ISC StormCast for Thursday, September 28th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 September 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, September 28, 2017 edition of the Sandcent Storm Center's Stormcast. |
| 0:08.6 | My name is Johannes Ulrich, and I'm recording from Baltimore, Maryland. |
| 0:13.5 | Did he today conclude his three-part diary about a resume PDF that he received? |
| 0:20.7 | If you remember, one of the sticking points kind of |
| 0:23.6 | wasn't embedded JPEC that DA wasn't really all that sure about. Well, he now managed to sort of |
| 0:30.3 | finally analyze it. And turns out JPEG structures, they are quite complex. And the DAG goes into quite a bit of detail about how JPEC structures, they are quite complex, and DDA goes into quite a bit of detail about how JPEX are composed. |
| 0:43.6 | And of course, he has a Python tool for you to help you analyze JPEX. |
| 0:49.1 | In the end, the JPEC didn't look malicious, but of course one of the hardest things in Info Security is to prove |
| 0:57.0 | that something is not malicious or not compromised. So he still leaves the opening here that |
| 1:04.3 | maybe there's actually an exploit that's being triggered in some JPEG viewers, but nothing that he was able to detect. |
| 1:13.0 | Nevertheless, he managed to disassemble the entire JPEC structure |
| 1:18.3 | and really explain quite well how JPEX are composed and how to analyze them. |
| 1:25.8 | And Linux 414 was released, and with that there are some quite interesting security enhancements that were introduced. |
| 1:35.3 | First of all, the Linux kernel now does support the AMD version of secure memory encryption. Now, this is only supported on the latest AMD processors. |
| 1:49.0 | Intel took a little bit different approach with SGX, |
| 1:53.0 | which really more isolates different memory areas from each other, |
| 1:58.0 | so one process cannot necessarily read memory from another process |
| 2:03.2 | and he also has a second sort of version of their encryption which is secure |
| 2:09.3 | encrypted virtualization that part is not yet implemented and it would allow the |
| 2:15.6 | hypervisor like send for example to isolate memory from |
| 2:20.8 | different virtual machines better in addition Linux now also supports some of the |
| 2:27.1 | cold boot attack protections that have been implemented in reasoned biases the |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

