meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, May 3rd, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 3 May 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VBA Project References; FRRouting Vuln; JWT ECDSA Algo Confusion

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, May 3, 2023 edition of the Sands and its Storms anders Stormcast.

0:08.4

My name is Johannes Ulrich and today I am recording from Jacksonville, Florida.

0:14.9

The day today wrote a diary about how to use his Olli dump tool to extract project references from Visual Basic for Application

0:25.3

Project files.

0:27.2

Everything you really need to sort of extract them is already in the tool.

0:31.5

You can identify the stream.

0:33.5

You can then decompress the stream.

0:36.4

And to make things easier, DDE even wrote a plugin that allows you to pretty much automate all of this.

0:44.7

Now, in addition to the project references that can be found in the DIR stream,

0:50.5

that's sort of what DDA shows you here how to extract.

0:56.3

There is also a compiled version of this in the performance cache. That's something that you sadly can't extract yet with DDA's tool.

1:04.7

That's just because, well, the format isn't documented and also this performance cache is somewhat optional. However,

1:13.4

DDA still shows you how to extract strings from the performance cache to see if you see anything

1:18.4

unexpected that you didn't see in the other project references. So certainly mandatory

1:25.0

reading if you are regularly analyzing VBA documents.

1:31.4

And Forkscout wrote a blog post about some newly discovered vulnerabilities in the Free Range

1:37.4

Routing Project. Free Range Routing Project is an open source implementation of routing

1:43.4

protocols, in particular

1:44.5

BGP.

1:45.5

If you're a bit more old-fashioned like myself, you may recognize the name Quagga and F-R routing

1:52.3

was forked from Quagga a few years ago.

1:56.2

Now like a lot of open source networking software, FR, finds itself in a number of commercial products as well.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.