meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, July 27th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 27 July 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. macOS Security; Executable Registry Files; Facebook Business Phishing; Proxy Headers; @xme @x86matthew @Synacktiv

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, July 27, 2022 edition of the Sands and at Storms,

0:07.8

and its Stormcast, my name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.8

Today's diary is just a quick reminder by Xavier that even Mac users should be aware of security Apple published and updated

0:23.0

security guide back in May. Xavier collected a number of different links with various

0:29.1

security hardening guidance and such from different organization specifically for Mac OS.

0:35.8

So if you're using Mac, take a look and make sure that you are following some of these

0:41.7

hardening steps.

0:43.8

And yesterday I mentioned how attackers are hiding part of their malicious code in

0:48.9

registry entries on Windows to evade some of the Antimelver scanning engines.

0:56.3

But there's another registry-related trick that attackers are able to play.

1:02.6

X-86 Matthew published a blog post showing how executables may be delivered in registry files.

1:11.2

So these dot rec files, that's the extension they are used to using,

1:15.9

they are used for registry data.

1:18.3

But in this case, the file contains an entry to add a Windows executable to Run One key.

1:26.7

Run One's key, this is software that's being executed on boot.

1:31.9

Now, the simple exploit just includes a path to the executable, but that of course would

1:36.9

require the attacker to then also deliver the executable into a predictable path on the victim's

1:43.7

system.

1:44.6

So Matthew goes actually a little bit further here and embeds the executable in the same.

1:52.1

Dot rec file.

1:53.3

Now it's only one file that needs to be delivered and one file the user needs to click on

1:59.3

in order to trigger execution.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.