ISC StormCast for Tuesday, May 28th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, May 28, 2019 edition of the San San Antonio's StormCast. My name is Johannes Ulrich. |
| 0:09.4 | And today I'm recording from San Antonio, Texas. |
| 0:13.2 | To start out with today, we have a macOS vulnerability, and it was discovered by Philippo Kavallarney and does result in a bypass of |
| 0:23.9 | Gatekeeper. |
| 0:24.9 | Gatekeeper is a tool that was introduced by Apple in order to flag any downloads as suspicious |
| 0:33.9 | and the user typically has to acknowledge that the file was downloaded before it's being executed. |
| 0:41.7 | The trick that Philippo found could lead to an attacker sending a remote file to a victim |
| 0:48.2 | that will then execute the file without gatekeeper interfering. |
| 0:53.7 | It's actually pretty simple. The way it would start out |
| 0:57.1 | with is that the attacker would send a SIP file to the victim. The victim then opens the SIP file |
| 1:05.2 | and within the Sip file there is a symbolic link. Now this symbolic link does point to a special path within |
| 1:13.2 | macOS that points to a network share that the attacker is set up. Now this doesn't have to be |
| 1:19.8 | just SMB, could be NFS and the like, and gatekeeper does consider network shares as safe. So gatekeeper does not warn the user in this |
| 1:31.4 | case of downloaded files, but these network shares will be mounted automatically as soon as |
| 1:39.0 | the user clicks on the link that directs them to a path that does imply network drive. |
| 1:47.0 | So overall, a pretty neat trick, and I think the root problem here is that network shares are considered safe, |
| 1:56.0 | and that's not necessarily easy fixed because network shares of course happen they exist in companies |
| 2:04.3 | all over the place and if you would mark all files on network shares as unsafe that of course |
| 2:09.9 | would be quite disruptive to users in these scenarios maybe a compromise would be |
| 2:16.5 | the only mark new network shares as unsafe and |
| 2:21.3 | then ask the user whether or not they actually would like to connect to them instead of automatically |
| 2:27.8 | connecting to these network shares. Overall reminds me a little bit of some of the problems that we |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

