meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 29th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 May 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Ultrasound Mobile Location Tracking; NSIS and Malware; Z-Wave Attacks; Electron Issues

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 29th, 2018 edition of the Sandtonet Storm Center's Stormcast.

0:07.6

My name is Johannes Ulrich.

0:09.4

And today I'm recording from Jacksonville, Florida.

0:12.9

Our handlers have been quite busy over the long weekend, so we have a number of diaries to talk about.

0:20.4

First of all, Kevin talked about the use of

0:23.8

ultrasound in order to either locate mobile devices. So that's, for example, used by stores

0:31.1

in order to detect customers and the like. And secondly, also to use it for chat applications or data exfiltration.

0:40.8

So there's a number of links here for various applications that either tell you how to, for example,

0:45.9

jam these locator applications or how to use it, for example, in a simple instant messenger application.

0:55.0

And DDA took a look at some malware that took advantage of the nullsoft scriptable install

1:00.5

system or NSIS.

1:03.4

Now this particular system isn't just used for malware actually a lot of normal software

1:10.1

uses as well and it simplifies the creation

1:13.9

of installers.

1:15.2

Now one interesting observation here from DDA is these NSIS installers, they come with

1:21.8

install script and turns out an old version of 7-zip is able to actually tell you what's in that install

1:29.7

script.

1:30.7

It essentially decompiles it.

1:32.9

Only caveat here, you have to download this old version which has its own problems,

1:38.3

speak vulnerabilities.

1:40.3

And Xavier took a look at how some word macros make it past some common antivirus systems.

1:48.1

Now, this of course has always been happening where you open a word document that supposedly

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.