meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 6th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 6 June 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Simple Archive Bruteforcer; Keepass Patch; Splunk Advisories; Chrome Extensions; Symantec Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, June 6, 2020,

0:04.1

edition of the Sansonet Stormsendors Stormcast.

0:08.4

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.8

Today we got a guest diary by Gephard.

0:16.3

The Gephard looked into how to quickly decrypt archives like zip files that may contain malicious

0:24.9

content.

0:25.9

Of course, this is something that's not new.

0:28.1

We have seen this a lot where email attachments arrive as an encrypted zip file.

0:33.6

The password is often in the email or maybe an image.

0:39.6

But sometimes it may also be something that a victim downloaded from a website and the password was displayed on that website, but

0:45.8

now you no longer have access to it. So it may be necessary to relatively quickly decrypt

0:53.4

this SIP file by just brute forcing it. There are dedicated tools

0:58.3

to this very quickly. The solution that Gephardt came up with distinguished itself by basically

1:04.9

being implemented in a simple bash script. Of course, the advantages you don't need to install or even purchase any specific software.

1:13.4

It's not the fastest way to brute force passwords.

1:17.0

But overall, if you consider a time it would take to acquire and configure and actually learn how to use a particular piece of software,

1:26.0

this may be the overall simpler and quicker way of doing it.

1:31.4

And we got an update for KeyPass. KeyPass, the password manager, I mentioned it a week or so ago,

1:38.4

had a vulnerability where the password, the master passphrase used to unlock a key pass, could be retrieved from memory.

1:48.0

This was in part due to the way how the passphrase dialogue was displayed.

1:54.1

So this was fixed now.

1:56.3

CVE 2023, 32784.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.