meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 5th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 5 June 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Authenticode Challenges; Miconfigured G-Suite Lists; PQCrypto VPN #quantumcomputing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 5th, 2018 edition of the Santernet Storm Center's Stormcast.

0:06.9

My name is Johannes Ulrich and the air I'm recording from Augusta, Georgia.

0:12.0

Rob today took a closer look at Authenticode Microsoft's longstanding standard to sign executable code.

0:20.1

In particular, Rob looked at how feasible it is to restrict

0:24.7

execution to signed code only. Rob put together some neat scripts to enumerate all executables,

0:33.2

summarizing the certificates used, and also the certificate authorities used to sign these certificates. to look at unsigned code of course as well to figure out if any unsigned

0:43.3

binaries are important in the daily use of Windows and products like Office.

0:49.9

One interesting find the copy of a Windows 10 Rob investigated, actually included one legitimate

0:56.7

binary that was verified using a test certificate authority.

1:02.9

But he also found a number of unsigned files.

1:06.4

For example, part of the Hyper V system appears to be unsigned, which is in particular troubling,

1:13.1

given the importance this HyperV subsystem has in some of the newer security restrictions on Windows.

1:20.6

Given the fact that numerous Microsoft Office files as well as Windows operating system components are not signed.

1:28.3

It turns out to be a little bit more difficult and expected to restrict Windows 10 to execute signed code only.

1:37.3

Take a look at his post.

1:39.3

If you are interested in this technique and his scripts or if you have any experiences to share, one reader

1:46.6

pointed out that just in time compiled.net applications are also a challenge when it comes

1:53.7

to executing signed code only.

1:57.2

And a cyber risk company, Kena security, reminds all organizations using Google's G Suite to review their Google groups.

2:05.8

Apparently, administrators do not quite understand the privacy settings for the corporate version of Google Groups.

2:14.3

As Kena discovered, groups are supposed to be for internal use only, are often configured

2:21.4

to be visible to anybody from the internet. Part of the misunderstanding may be how these groups

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.