meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 3rd 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 3 January 2018

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Extracting URLs From PDFs; Local PE in macOS; 34C3 Videos; GPS Website Vulnerabilities

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 3rd, 2018 edition of the Sansonet Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:12.0

One rather common social engineering technique is the use of URLs inside PDF's documents.

0:20.0

Now, a lot of spam filters aren't able to really extract them and filter PDFs properly,

0:28.1

so DDA came up with Python script to do that for you.

0:34.1

Now originally Didier talked about this in a diary that he published on the 24th, but he got

0:41.8

quite a bit of feedback based on that blog post. So today he kind of updated that by adding a video

0:50.1

with a walkthrough to the tools that he's using in order to accomplish this.

0:55.8

And this weekend, a security researcher who goes by the pseudonym of Sigusa published

1:03.8

an exploit for a privilege escalation vulnerability in Mac OS.

1:10.3

According to him, the exploit works for any version

1:14.4

of OS10 or macOS back to 2002, possibly earlier ones. Guess he hasn't tested any earlier ones yet.

1:24.1

This exploit takes advantage of vulnerability in the I.O.H.D. family macOS

1:31.6

kernel driver. Now, to take advantage of this vulnerability, an attacker has to have already

1:38.0

local user access to the system in order to launch the exploit. These type of exploits are very common in pretty much

1:47.3

all operating systems. If you remember for Windows, for example, there's usually a whole

1:52.9

set of kernel driver vulnerabilities that can lead to escalation in every monthly update.

2:02.5

Sadly, Apple was not notified of this vulnerability prior to the release of the exploit.

2:10.2

Now, since this is only a local approach escalation vulnerability, I don't think Apple will make

2:15.8

this a huge priority and expect an update with any of the

2:21.6

next few regular updates, I would think, sort of over the course of this year. That's at least

2:27.4

my guess how Apple would address vulnerability like this. Now, over the last week, there was also

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.