meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 30th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 June 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Sysmon and ADS; PAN-OS SAML Issues; Old Telnet Issue in Cisco IOS XE

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 30th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:07.2

My name is Johannes Ulrich.

0:08.8

And today I'm recording from Jacksonville, Florida.

0:13.2

The DA today is going over a brief a little bit.

0:16.8

A really neat feature that was added in Sysmon version 11.10, which was just released a few days ago, that allows you to log alternate data streams.

0:29.3

Now alternate data streams, yes, they have been used in the past by attackers to hide data, but they often also contain quite useful data. And the alternate

0:41.3

data stream that D.D.E. was looking at here is Sone Identifier. If Microsoft Edge is downloading

0:49.8

a file from a website, it will add this alternate data stream with additional information

0:55.6

where the file came from. So if you find a suspicious file on a system of course, that's

1:02.1

always interesting or also to log where your users are downloading files from in order

1:09.6

to, for example, look for suspicious downloads.

1:14.5

And if you are a Palo Alto Networks customer, you probably already got a call from your sales

1:21.2

rep last week about this new vulnerability that was announced by Palo Alto today. A patch was made available

1:31.9

late last week, and this is one of those things you really, really need to patch quickly.

1:38.4

It does affect you if you're using SAML for authentication with your Apollo Alto devices, including,

1:47.1

for example, for your global protect VPNs.

1:51.4

The problem here is really more configuration issue and well how PanOS dealt with that.

1:57.6

If you enabled SAML authentication and you disabled the validate identity provider

2:04.7

certificate check, then you are vulnerable to anybody essentially logging in to your system.

2:13.9

This is really sort of a very fundamental SAML problem.

2:20.6

With SAML, of course, you're relying on an identity provider to make sure a user is authenticated to, for example, connect to a VPN in

2:28.3

this case. Now, for your VPN concentrator here, your Global Protect Gateway, it needs to verify that this signature

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.