4.9 • 696 Ratings
🗓️ 30 March 2021
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, March 30th, 2021 edition of the Sansonet Storm Center's Stormcast. |
0:07.9 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:13.9 | If you're into Malver analysis, you'll enjoy Xavier's diary from today. |
0:20.6 | He's analyzing an RTF document. |
0:24.3 | Now, what was sort of special here is, first of all, it was actually a valid RTF document. |
0:30.8 | It did open a fake document if you open it in an RTF reader, but the shell code was just sort of appended to the end of |
0:40.9 | the file. Of course, Xavier didn't stop here. Xavier will walk you through the entire analysis |
0:47.8 | and show how he managed to actually decode this shell code and figure out what it did. |
0:57.0 | And probably the biggest news today was that over the weekend, it appears the |
1:03.6 | PHP Git repository was compromised and at least two malicious commits were pushed to the PHP source repository. |
1:15.6 | At this point, there's still a lot of questions about as to what actually happened. |
1:19.6 | The two commits are implementing a pretty obvious backdoor that would allow an attacker to execute arbitrary codes via a specifically |
1:31.0 | crafted HTTP user agent header. |
1:35.7 | Now in my opinion, looking at the commits, it looks like the attacker wanted these commits |
1:41.0 | to be found. |
1:42.0 | They were not very well hidden, but essentially demonstrate what |
1:46.3 | could have happened here if the PHP maintainers would not have been more careful reviewing |
1:53.5 | the code. If you're currently a PHP user, this is unlikely going to affect you because |
2:00.4 | these commits did not make it in any of the current |
2:04.2 | released versions of a PHP. So this will only affect you if you did download the actual current |
2:12.8 | Git version of a PHP. On the other hand, since we don't really know much as to what exactly happened, there is still |
2:21.3 | a question that this may sort of be a tip of the iceberg kind of situation where we have |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.