ISC StormCast for Tuesday, March 17th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 March 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, March 17, 2020 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich. |
| 0:09.5 | And I'm recording from Jacksonville, Florida. |
| 0:13.7 | Jan today took a look at good old desktop.in.i. |
| 0:17.7 | These files in Windows are typically used to assign icons to different files in a directory. |
| 0:26.9 | But what Jan found out is that, well, they can actually be also used to rename files within |
| 0:33.9 | Windows Explorer. |
| 0:36.3 | So using a specifically crafted desktop. I and I, |
| 0:40.3 | and essentially just easy to rename files, |
| 0:44.3 | replace the file names that are being displayed in Windows Explorer, |
| 0:49.3 | and with that, of course, tricking users into clicking on the wrong file or executing malicious |
| 0:57.0 | code. |
| 0:58.0 | Now you may ask, why not just rename the file or the folder? |
| 1:01.0 | Well, the advantage of doing it via desktop.I&I is that whenever you rename folder, well, there's |
| 1:07.0 | an event tricker that could possibly be detected, but if you do it via changing or creating a desktop.I. file, |
| 1:16.2 | then you technically don't rename the directory or the file, |
| 1:20.6 | and such there is no event that is being created |
| 1:24.4 | that could be used to detect this activity. |
| 1:28.2 | And if you are relying on VMware, VMware Workstation, VMware Fusion to isolate |
| 1:34.9 | malicious code from your host, well, make sure you update. |
| 1:39.7 | VMware did patch use after free vulnerability in VMNet DHCP that could be used to execute |
| 1:49.3 | arbitrary code on the host. This vulnerability was assigned a CVSS version 3 score of 9.3. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

