ISC StormCast for Wednesday, November 1st 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 31 October 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, November 1st, 2017 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. And today I'm recording from Stockholm, Germany. |
| 0:12.8 | Xavier today took a look at a malicious PowerShell script and some of the features implemented in it. |
| 0:21.6 | For example, this particular PowerShell script had two different ways, how it sort of avoided |
| 0:28.1 | sandboxes. |
| 0:29.9 | First it queried the bias to check if it's running in a virtual machine. |
| 0:34.8 | If strings like VMware or Senver returned, then it knew it would run in a virtual machine. If strings like VMware or Senware returned, then it knew it would run in |
| 0:40.0 | a virtual machine. It also avoided sandboxes by looking at the uptime of the machine. |
| 0:47.5 | Sandboxes typically are rebooted quite often, so if the uptime was too short, then it assumed it was running in a sandbox. |
| 0:56.0 | It also includes functions to create screenshots, and it is able to steal saved password lists from a number of different browsers. |
| 1:08.0 | So this is pretty capable now. These particular script snippets are |
| 1:13.9 | necessarily new. Some of them for example come from PowerShell Empire |
| 1:19.1 | framework that does implement a lot of features like this in PowerShell. And yet |
| 1:25.8 | again Apple updated yesterday. |
| 1:28.1 | Everything. |
| 1:28.9 | We got updates for ICloud, for Windows, for iTunes for Windows, for Safari, TVOS, |
| 1:36.1 | MacOS, iOS, and of course, watchOS. |
| 1:41.1 | Now, probably the most well-known vulnerabilities that's being patched here across all platforms is |
| 1:47.0 | the famous crack Wi-Fi or WPA-2 key reuse vulnerability. It was partly addressed in |
| 1:56.1 | prior updates, I believe, but this fixed it again and hopefully right now one of the new |
| 2:04.0 | features that was enabled in macOS hysera was the new Apple file system |
| 2:10.8 | there are two vulnerabilities that being addressed in APFS one could leak |
| 2:16.2 | encrypted disk data via the Thunderbolt port. That has also been |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

