ISC StormCast for Tuesday, May 7th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, May 7, 2019 edition of the Sanctur Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:13.6 | The DA today wrote up a quick note regarding an issue that Xavier ran into when he looked at these malicious UDF files recently. |
| 0:23.9 | Part of these files were actually in UTF-16 encoding. |
| 0:28.6 | UTF-16 uses at least two bytes per character, and with that what you typically end up |
| 0:35.1 | with if it's ASCII text, one of the bytes is zero |
| 0:39.2 | followed by the ASCII code. |
| 0:41.8 | So not terribly difficult to decode this and make sense of it, but the DA is going over |
| 0:48.1 | some of the tools that you have available in order to actually decode and then read the data more easily. |
| 0:57.0 | One set of vulnerabilities that is really sort of taking off is HTTP services starting on the |
| 1:05.1 | loopback interface to interact with various software packages. |
| 1:10.4 | Latest example, VMware Fusion. |
| 1:12.9 | VMware Fusion is setting up this listener on Port 8,698, and by connecting to it, |
| 1:21.0 | you were able to actually execute arbitrary commands on the guest without authentication. Since these are WebSocket and Rest |
| 1:32.2 | APIs that are being exposed here, all you need is some JavaScript so an attacker could execute |
| 1:38.9 | arbitrary code if the victim is visiting a malicious website and loads the respective JavaScript. |
| 1:47.1 | The envir patched this issue late in March, so about a month ago, and the actual proof |
| 1:54.0 | of concert exploit was released. |
| 1:56.8 | Also late March, but really didn't run into this until now. |
| 2:00.7 | So I figured I'll still mention |
| 2:02.3 | because this is a real simple exploit. So make sure that you are patched if you're running |
| 2:08.8 | VMware Fusion. And then again, this kind of vulnerabilities, we just have seen it with |
| 2:15.0 | Dell last week and with everybody moving to these sort of HTTP |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

