meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, May 31st 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 31 May 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Windows JScript Vulnerability; Git Vulnerablity; SpamCannibal Blacklist;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, May 31st, 2018 edition of the Sansonet Storms and Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:12.1

Trent Micro's Seraday initiative released an advisory making public a remote code execution vulnerability in Windows JScript.

0:21.6

This means that essentially an attacker would be able to execute code using malicious JavaScript.

0:29.6

Now I think there are two reasons why you shouldn't really be panicking about this disclosure.

0:35.6

First of all, while this does execute code, it is still limited by

0:40.7

the browser sandbox, so you would need a second exploit to break out of the sandbox and

0:46.4

really compromise the system. Secondly, there are literally dozens of bugs like this that Microsoft fixes each year.

0:56.5

I think there are probably a few dozen more out there.

0:59.3

This is just one more J-Script vulnerability.

1:03.3

And I hope come June patch Tuesday, Microsoft will release a patch for this.

1:09.6

But talking about vulnerabilities, there's actually what I consider a more severe vulnerability

1:15.2

in Git.

1:17.0

And this is one that has been patched today.

1:19.8

And it could lead to arbitrary code execution if you clone a malicious repository.

1:26.7

The problem here is that on the client side, when you clone a malicious repository. The problem here is that on the client side when you clone a repository, you can define post-checkout scripts.

1:35.3

These scripts run after you check out the repository.

1:39.3

Now, of course, these scripts are not downloaded from the repository.

1:43.3

However, due to this vulnerability that does affect submodule repositories, it is possible

1:51.5

for an attacker to set up a malicious repository that will then lead to script execution

1:58.8

using these post checkout hooks.

2:01.6

Interesting vulnerability and something that you should definitely patch.

2:06.6

In particular, if you clone repositories that you don't necessarily control.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.