meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 19th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 19 October 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Certificated Auth for C2; PowerShell Patches; JunOS Patches; TianFu Cup

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, October 19th, 2000, 21 edition of the Sands and its Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich, and I'm recording from Riyadh, Saudi Arabia.

0:14.2

Well, attackers have problems, too, and one of those problems is how do they prevent systems that are not infected by their malware, for example, researchers and such, from connecting to their command and control servers.

0:28.6

So essentially attackers would like to authenticate the software that is connecting back in order to receive new commands.

0:38.4

One strong way to do authentication, of course, is certificates.

0:42.7

And Xavier ran into some interesting malware written all in PowerShell that

0:49.2

implements Glineside certificate-based authentication.

0:54.0

While cryptographically, well, pretty strong,

0:56.8

the problem, of course, remains how do you protect the credentials?

1:00.7

In this case, the certificate and private key.

1:04.5

The malware that Xavier ran into does use a password,

1:07.7

but then again, the password has to be included in the malware as well.

1:13.1

It was, in this case, just password literally.

1:16.3

And given the challenges, of course, how to protect a password like this, it doesn't really

1:21.6

make a difference that the password was trivial.

1:26.7

At this point, given the novelty of the approach,

1:29.3

probably this really comes down more to security through obscurity,

1:34.2

because many analysts aren't ready yet to look for a certificate

1:38.0

that is being used to authenticate to a command and control channel.

1:42.3

Of course, as a side effect,

1:49.3

you also protect the channel itself from various machine in the middle attacks.

1:53.1

And sticking with PowerShell here for another story,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.