4.9 • 696 Ratings
🗓️ 2 November 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, November 2, 2020, 23 edition of the Sans and its Storm Center's Stormcast. |
0:07.5 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:14.0 | The bad guys are never shy to try out a new file format if they figure it allows them to bypass some kind of protection |
0:24.9 | mechanism. The latest example is a file format known by extension as CPAC and the idea behind |
0:34.4 | this file format, the legitimate idea is that it's an append only archive. So you can |
0:40.0 | essentially add various versions to the archive and with that then also sort of roll back, basically |
0:48.4 | the state of the archive. But that's actually not what the attacker is interested in here. |
0:55.7 | They're really just looking into bypassing the standard detection mechanisms by using a file format that's not quite that common. |
1:05.6 | Well, easy enough, I think, to block the .cpaq extension in whatever mail filters, web filters and such you have. |
1:17.9 | Haven't really seen this being used legitimately. |
1:21.7 | The file that Xavier is describing here is also very large once it is unpacked, which of course, then also as |
1:30.0 | discussed earlier this week, does sometimes help in bypassing security controls. And as a reminder |
1:37.6 | as of today, CVSS version 4.0 is official. Pretty sure we'll see 3.1 and such around for a while longer. |
1:48.0 | Just as people switch over to 4.0. A couple advantages of 4.0 is sort of some cleanup in a language, |
1:55.9 | but also, for example, better distinguishing between passive active user interaction and a couple |
2:03.4 | things that should make the CVSS score more telling. |
2:08.1 | Of course, there is still a lot of sort of flexibility as we have seen in the past and how |
2:12.4 | these particular categories are then going to be applied. |
2:17.4 | It looks like someone pulled the plug on the Mosey. categories are then going to be applied. |
2:22.5 | It looks like someone pulled the plug on the Mosey botnet. |
2:26.5 | Now, we have in the past, of course, seen law enforcement do similar things. |
2:31.6 | This does not appear to be a publicly announced law enforcement action. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.