4.9 • 696 Ratings
🗓️ 27 April 2021
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, April 27th, 2021 edition of the Sandcent Storm Center's Stormcast. |
0:08.4 | My name is Johannes Ulrich. |
0:09.9 | And today I'm recording from Jacksonville, Florida, but actually sort of virtually today teaching in Baltimore, our intrusion detection in depth glass. |
0:21.9 | In diaries today, we got a diary by DDA. |
0:24.9 | DDA took a look at a microstation files. |
0:28.2 | Microstation is CAD software. |
0:30.7 | I actually wasn't familiar with it, but apparently just like AutoCat files that DDA has |
0:36.8 | looked at in the past, Microstation |
0:39.3 | CAD files may also include Visual Basic for application code. |
0:45.4 | So they're using the same OLE format that, of course, DDA's OLEA dump tool will gladly analyze, and DDA now extended the tool to work also with the |
0:59.4 | dot DGN and NVBA files that a micro-station uses. At this point no need to panic. |
1:08.5 | There is as far as the DDA is, no matter being distributed with these files, |
1:15.1 | but by getting his tool ready and showing how to use it with these files, |
1:20.5 | well, if you run into anything suspicious, please let DDIHA know. |
1:26.1 | And then probably the big event today was that Apple updated literally everything. |
1:31.3 | iOS, iPad OS, Mac OS, watchOS, as well as some standalone applications for Windows, Safari, and the like. |
1:42.3 | But among all the bugs patched is one particular dangerous vulnerability |
1:47.9 | that apparently is already being exploited in the wild. This vulnerability does bypass |
1:55.5 | protections that Apple has put in place in order to prevent users from launching untrusted or malicious code. |
2:06.1 | There are really two different technologies that are at play here. |
2:10.7 | First of all, file quarantine. |
2:13.3 | Whenever you download a file from a website, then try to execute it. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.