ISC StormCast for Tuesday, January 10th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 January 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, January 10th, 2017 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:08.5 | And I'm recording from Jacksonville, Florida. Over the last few years, web browsers implemented a new JavaScript |
| 0:16.1 | API for WebSockets. Now, WebSockets allow bidirectional communication with web servers, and the |
| 0:23.6 | secured impact of WebSockets isn't always well understood. One of the better ways to learn about |
| 0:29.9 | new features like this and to explore different vulnerabilities and attacks is typically just, |
| 0:35.0 | well, to experiment, to have some real-world code that you can play with. |
| 0:38.9 | And for Web Sockets, we now have Damn Vulnerable Web Sockets. |
| 0:43.4 | That's a little PHP web applications that demonstrates various vulnerabilities in web sockets. |
| 0:51.7 | It's a little bit similar to the damn vulnerable web application that of course |
| 0:57.0 | does implement more of the traditional vulnerabilities. To run it, you need Apache, PHP, MySQL. So |
| 1:04.8 | nothing really all that fancy in PHP itself, of course. You also need support to connect to MySQL via the MySQL I library, which, as far as I may wear, |
| 1:15.9 | all major Linux distributions installed sort of by default or in Windows, probably something |
| 1:20.2 | like XAMP or so will allow you to install all of this very easily. |
| 1:25.1 | So if you are a developer or a pen tester, take a look at the Git Repar |
| 1:29.8 | Story and the link you'll find in the show notes. One of the big news stories last year was |
| 1:36.3 | a vulnerability in defibrillators and pacemakers made by St. Jude Medical. Now the vulnerability |
| 1:43.6 | allowed an attacker to remotely manipulate |
| 1:47.0 | these devices and seriously affect the health or even kill a patient that had one of these devices |
| 1:55.0 | implanted. Today, Sanjude released a patch for these devices. It should be rolled out automatically. Now, one reason |
| 2:02.7 | this particular vulnerability made so many headlines was also that the company that released |
| 2:09.2 | details about the vulnerability got together with an investment company that took a short |
| 2:14.6 | position in Sanjude Medical in order to financially gain from this |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

