ISC StormCast for Wednesday, February 6th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 February 2019
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, February 6, 2019 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.1 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:13.2 | If you have been in security for a while, you probably heard of Mimicats. |
| 0:17.3 | Mimicats is a great exploit tool that allows you to get passwords out of memory |
| 0:24.9 | and password hashes and the like that the operating system may use to authenticate. |
| 0:30.3 | Of course, once an attacker has this data, they can then use it in order to impersonate various |
| 0:36.6 | users. This technique is probably the favorite thing to impersonate various users. |
| 0:37.9 | This technique is probably the favorite thing to do for an attacker after the initial access |
| 0:43.1 | to a system on your network and defending against these Mimicats attacks should be a high |
| 0:50.6 | priority. |
| 0:52.2 | Rob's diary today goes over a number of different methods that you can use |
| 0:56.9 | in order to block this attack. Now, the problem here is a little bit the way Rob puts it's a |
| 1:03.4 | cat and mouse game between good guys, bad guys in that there are more than one way to actually get these credentials out of memory. |
| 1:13.1 | So you have to be really careful that you're up to date on your protections. |
| 1:17.5 | So take a look at Rob's right up and see if there's anything that you forgot in your environment. |
| 1:26.1 | In the open source office suite world, there are really two very similar products that you often see in Linux environments. |
| 1:35.3 | Open Office, which originally came out of Sun, but is currently being maintained by the Apache Foundation, and Libra Office, which sort of split |
| 1:46.8 | off open office during the time when it was owned by Oracle after Oracle acquired Sun. |
| 1:53.7 | But overall, Libra Office, open office tend to be somewhat similar even though they have diverged |
| 2:00.1 | a little bit over the last couple years. |
| 2:03.7 | Well, one important problem now why you may want to consider using Libra Office instead of |
| 2:11.4 | open office aside from politics like who exactly owns the code and what open source license is being applied |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

