meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, September 3rd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 3 September 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Evil Windows Python; iOS 13.7; Cisco Jabber Patch; MoFi Vulnerabilities

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, September 3, 2020 edition of the Sandstone at Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.0

In diaries today, we got one by Xavier looking at a malicious Python script, and the main reason that Xavier sort of picked this particular

0:23.7

Python script is to show how you can sometimes eyeball essentially a Python script and figure

0:29.1

out that it's probably malicious. In this particular case, I guess just by looking at it,

0:35.0

it's heavily obfuscated. But then once you de-offuscated,

0:39.8

there are a number of specific Windows API calls that you wouldn't find in a normal little Python script.

0:48.8

Like, for example, virtual alloc, alok, which will allocate memory, which is typically something that you don't really

0:57.0

need in Python other than to, like in this case, inject shell code into this memory.

1:05.0

In this particular case, the shell code just tried to connect to a particular IP address to then receive additional commands.

1:16.4

And QNAP today released an update for many of its storage devices. QNAP has been a huge target

1:25.6

like many of these network attached storage devices.

1:29.3

So certainly something that you should keep up to date.

1:33.3

Noteworthy here are updates to pro FTP demons.

1:37.3

So if you have FTP enabled on the device, definitely update some of these vulnerabilities, go back to 2017,

1:47.8

and then there are also a number of newer vulnerabilities that are being addressed with this

1:53.5

update. While you are working on the device and applying the update, I highly recommend that you disable whatever service,

2:04.4

whatever application you don't need on these devices. They typically come with a bunch of

2:11.3

different web applications enabled, things like photo station, for example, to share photos and the like.

2:18.6

Many of them you may not need, so please disable them to reduce your attack surface somewhat.

2:25.7

And yes, if at all possible, please do not expose these devices directly to the internet.

2:34.4

And Apple yesterday released an update to iOS, iOS 13.7.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.