ISC StormCast for Tuesday, December 12th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 December 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, December 12, 2017 edition of the Sancton Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Washington, D.C. |
| 0:11.6 | This weekend, Brad came across some malware that tricks the user into installing a crypto coin miner on systems. |
| 0:20.5 | This is actually not really using an exploit. It just a rinked. into installing a crypto coin miner on systems. |
| 0:23.8 | This is actually not really using an exploit. |
| 0:31.3 | It just arrives claiming to be a viewer for pornographic images and then tricks the user into installing the software. |
| 0:34.4 | I've mentioned a few times already that as the value of these crypto coins goes up, |
| 0:39.8 | this really becomes the new way how the bad guys are monetizing their skills. We see less things |
| 0:48.2 | like crypto ransomware, even though they're still out there or things like installing just |
| 0:53.9 | bots on systems. |
| 0:55.8 | These crypto coin miners are really a much more efficient waste right now, |
| 1:01.0 | how bad guys can make money using your resources. |
| 1:05.2 | And if you're a user of Microsoft's ERP software, also known as Microsoft Dynamics, then you probably heard that |
| 1:14.1 | this software is now also available in a software as a service offering, where essentially |
| 1:20.5 | Microsoft does deploy this software in Azure for you, and you get control over the software |
| 1:27.4 | remotely. |
| 1:28.3 | Now in order to accomplish this, Microsoft actually sets up three different tiers for their customers, |
| 1:35.3 | one for development, one for integration, and finally one for the life production service. |
| 1:42.3 | For the development site, the customer actually has full RDP access to the virtual machine. |
| 1:51.3 | One developer, Matthias Glicka, actually took this RDP service to look a little bit around |
| 1:58.2 | the machine, and what he realized was that all of these |
| 2:02.8 | development or sandbox machines regardless of the customer are sharing the same wildcard certificate |
| 2:10.8 | this is asterix dot sandbox dot operations dot dynamics dot com so what this means is via RDP access. It was pretty trivial to extract the secret |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

