meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 30th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 30 December 2020

⏱️ 4 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Simple AV Priv Escalation; Go Miner Malware; AutoHotKey Credential Stealer

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 30th, 2020 edition of the Sandstone Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.5

And today I'm recording from Jacksonville, Florida.

0:14.0

Well, this is the last podcast of the year and, well, no real big news today.

0:20.3

So I'll keep it short and let's get started

0:23.3

with what we have here at the Internet Storm Center Diary. Jan took another look at the ability

0:32.3

of users on a system to get directory listings of folders to which they don't have access to.

0:39.7

And well, the tool he turned to here are antivirus engines.

0:45.3

So Jan took a look at 25 different antivirus tools.

0:49.0

Now, eight of those tools did not allow a user to initiate a scan for a directory that the user didn't have

0:57.3

access to, but the others did allow access to those folders and then released file names.

1:04.5

Again, no content of the files, just the file names themselves, but it's actually a common problem. We have talked about this

1:13.1

here many times the past antivirus engines have to run with elevated privileges, so any

1:19.8

kind of vulnerability in an antivirus engine then quickly becomes a privilege escalation,

1:25.4

and this is probably the most minor one of the ones that could

1:30.2

potentially happen. Jan did notify anavirus vendors, and all but two actually considered

1:38.1

that intentional behavior, and the two remaining ones did actually fix this problem or scheduled a fix for a future update.

1:49.9

And one of the things that we have sort of seen often on this year is Malware written in Go.

1:55.9

Now, the Go language, of course, is sort of one of the up-and-coming languages that developers are using,

2:03.4

and yes, Malware writers are, of course, catching up with this trend.

2:09.3

Least example, a security company in Teaser, found some Malver that does install crypto coin miners.

2:18.3

And of course, with anti-malver engines being a little bit behind in the Golang trend,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.