ISC StormCast for Tuesday, August 13th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 August 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, August 13th, 2019 edition of the San Santernut Storm Center's Stormcast. |
| 0:08.5 | My name is Johannes Ulrich. |
| 0:10.0 | And today I'm recording from Jacksonville, Florida. |
| 0:14.9 | Attackers are working their way through possible file extensions in order to infect users. |
| 0:22.6 | The latest example is DAA files and one of our readers Jason did send us a file that he received. |
| 0:31.5 | Now DAA stands for Direct Access Archive and it's a type of ISO files as you may know them from CD |
| 0:40.5 | images now the trick here is that the A files are less common they're also not |
| 0:45.8 | automatically mounted in Windows like ISO files so a victim actually needs to |
| 0:52.3 | have additional software available in order to read these files |
| 0:57.4 | and be infected by it. |
| 1:00.6 | One such tool is power ISO, that's for pay application. |
| 1:06.0 | DDS suggests that this could be used in a more targeted attack where the attacker knows the victims are |
| 1:12.6 | familiar with these type of files or we had one comment being submitted to this story that |
| 1:20.6 | the power ISO tool in particular is often also used in pirated versions. |
| 1:28.3 | I doubt there are a lot of legitimate reasons to receive the A file as an email attachment, |
| 1:34.3 | so I would probably recommend you just strip them out at your mail gateway. |
| 1:40.3 | And a couple different news articles actually pointed to SQLite last week. |
| 1:47.0 | SQLite is one of the software components that has long been overlooked. |
| 1:52.0 | More recently, there have been a number of interesting vulnerabilities that were discovered |
| 1:58.0 | in this library. Now, SQLite really doesn't have much in common with traditional SQL other than a similar query language. |
| 2:07.6 | The data is stored in flat text files and from a security perspective it actually looks pretty benign initially |
| 2:15.6 | because there is no server listening and it's less exposed |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

