meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 18th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 February 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Curl on Win; WHO Phishing; Malicious Chrome Extensions @bumblebreaches @crxpert

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, February 18th, 2020 edition of the Sandson and Storms,

0:06.2

on us Stormcast. My name is Johannes Ulrich. And the day I'm recording from Jacksonville, Florida.

0:13.4

All this weekend's diaries about W. Get and Curl on Windows caused quite a few comments and really some good ones.

0:22.7

For example, one thing I forgot to mention yesterday is that as of Windows 10,

0:29.5

curl can actually be found as a standard component within Windows.

0:34.9

Another question that came up is how to deal with W get and curl with

0:41.3

proxies that actually require authentication. And turns out, well, a curl in particular

0:47.3

a curl that comes with Windows 10 can deal with that quite nicely. It does support SSPI, the security support provider interface.

0:58.1

That's a Windows API that allows you to tie into the Windows authentication system. So even

1:05.7

in TLM authentication and such, no problem for the version of Curl that comes with Windows 10.

1:13.8

Now, not all versions of W-Get and Curl support this, so if you download it from a third party,

1:19.9

you may have to double check to see if it's available.

1:23.5

Also, an interesting kind of comment here I thought to the initial blog post about, well, in the one Malera sample that was discussed there,

1:36.2

curl was actually first downloaded via HTTP using one of the standard APIs for HTTP requests.

1:42.5

So it's a little bit of catch-22 here.

1:44.6

How do you get curl if you don't really have a HTTP request tool that you like?

1:51.1

But like I mentioned yesterday, there are a number of these tools already on Windows.

1:57.2

And sometimes people just prefer the user interface, the options they have available with

2:03.6

the specific Unix tools.

2:06.6

Now of course we remain interested in various scams around the coronavirus outbreak.

2:14.6

Now at this point I just see an awful lot of spam, but today the World Health

2:21.9

Organization, WHO, did notice that they're seeing a lot of fishing attempts trying to impersonate

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.