ISC StormCast for Thursday, May 18th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 May 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, May 18th, 2020, edition of the Sands and at Storm Center's |
| 0:08.2 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.5 | Savvy wrote a quick diary about an increase in the use of self-extracting rar files that he's observing. |
| 0:24.0 | Self-extracting files are always interesting because by definition, as they're being |
| 0:29.5 | expanded, they will execute code. |
| 0:32.8 | Same here with these rar files. |
| 0:35.9 | The attacker can pretty much just include a simple visual basic script |
| 0:40.3 | as is shown in this example and then execute it as the files are being expanded. |
| 0:47.6 | Most of the files in the archive are actually harmless and just garbage data, but the script |
| 0:54.0 | and a couple configuration files to go with it |
| 0:56.4 | are what actually causes the damage here. |
| 1:00.3 | Xavier offers a Yara rule to detect self-extracting RAR files. |
| 1:06.5 | They shouldn't really be that hard to spot given that usually they also just use dot eXE as an extension, |
| 1:12.9 | which probably should be treated with caution anyway and stripped out in any mail filters. |
| 1:21.3 | And then we have an interesting vulnerability in Waymo smart plugs. |
| 1:26.1 | These smart plugs are made by a Belkin and it's a pretty straightforward buffer |
| 1:31.9 | overflow in the friendly name. The name is supposed to be up to 30 characters long, but this |
| 1:39.8 | limit is really only enforced in the app that's used to control the plug. |
| 1:44.5 | If you can send the update name command directly without the app, |
| 1:49.0 | then you can specify whatever length you want, giving you ample space for a buffer overflow. |
| 1:55.0 | Amid Serper and Ruhn Yaka, who discovered the vulnerability, did write a lengthy blog, including |
| 2:02.7 | proof-of-concept exploit code. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

