ISC StormCast for Thursday, June 15th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 June 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, June 15, 2020, edition of the Santonet Storms, Stormcast. |
| 0:07.9 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.8 | Today I would like to start out to thank all the Malver authors that keep coming up with |
| 0:19.2 | interesting obfuscation techniques for Didy to reverse. |
| 0:24.4 | Today, Didier is looking at an obfuscated visual basic script and shows how to, well, |
| 0:32.1 | use a combination of standard command line tools like starting out with grep and the like, and then quickly moving |
| 0:39.3 | to DDA's own public domain tools like REsearch.P.I and sets.P.I.2. |
| 0:48.0 | Then further manipulate the payload and reverse engineer it in order to obtain the de-obuscated script. |
| 0:57.0 | Pretty nice analysis and as usual highly recommended if this is the kind of work that you |
| 1:05.0 | like to do or have to do as part of your day job. |
| 1:10.7 | Researchers from the Rue University, Bohm, did publish a paper outlining some weaknesses |
| 1:18.2 | in the Microsoft Office Open Office XML signature. |
| 1:24.6 | Despite the name Open Office, Microsoft Office documents are created using the Open Office |
| 1:31.0 | XML standard, which, well, is a rather complex standard. If you ever looked at an office document, |
| 1:37.9 | it's usually a SIP file, actually, when you're looking at the dot-docx file, that contains a number |
| 1:44.0 | of different XML files. |
| 1:47.0 | The problem with these signatures is that they allow for only some of these files to be signed. |
| 1:55.8 | So an attacker, of course, may alter any files that are not signed, with that of course change the content that's |
| 2:04.3 | displayed to the user. For example, what fonts are being used is not typically part of the |
| 2:11.3 | signed parts. Changing fonts, of course, will easily then allow an attacker to change what's being displayed as |
| 2:19.1 | the user opens the document without actually alerting the user of a changed or broken signature. |
| 2:26.9 | There are various attack scenarios that are outlined in the paper too much to really adequately |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

