ISC StormCast for Wednesday, June 7th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 June 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, June 7th, 2017 edition of the Sands and at Storm Center's |
| 0:06.3 | Stormcast. My name is Johannes Orich, and today I'm recording from Washington, D.C. |
| 0:12.7 | Yesterday, D.D.D.A. promised a second part to his Ex-Or diary. Now, today he delivered on this promise, |
| 0:20.3 | and he provided a Python script that will help you |
| 0:24.5 | extract the XR key used to encode binaries. Now this was written mostly with PE executables in mind, |
| 0:33.9 | but I believe the script can actually work for other binaries as well, since it sort |
| 0:40.0 | of tries to look for these repeating patterns that typically show up when you are using |
| 0:45.6 | an XR key to encode a file that contains several parts that are all null. |
| 0:52.6 | So give it a try and let the DA know how it works for you. It will |
| 0:57.0 | actually give you multiple possible keys if it can't really figure out one particular key |
| 1:02.8 | that definitely works. Now it was a few years ago that sightjacking was a big deal and became really sort of a very popular exploit with the |
| 1:14.6 | Firefox Fire Sheep extension, if anybody remembers. |
| 1:18.8 | Sidejacking refers to the idea where the login page itself is using HTTP, but later, |
| 1:26.6 | of course, a cookie is used to authenticate the user and |
| 1:29.6 | if this cookie is sent over HTTP, someone can easily intercept it and use it. |
| 1:36.8 | Fire Sheep was the Firefox extension that really made this tag mainstream and very |
| 1:43.3 | easy to perform. Well since then most sites like |
| 1:47.6 | Facebook for example which was a big target went to all HDPS where every single |
| 1:54.5 | request is supposed to use HTTP or so you thought well appears that |
| 1:59.9 | Facebook and Instagram aren't really all |
| 2:03.2 | HTTP. Turns out that Instagram stories, which have gotten popular recently, are transmitted |
| 2:11.6 | from mobile devices via HTTP, not HTTP. This is in particular interesting since Instagram stories were in part being introduced |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

