ISC StormCast for Wednesday, May 24th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 24 May 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 24th, 2017 edition of the Sands and its Storm centers. |
| 0:06.7 | Stormcast, my name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:12.3 | Video players have often been a favorite attack vector for attackers because they're usually |
| 0:18.5 | numerous vulnerabilities that can be exploited and of course it's |
| 0:23.3 | difficult for the user to always be up to date on patches. The latest such exploit was just made |
| 0:31.7 | public by a checkpoint. It does affect a number of different video players. |
| 0:38.4 | What they found was that Popcorn, Cody, VLC, also known as VideoLand and Stremio are all |
| 0:45.7 | vulnerable to this particular exploit, which actually affects not so much the video files |
| 0:50.5 | themselves, but subtitles. |
| 0:53.6 | Now the problem here is that you could download these subtitle files in addition to a movie |
| 1:01.0 | that you already own. |
| 1:02.4 | So if this movie came without subtitles in a particular language that you're interested in, |
| 1:08.1 | then you can download these subtitle files later. And of course, |
| 1:11.7 | that's how you may pick up one of these corrupt malicious files. Now, Checkpoint did disclose |
| 1:18.9 | this vulnerability to the four named products and patches have been released, so better make sure |
| 1:26.1 | you are again up to date. |
| 1:28.3 | In particular, since these video players had issues with subtitle files before it probably |
| 1:35.3 | shouldn't take too long for an attacker to come up with an exploit. |
| 1:40.3 | And recent mobile phones have started adding iris scanners as part of their biometric authentication, |
| 1:48.2 | in addition to typically fingerprint sensors. |
| 1:51.5 | Now, one of the nice things of iris scanners, of course, is that you essentially can get logged into the phone just by looking at it. |
| 2:00.2 | Also, iris scanners, of course, work better if you |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

