ISC StormCast for Thursday, March 9th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 March 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, March 9th, 2017 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.3 | My name is Johannes Ulrich, and I am recording from Jacksonville, Florida. |
| 0:12.7 | A few days ago, Nintendo came out with its new Switch console, and well, of course, there is now a pretty intense search for possible |
| 0:24.0 | vulnerabilities in this new toy. Probably it's almost more surprising that there is no exploit |
| 0:31.1 | out yet after a couple of days of searching but on the other hand there are already a couple of days of searching, but on the other hand, there are already a couple of smaller |
| 0:40.3 | hints that may lead to exploitation in the future. One thing that sort of limits the attack |
| 0:47.7 | surface of this console is that it doesn't come with a web browser. Well, at least it's not |
| 0:53.9 | advertised. There is actually a |
| 0:56.1 | hidden web browser installed on the console, and that web browser is launched whenever the user |
| 1:03.1 | connects to a Wi-Fi network that requires the user to log in. Many Wi-Fi networks, of course, |
| 1:09.5 | have these pages that you have to acknowledge |
| 1:12.3 | or you have to enter some credentials in order to connect. And for this purpose, they did install |
| 1:19.1 | this browser. And of course, at that point, it's possible to exploit various browser vulnerabilities. |
| 1:27.2 | The browser appears to be WebKit-based. |
| 1:29.9 | WebKit has had vulnerabilities in the past, and there are probably more to go. |
| 1:35.0 | Also, the stage fright library is installed on the console, so in conjunction with the browser, |
| 1:42.4 | there may be a way to exploit it. |
| 1:44.3 | Well, on the other hand, even if there is a vulnerability, it will be difficult to exploit. |
| 1:49.9 | The console does use the arm trust zone. |
| 1:53.5 | So that's supposed to secure applications by running them in a sandbox. |
| 1:59.6 | We'll see what's going to happen. |
| 2:01.6 | Nintendo has put out a $20,000 buck bounty |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

