ISC StormCast for Wednesday, November 18th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 November 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, November 18th, 2020 edition of the Sansaernet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.6 | So if you installed macOS 11 bixer, you probably noticed that some network security software like Little Snitch, for example, |
| 0:23.5 | had to be updated. |
| 0:24.9 | This software is no longer able to use kernel modules in order to intercept network traffic. |
| 0:32.7 | Instead, Apple made available a special API, the network extension API, |
| 0:38.3 | that is supposed to be used to inspect network traffic, |
| 0:43.3 | and the latest version of Little Snitch, Little Snitch 5, |
| 0:47.3 | is taking advantage of this API. |
| 0:51.3 | So the switch to the API was mandated by Apple by removing the ability to load |
| 0:56.7 | kernel modules. And in the end, it looked all fine. We now have a nice API to inspect network |
| 1:04.6 | traffic. But the side effect of this is that Apple exempted some of its own software from inspection. |
| 1:14.6 | So all you have to do is you have to find an Apple application that is in this content filter exclusion list, as they call it, pick a back traffic on it, and you have a nice covert channel that bypasses any kind of |
| 1:31.4 | third-party filtering products. |
| 1:34.7 | Now, Patrick Wardle has been communicating with Apple about this problem. |
| 1:39.5 | He has filed a vulnerability report about this, but this hasn't been addressed in the final release |
| 1:46.2 | of macOS 11. So now he tweeted a couple of proof of concept exploits that show how he was able |
| 1:56.4 | to exfiltrate data, essentially set up a command control channel by piggybacking traffic |
| 2:02.5 | on software that is in Apple's content filter exclusion list. |
| 2:08.6 | Apple is kind of typical, has not released any comments about this. |
| 2:12.6 | Aside from a couple of tweets from Patrick Wardle, there are no additional details, so I don't think he has released any tools at this point. |
| 2:23.9 | And I'm using Little Snitcher as an example. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

