ISC StormCast for Wednesday, August 7th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 August 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, August 7th, 2019 edition of the Sansonet Stormsanders Stormcast. |
| 0:07.6 | My name is Johannes Ulrich. |
| 0:09.2 | And then I'm recording from Jacksonville, Florida. |
| 0:13.5 | Well, it's Blackhead and DefCon again, so lots of press releases from company trying to talk about what they sort of consider the latest attacks |
| 0:23.8 | and vulnerabilities. One release that sort of stuck out a little bit is one from Microsoft Security |
| 0:30.2 | Response Center. It's talking about how earlier this year a company was breached via internet of things devices. In this particular |
| 0:41.1 | attack, a voice over IP phone, an office printer and a video decoder were used in order to |
| 0:48.7 | maintain persistent access to the victim's network. Now not a ton of details here but they did release out of the little bash one-liner that |
| 1:01.2 | was used to actually establish the command control channel. |
| 1:05.9 | Pretty straightforward, pretty simple, really just of an SSL connection on port 443 and not HTP. |
| 1:13.6 | So it was not HPS, it was just sort of TCP over TLS. |
| 1:19.6 | Pretty simple, pretty straightforward and certainly effective. |
| 1:23.6 | There are a number of indicators of compromise that Microsoft made public like five IP addresses |
| 1:30.3 | of command and control servers related to this attack. |
| 1:35.3 | Similar attacks we have seen in the past, but nothing sort of quite as sophisticated and |
| 1:40.3 | deliberate. |
| 1:41.3 | I remember sort of one of the early video camera compromises that we have seen was used, |
| 1:48.8 | for example, to then reach out to internal disk storage devices. And then, of course, |
| 1:57.2 | there has to be another specter variant. |
| 2:00.8 | This time it was researchers at Bit Defender who uncovered this particular method to exploit |
| 2:08.4 | the specter flaw which of course deals with speculative execution and they doubted the |
| 2:15.3 | swap GS vulnerability based on the instruction swap gs that's being used here |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

