ISC StormCast for Tuesday, October 10th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 October 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, October 10th, 2017 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and today I'm recording from Singapore. |
| 0:11.0 | Xavier today had some fun with a Word document that arrived as an XML file. |
| 0:17.0 | I believe ever since Word 2007, the default format was actually XML and it's the open |
| 0:25.8 | XML format that Word is using to save files as. |
| 0:30.2 | But in this particular case, while it does use open XML data, the actual data part is |
| 0:36.6 | base 64 encoded. |
| 0:39.0 | This leads to many anti-malware products not actually recognizing this file as a Word document, |
| 0:45.1 | so they're not looking for some of the standard tricks that the bad guys are playing |
| 0:51.0 | with Virt. |
| 0:52.0 | In this particular case, a malicious macro. |
| 0:55.0 | So after all, an old trick, base 64 encoding can still be used to fool various anti-malware products. |
| 1:03.0 | I don't really think there are a lot of business reasons to receive an XML document that's not recognized as a vert document which actually |
| 1:13.5 | may be one way to filter these particular files. Credit card skimmers that are built |
| 1:19.9 | into gas station gas pumps have become a real big problem in part because it's |
| 1:26.2 | relatively easy usually for an attacker to install |
| 1:29.4 | these skimmers without being noticed. |
| 1:32.3 | Now a new project developed an Android app skimmer scanner that will look for these skimmers |
| 1:39.7 | using Bluetooth. |
| 1:41.1 | The way this particular app works is that it does look for Bluetooth devices |
| 1:46.8 | with specific titles, HC05, which is very typical for these skimmers. And I will try to connect |
| 1:54.4 | to them with the default password, one, two, three, four, and send just a letter P to that |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

