4.9 • 696 Ratings
🗓️ 3 October 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, October 3, 2020, |
0:04.5 | edition of the Sansonet Storm Center's Stormcast. |
0:08.4 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:14.5 | Good reminder from DDA today that encrypted zip files do not encrypt the metadata that comes with the SIP file. |
0:24.6 | This includes the file name itself, but also the CRC 32 checksum. |
0:31.4 | Now these checksums, they're not cryptographic hashes, so sure, there are plenty of collisions, |
0:36.3 | or it would be easy to create a collision, |
0:39.4 | but still it can help someone narrow down what file is likely included in the encrypted SIP |
0:46.8 | file. A reader also points out that, well, it's even better because you also have the original |
0:52.2 | length of the file as part of the metadata available, |
0:56.3 | so that can then further be used to narrow down a particular file that may be included. |
1:03.2 | Probably the simplest way to avoid this issue is that you just sip the file twice. |
1:08.9 | That way the second time you sip the file the metadata will just |
1:12.8 | be the overall metadata for the first encrypted zip file and not the content of the first |
1:20.6 | encrypted zip file well and then I have an update to an update yesterday I talked about |
1:26.8 | XM soon going to release an updated version of its mail server |
1:31.1 | to fix the War on abilities being made public by the Saturday initiative. |
1:37.1 | Out of the six War on abilities, we have three fixed now, and the new version released today |
1:43.1 | was 4.96.1, and there's also an upcoming |
1:47.9 | version 4.97 that will fix these issues. The issues being fixed here are the more |
1:55.5 | important one, including the auth out-of-bounds right vulnerability, which had a CVSS score of 9.8. |
2:03.0 | The remaining vulnerabilities, there are some workarounds that you can apply, and the XM advisory. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.