meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, March 28th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 March 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Apple Updates Everything (Again); IIS6/Win2013 WebDav Exploit; Symantec SSL Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, March 28th, 2017 edition of the Sandtonet Storm Center's Stormcast.

0:07.5

My name is Johannes Ulrich, and the time recording from Jacksonville, Florida.

0:12.2

Well, Apple updated everything. Again, everything in this case also included the Apple Iverg office applications.

0:21.6

Haven't really seen any specific patches being released for Iverg in the past from Apple.

0:28.6

In this case it fixes a problem with the document password encryption.

0:34.6

Up to now it used RC4 which of course is not the greatest encryption

0:40.3

algorithm to put it lightly. They now changed that to ES 128. For Safari, Apple fixed

0:48.8

38 different vulnerabilities didn't see anything really special or out of the ordinary here. Of course,

0:55.0

there are several code execution vulnerabilities in here. That's one reason why you definitely

1:00.1

do want to patch this. Now, there are a number of other typical web browser vulnerabilities

1:06.5

that are being addressed, like same origin validations, there are some cross-site scripting issues

1:12.3

in WebKit that are being patched, and then of course some denial of service conditions.

1:20.7

Mac OS Sierra and OS 10L Capitan also received updates.

1:26.2

Now, there are a couple of ones that sort of stick out.

1:28.5

First of all, updates to open source software that Apple is using, for example, Libre

1:34.3

Essel, the Azale library that Apple is using for Apache received an update,

1:40.1

PHP received an update.

1:42.0

An interesting update for Thunderbolt.

1:44.1

I thought something like this was already fixed in the last update.

1:48.0

Essentially, as the system boots the file vault password may leak via Thunderbolt.

1:55.0

This is an issue where Thunderbolt really physically has access to the system's bus. Now there are some software protections

2:03.2

that are put in place to prevent someone from just blocking in a device into Thunderbolt

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.