ISC StormCast for Thursday, September 14th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 September 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, September 14th, 2017 edition of the Sandinert Storm Center's Stormcast. |
| 0:08.2 | My name is Johannes Ulrich, and the time recording from Las Vegas Levada. |
| 0:12.9 | Rob is covering today one of my favorite topics in his diary, and that's IPV6, in particular networks that believe that they are not using IPV6. |
| 0:25.3 | Most modern operating systems have IPV6 enabled by default, which means that you may not have |
| 0:32.3 | any infrastructure providing IPV6 connectivity, but your operating systems are almost always set up for IPV6. |
| 0:42.5 | So all NetHacker, or in Rob's case, a pentester has to do is provide that infrastructure for you, |
| 0:49.9 | and they're now able to move around your network, pretty much unimpeded by any of your security devices. |
| 0:59.8 | So whenever you have an assumption like that you're not using IPV6, always back it up by actually |
| 1:07.2 | making sure that you detect any rogue IPV6 traffic. |
| 1:12.1 | And Rob also provides some advice in how to configure switches and the like in order, |
| 1:17.7 | for example, to prevent rogue routers from offering IPV6 addresses. |
| 1:23.2 | Probably the most serious vulnerability was addressed in Microsoft's Patch Tuesday this week |
| 1:30.9 | was CVE 2017-8759. |
| 1:36.1 | This was the dot-net soap parser vulnerability that was exploited by Finn Fisher. |
| 1:42.0 | If you remember, Finn Fisher is an APT campaign that was described by Fire Eye, |
| 1:50.1 | and the exploit arrived as a VIRD document. Well, we now have a detailed tutorial about how |
| 1:57.9 | to exploit this particular vulnerability. |
| 2:01.3 | Turns out it's actually pretty straightforward to create a malicious RTF document |
| 2:06.6 | that will exploit this vulnerability. |
| 2:10.7 | Again, the RTF document and VERT is really just a delivery vector. |
| 2:15.0 | The actual vulnerability was in the dot net component that parses |
| 2:19.7 | the malicious file. Given these instructions and the easy exploitability, this is definitely a must-patch |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

