker already has access to a system.

1:31.3

It may also require some limited user interaction.

1:37.3

Another follow-up story to Microsoft's patch Tuesday, CVE 2019 1040.

1:45.0

This is a message integrity code tampering vulnerability and we have more details about this vulnerability that was patched yesterday from preempt the company that originally discovered the vulnerability.

2:01.2

One of the more popular attacks against active director environments is NTLM relay, where an attacker

2:10.6

essentially getting in the middle and is relaying messages that are being exchanged between an authenticated client and a server.

2:21.2

In order to prevent these attacks and in order to prevent the attacker from tampering with these

2:26.5

authentication messages, Microsoft did introduce a mic or a message integrity code.

2:35.0

This is essentially a digital signature for these messages.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.