meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 3rd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 3 November 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DarkVNC History; Sigstore; URLScan.io Leak; Checkmk Exploitation

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, November 3, 2020 edition of the Santernate Storm Center's Stormcast.

0:09.0

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:14.0

Brad's diary from today goes a little bit of different route than what he usually does.

0:20.0

He's not looking at sort of one specific infection,

0:23.7

but really more looking at how a particular tool,

0:27.2

dark VNC, evolved over time.

0:30.8

Now, first time that Pratt was able to find,

0:34.3

or the earliest sample that Pratt was able to find is sort of from the 2012-2013

0:41.3

time frame, but then he hasn't seen it much sort of just occasionally until sort of mid-2021,

0:49.4

when it sort of really showed up much more common.

0:53.5

You're probably familiar with the tool VNC, the virtual network computing, which is a remote admin

1:00.1

tool, legitimate tool, often, of course, abused.

1:03.6

But that's not what we talk about here.

1:06.2

Dark VNC or another variant, sometimes called hidden VNC, essentially uses the same sort of network

1:13.0

protocol and capabilities.

1:14.8

So from an attacker's point of view, it looks very similar, but it removes some of the

1:20.2

indicators that a user may see of this tool running on their system.

1:25.5

That, of course, makes it ideal for malicious remote access to a system

1:30.7

and Brad is going over some of the network traffic patterns that you may see if a system is

1:38.3

infected with dark VNC, VNC, hidden VNC, the network traffic for all these tools looks somewhat similar.

1:49.0

Well, I haven't really seen a lot of sort of news articles reporting about the open source

1:55.2

security foundation, finally releasing version 1.0, so the general availability release of Sixth Store.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.