meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, March 31st 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 31 March 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Crashing Windows Explorer; Zoom Privacy; Zoom Bombing; Zoom Phishing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, March 31st, 2020 edition of the Sansonet Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:14.0

And today we got a diary from Jan with an unpatched denial of service vulnerability in Windows Explorer.

0:23.2

So not in an Explorer, but Windows Explorer that you use to look at local files.

0:29.1

The trick that he's using here are self-referential link files.

0:33.8

Link files usually point to a different files, but well, they can also point to themselves,

0:39.3

and apparently Windows Explorer has issues with those files.

0:45.2

Now, there are two different type of link files.

0:49.5

They're URL link files, little text files in INI format, and then there are shell links that are

0:56.3

using a binary format.

0:58.7

The difference in impact here is that in order to experience the denial of service condition

1:04.3

with a URL link file, you actually have to try to open the URL link file with the shell link file. The only thing you have to do is

1:12.7

open a directory within which you can find this malicious shell link file. And again,

1:20.5

Windows Explorer will crash. Jan did report this vulnerability to Microsoft. Microsoft decided not to fix it due to the limited impact.

1:30.5

Of course, this is really a little bit more of an annoyance in particular since an attacker

1:35.8

would already need the ability to place the file on your system.

1:41.5

And of course, over the last couple weeks, video conferencing has become a lot more popular,

1:49.0

and there are a number of different solutions that have seen a large increase in their user base.

1:56.0

One of the standouts kind of has been Zoom.

1:59.0

Zoom has sort of been in startup mode and yes has been somewhat

2:04.3

popular, but really its popularity sort of exploded these last couple weeks. And with that, of course,

2:11.4

also a lot more attention has been paid to Zoom's security and privacy posture. Now, I have a couple of stories here about

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.