meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 27th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 27 October 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Excel 4 Visibility; HP Revoked Cert; Link Preview Privacy

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, October 27, 2020 edition of the Sand Center Storm Center's

0:07.0

Stormcast.

0:08.0

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.0

The DE today is talking about a new trick that he found used in Excel 4 Macro, something that

0:20.0

the has been writing in the past about.

0:24.9

Now, XL4 of course, no longer an active version of Excel, but these Excel 4 macros

0:32.1

will still be parsed fine by current versions of Excel. And one property that's often used by Malware is the visibility field in Excel spreadsheets.

0:46.3

So each sheet has its own visibility, and this can be either visible, hidden, or very hidden, taking up two bits in a byte that's otherwise

0:57.0

not defined. So very hidden would mean that the bit value 2 is set, hidden bit value 1 and

1:06.3

visible while the value is 0. The other bits are ignored, and that's, of course, a great opportunity for Malware

1:15.5

writers to evade signatures.

1:17.9

If particular Anteimalver is just looking for these predefined visibility values, then

1:26.1

they may not identify a sheet as very hidden and the signature

1:31.4

may fail, while Excel, of course, will just ignore the other bits and open that macro

1:37.9

just fine.

1:40.5

And if you're using an HP printer and a Mac, you may have had some problems these last couple days with the HP printer applications refusing to launch.

1:55.3

Apparently the problem here was that one of the signing certificates being used by HP had been revoked.

2:02.6

And as a result, of course, the operating system did no longer allow that software to run.

2:10.6

Of course, the entire certificate revocation ecosystem is kind of messy.

2:15.6

Also the same for a Mac OS.

2:18.8

It didn't affect all versions of Mac OS.

2:21.8

Apparently older versions of Mac OS do no longer update the database of revoked certificates,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.