meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 31st 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 31 January 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Decompiling #py2exe; Leaked Calls; #FB introduces delegated recovery

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, January 31st, 2017 edition of the Sandton and Storm Center's

0:07.1

Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.4

Did he has been talking about a matter that's really just created by compiling Python code using

0:19.5

Pi 2 EXE.

0:21.6

Now a while ago he published a Yara rule for this and showed how to decompile

0:26.6

Python 2 using unpy2exe.

0:30.6

But so far there wasn't really a good tool for Python 3.

0:34.6

Well there is now a decompile Pi 2 EXE is the name of the tool.

0:40.0

It does deal with Python 3.

0:43.3

So if you're running into this, take a look at the DA's diary for the links.

0:49.9

And a Florida marketing firm VC marketing with somewhat spotted history did leak call recordings on the internet, and these recordings did include credit card numbers.

1:04.0

Now, besides of this happening to this particular company, it's actually somewhat a common problem that companies deal with how to remove credit card information from recorded calls.

1:15.7

Most customer support calls are recorded and of course customers often do give their credit card number over the phone,

1:24.0

not realizing that first of all, the credit card number is probably going to be entered

1:28.9

into an website by the customer support representative, and secondly, that this credit card number

1:37.3

may now end up on a call recording, which of course is also kept in digital form.

1:48.4

Now, there are a number of ways to avoid that where you, for example, give customer support representatives a button they can press whenever they would like to black out a part of

1:53.2

the recording, but then again there's no guarantee that they will press that button.

1:59.4

And of course for the customer it's a lot easier to provide that credit card number over the phone

2:04.6

while they're talking to customer support, then have it to go back to some kind of website

2:09.6

and enter the number there.

2:12.6

So if you do record calls from customer service, make sure that you take care of any personal

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.