meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, May 31st, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 31 May 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. ModiLoader Sample; MacOS SIP Bypass; OpenSSL Update; Barracuda Vuln Details; Nextcloud, Zyxel Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, May 31st, 2020,

0:04.4

edition of the Sansonet Stormstar's Stormcast.

0:08.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.7

Well, it's just a couple days after the last one.

0:16.7

We got another diary from Brad.

0:19.3

This time, it's about Modi Loader, also known as DeBad Loder.

0:25.3

A sample that Pratt found just on Monday, it uses the ISO file trick.

0:32.5

Remember, since Microsoft made it more difficult to execute code from files downloaded directly from the internet,

0:41.2

hiding them inside ISOs was one trick to avoid some of these restrictions.

0:47.1

We have a simple executable that then also uses OneDrive to communicate,

0:53.0

a cloud service that of course is less likely going to raise suspicion, in particular in Microsoft Network.

1:01.9

In the end, the victim ends up with Remco's RAD, the well-known remote admin tool, of course, the malicious type of remote admin that you're

1:13.3

going to invite in your network. More details, packet captures, samples, and everything

1:20.4

you need to follow Brad along as he analyzes the file can be found in links in the diary.

1:28.3

In Microsoft published a blog post with details regarding a vulnerability that Apple recently patched CVE 2020-232369.

1:41.3

This vulnerability allows bypassing SIPD system integrity protection.

1:47.8

SIP is important because it does prevent at hackers from altering system binaries, and the

1:55.1

only way to officially bypass SIP is to disable it if you're booting the system into maintenance mode,

2:03.3

which of course not only requires physical access, but also requires access to an administrator password.

2:09.7

But what Microsoft found is that the migration assistant, or at least the component started by it,

2:16.1

which is used when you're migrating your system to another system,

2:19.6

also has the ability to bypass SIP, and it can actually spawn, Bash, and Pearl, which are interpreters,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.