ISC StormCast for Thursday, November 30th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 November 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, November 30th, 2017 edition of the Sandton and Storm Center's |
| 0:06.9 | Stormcast. My name is Johannes Ulrich, and the damn recording from Augusta, Georgia. Apple wasted no time |
| 0:14.7 | and released today an update for the high Sierra vulnerability that allowed logins as root without password. |
| 0:23.6 | The patch is only a little bit more than a megabyte in size. |
| 0:27.6 | It came out as Security Update 20071 and does not require a reboot of the system. |
| 0:36.6 | However, if you enabled the route account |
| 0:40.3 | either to protect yourself from the vulnerability or because you had another reason why you needed |
| 0:46.3 | the root account enabled, after you apply this patch it will be disabled again. So you will have |
| 0:53.3 | to reenable it if you need to on the other hand |
| 0:56.0 | if you do not need the route account then you're probably better off leaving it |
| 1:01.5 | disabled Apple also notes that after applying this patch you may have issues with |
| 1:08.0 | file sharing if you do run into the, there is a link to a fix within |
| 1:13.9 | the security bulletin. And mobile security company High Tech Bridge took a look at Android |
| 1:20.7 | Bitcoin application and shouldn't surprise anybody that they came up with some pretty grim |
| 1:27.0 | results. High Tech Bridge operates a free |
| 1:30.6 | online service, mobile x-ray that can be used to analyze mobile applications for vulnerabilities, |
| 1:37.5 | and of course they use that tool to examine a number of different crypto coin mobile applications. |
| 1:45.0 | Now just looking at the top 30 most popular applications, it looks like about a third of the applications |
| 1:53.0 | are vulnerable to man in the middle attacks, but the same number also has hard-coded sensitive |
| 2:00.0 | data like passwords or API key |
| 2:03.5 | 70% of the applications do still support SSL version 3 or TLS 1.0 so if you are using a |
| 2:14.6 | mobile application to keep your crypto coins, take a look at their list |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

