ISC StormCast for Wednesday, October 18th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 October 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 18th, 2017 edition of the Sansonet Storms and a Stormcast. My name's |
| 0:08.4 | Johannes Ulrich and I'm recording from Singapore. Yesterday, of course, was all about the new WPA-2 crack attack, |
| 0:17.8 | but looking at some of these more sophisticated and technically complex attacks, |
| 0:23.6 | it's easy to forget that most people probably still get infected using fairly simple techniques. |
| 0:32.6 | And Pratt is writing about how the DDE, the dynamic data exchange technique, is being used in |
| 0:41.9 | recent mal-spam in order to infect users. I've talked about DDE before. It's nothing new at |
| 0:50.6 | all and actually kind of odd that people fall for it at all because they do have to |
| 0:57.0 | click through multiple warnings in order to execute the malicious code. Now Brad did include a number |
| 1:04.3 | of screenshots from these warning dialogues. The only thing I can think of is that some of them |
| 1:10.6 | are a little bit |
| 1:11.4 | cryptic and that may be why users click okay and execute the malicious code if you were |
| 1:20.2 | hit by this latest way if you may have seen the docu sign themed emails that were |
| 1:27.1 | used and if a user clicked and executed the malicious |
| 1:31.3 | code they're likely infected now with banking malware well it's just a quick update on the |
| 1:38.0 | WPA to crack attack well vendors have been pushing out updates for it and Microsoft and Apple already had updates included in their most recent operating system updates. |
| 1:54.0 | So for those systems, you should be fine if you're up to date. |
| 1:58.0 | Cisco, Obiquity and a lot of other vendors have also published |
| 2:02.8 | patches. So like I said yesterday, make sure that you check for your access points, for your |
| 2:09.2 | clients, that you're updating them. Probably this weekend is a great day to do that for your |
| 2:15.7 | home devices. And RSA keys created by chips made by Infineon apparently are not as secure as originally believed. |
| 2:27.3 | Infinion's chips are often used in smart cards, they're also used in some TPM modules and UBiki used them in some of their products. |
| 2:38.5 | The problem here is that if you are creating the keys on the device itself, they may be |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

