meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 19th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 October 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Obfuscating Python; Oracle CPU; Office 365 Encryption;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, October 19th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:09.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.7

So we here today looked at a technique used to obfuscate malicious Python scripts, and well, that particular

0:22.7

obfuscator is actually available as a web page. You just copy, paste your Python code and

0:29.5

get the obfuscated script back. The technique overall is pretty simple and straightforward,

0:35.6

and I've seen actually very similar stuff also in

0:39.2

JavaScript. The obfuscated Python script uses a number of eval statements that then

0:45.9

decode a hex-encoded version of the script, and then base 64 decoded.

0:52.3

Xavier tested a couple of malicious scripts to see how the simple and obfuscated version scored in virus total.

0:59.9

As expected, virus total detection rates dropped quite a bit for the obfuscated version.

1:06.2

So with a little effort, a simple copy paste to a web page, an attacker is able to bypass a good number of anti-maliver tools.

1:17.1

Personally, I think there's actually sort of an opportunity here for a somewhat more holistic signature,

1:23.0

given that the obfuscated scripts consist mostly of eval statements.

1:28.7

Eval statements, they happen, but they shouldn't really dominate your script like that.

1:35.9

And Oracle, as expected, dropped its quarterly critical patch update today, and as also expected, there are too many products and vulnerabilities covered to really

1:49.1

discuss them here at any lengths.

1:51.7

370 vulnerabilities are addressed and looks like something like 110 or 120

1:58.0

different product families.

2:00.3

So per product, it's actually not that bad.

2:03.3

It's about three vulnerabilities product.

2:07.4

I looked at sort of what the highest TWSS scores,

2:10.1

where they were a good number of vulnerabilities with a score of 9.8.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.