4.9 • 696 Ratings
🗓️ 2 August 2017
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, August 2, 2017 edition of the Santernet Storm Center's Stormcast. |
0:07.8 | My name is Johannes Ulrich, and the I'm recording from Nashville, Tennessee. |
0:13.0 | Of course, SMB is still on everybody's mind with the recent denial of service attack, adding yet another current exploit to the tool chest |
0:24.5 | that an attacker may use against hosts running SMB. Now one thing that was mentioned often |
0:31.8 | when you talked about the Wanna Cry and such was disabling some of the old Smbb versions, in particular Smbb version 1. |
0:40.3 | This isn't too hard to do in a pure Windows network where you have active directory control |
0:45.7 | over all hosts, but in smaller networks without active directory and also when having other |
0:52.2 | systems like, for example, Samba servers on Linux systems, |
0:57.9 | this can be quite challenging. |
1:00.0 | So today we have a diary by Rob telling you how to use NMAP with some recently related |
1:07.5 | Nassel scripts in order to detect S&B versions in use on your network. Make sure you're |
1:14.0 | using the very latest and created version of NMAP, which is 7.6 and was released on Monday. |
1:23.2 | And I'm teaching here today at the Security Awareness Summit, and of course fishing is on everybody's mind here. |
1:30.0 | Now, fishing is often seen as an attack that affects more non-technical users, |
1:35.2 | but yes, more technical savvy users like developers are sometimes subject to fishing attacks and fall for it. |
1:45.3 | The latest example here are the authors of Copyfish. |
1:49.4 | Copyfish is a Google Chrome extension, also available for other browsers, |
1:54.4 | that allows you to extract text from images. |
1:57.4 | So essentially, it does OCR. |
2:00.7 | Now, the developers for this extension fell |
2:03.8 | for a phishing attack stealing their Google developer credentials and as a result |
2:09.1 | and their extension was taken over by an adware campaign so if you installed a |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.