meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 31st 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 January 2018

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DCShadow Attack; Cisco WebVPN Vulnerability Update; Bypassing DDE Protection via OneNote

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 31st, 2018 edition of the Sansonet Storm Center's

0:07.3

Stormcast. My name is Johannes Ulrich, and then I'm recording from Miami, Florida.

0:13.3

D.C. Shadow is a new attack released last week by Benjamin Delpy and Vincent Latu at Microsoft's Blue Hat, Illinois conference.

0:24.0

You may have heard about them from their popular work on mimicats.

0:29.9

The DC part of the name DC Shadow is short for domain controller,

0:35.6

and the attack really takes advantage of the replication feature built into

0:40.6

Windows domain controllers. To better understand how DC Shadow works and how it ties in with

0:47.2

mimicats, let's talk a little bit about how mimicads can be used to interact with domain controllers. If an attacker can run

0:57.0

mimic hats on a domain controller, of course, then the attacker has access to the hashes

1:03.6

within the domain controller and can issue what's often referred to as a golden ticket, which

1:09.2

gives access to features the domain controller offers.

1:13.6

This already provides an attacker with a far-reaching set of rights to access and modify

1:20.0

all thecation data. What's really more the problem here is how noisy all of this is. Later,

1:26.8

the DC sync attack was added to Later, the DC Sync attack was added to Mimicats.

1:31.0

DC Sync again uses replication now due to replication or by taking advantage of replication,

1:38.4

an attacker is able to read information from a domain controller across the network.

1:45.0

So this gives the attacker a little more persistent access to the domain controller

1:50.0

and requires less work to be done on the actual domain controller.

1:56.0

In order to run DC Syn, the attacker, however, does need to have credentials that do have permission

2:03.7

to request replication. Now, typically administrators and members of the domain controller

2:10.0

group have that kind of access. Replication can be detected using an IDS, of course.

2:17.2

The new DC shadow attack really takes us a step further.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.