ISC StormCast for Tuesday, October 8th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 October 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, October 8, 2019 edition of the Sansonet Stormsendors Stormcast. My name is Johannes Ulrich, |
| 0:09.7 | and I'm recording from Chicago, Illinois. First, we have an observation by a reader of the Register, |
| 0:19.0 | who apparently was running two VPNs at the same time. |
| 0:24.1 | First of all, they were running the iOS Warp application that Cloudflare came up with |
| 0:29.8 | in order to use its 1-1-1-1-DNS over-HdPS service. |
| 0:37.3 | Now, secondly, he was also using NordVPN as an IPSEC VPN provider using |
| 0:45.8 | Ike. The problem here, at least my opinion, is that Cloudflare implemented their solution |
| 0:52.7 | as a VPN. Now he disabled the actual warp application, |
| 0:57.5 | but left that VPN established. Now, when he then also enabled the NordVPN, VPN, well, |
| 1:06.7 | in essence, nothing was encrypted at all. |
| 1:11.2 | Now, a register is putting it somewhat here on NordVPN to actually come out with a patch |
| 1:15.7 | for it. |
| 1:16.7 | Possible that this is a solution, but in the end, you always have to be careful if you're |
| 1:22.1 | running two VPN solutions at the same time because you can end up with some odd routing situations |
| 1:30.3 | where like in this case your traffic is not actually going to get encrypted. |
| 1:36.3 | And Singapore security researcher by the handle of vacant found interesting vulnerability in WhatsApp that Facebook patched last week. |
| 1:48.6 | This vulnerability can be triggered with a simple gif image that has been manipulated to trigger |
| 1:55.7 | a double free vulnerability. Awakened has published a pretty detailed blog with sample code and proof of concept, |
| 2:04.5 | walking you through the exploitation year, given that we hear so much about these double-free |
| 2:10.7 | vulnerabilities. Well, it's certainly a good idea to take a look at this blog post to better |
| 2:17.3 | understand what these vulnerabilities are and how they are exploited. |
| 2:22.4 | Probably the most straightforward way to exploit this vulnerability is for an attacker to send an image that has been crafted to exploit this vulnerability to the victim. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

