ISC StormCast for Wednesday, May 3rd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 May 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 3rd, 2017 edition of the Sansanet Storm Center's Stormcast. |
| 0:07.4 | My name is Johannes Ulrich, and the I'm recording from Jacksonville, Florida. |
| 0:12.0 | Just a quick update on the Intel chipset vulnerability that we talked about yesterday. |
| 0:17.7 | We do see some initial scanning for this vulnerability at this point the majority of |
| 0:25.3 | the scans come from shadow server shadow server is part of the good guys they do notify users |
| 0:32.6 | that are affected by this vulnerability if they find vulnerable, they work closely with ISPs on this. |
| 0:40.4 | They do not publish lists of vulnerable hosts like others may be doing in the future. |
| 0:48.4 | Overall, you should have these ports blocked, whether you are vulnerable or not having these ports open if you're not vulnerable |
| 0:57.7 | does expose you to the risk of someone essentially just password brute forcing and such |
| 1:03.4 | these IPMI interfaces and such that tend to listen on some of these ports. |
| 1:10.0 | At least at this point I'm not aware of an exploit that is at hacking |
| 1:13.7 | this particular vulnerability, but always possible there's something out there that I haven't |
| 1:19.8 | seen yet. If you see something, please let us know. And SensePost came up with an interesting |
| 1:25.7 | way how to get access to a system that does synchronize |
| 1:31.8 | its email with a compromised email account via Outlook. |
| 1:37.8 | Turns out Outlook has a nice feature called Forms. |
| 1:41.5 | Now, Forms cannot be sent to a user as an email. They're used to create emails |
| 1:48.0 | that you're sending out, and as part of these forms, you can also add scripts. These scripts are treated |
| 1:55.9 | differently from any scripts that you may receive in an email. Outlook actually is going to phase out |
| 2:02.8 | parsing scripts in emails altogether, and for the most part, it's best practice for a long time |
| 2:09.7 | to disable this. But these scripts in forms, because forms are usually created by the user, |
| 2:16.0 | stored with the exchange server. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

