4.9 • 696 Ratings
🗓️ 18 September 2018
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, September 18th, 2018 edition of the Sansonet Storm Center's |
0:06.4 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:13.6 | One sadly still a common exploit scenario are documents with links to SMB shares. |
0:27.5 | The goal here isn't often to actually get the user to download and launch the file, |
0:32.1 | but instead to transmit credentials to the SMB server. |
0:40.0 | So to help you identify office documents that take advantage of this problem, Rob is going over some tricks how to identify these links in office documents without having to fully reverse |
0:46.5 | these documents and figure out what else is happening with them. |
0:52.6 | And then somewhat pre-announced we got from Apple a new version of iOS, TVOS, and |
0:58.8 | watchOS. |
1:00.0 | Now, as usual, I'm not too concerned about all the fancy new feature in these operating |
1:05.1 | systems, but instead about the security content. |
1:08.8 | And there are a couple of interesting things that are being fixed |
1:12.1 | here. First of all, the Safari URL spoofing vulnerability that already has been made public |
1:19.5 | after Microsoft patched it in Edge. Well, that's now patched in iOS. And since we didn't yet get the new version of macOS today, Apple also released a new |
1:32.3 | version of Safari for all current versions of OS10 and MacOS. |
1:38.0 | This version of Safari again also patches this URL spoofing vulnerability. |
1:43.7 | Another known safari issue being addressed is a problem |
1:46.7 | with autofill. Now, auto fill is meant to only auto fill data on particular sites, but due to this |
1:52.9 | vulnerability, it was possible for an attacker to trick Safari into autofilling data into a malicious |
1:58.8 | site. Another sort of interesting issue that's being addressed is that RC4 was removed as an encryption algorithm. |
2:06.6 | So in summary, there are some critical security issues that you probably do want to address, |
2:12.6 | and that's one reason to apply this update. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.