4.9 • 696 Ratings
🗓️ 11 February 2025
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, February 11th, |
0:03.0 | 2025 edition of the Science Internet Storm Center's Stormcast. |
0:08.4 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:13.0 | Today we got a diary by Dedi with more details regarding that famous mark of the web issue. |
0:20.2 | As I indicated, |
0:21.6 | there have been ongoing issues with the mark of the web, |
0:26.0 | not properly propagating if you're decompressing files |
0:30.5 | or other sort of multifile compound formats, |
0:34.6 | like, for example, disk images. |
0:41.3 | DDA is talking here specifically about 7Sip. 7Sip on Windows has a specific setting that's actually disabled by default |
0:47.3 | to set the mark of the web for all extracted files |
0:51.3 | if the archive overall had this mark set. |
0:55.6 | And again, this is an issue that has to be taken care of on unpacking, on decompression, |
1:01.3 | not on compression, kind of nice if an attacker assembles an archive with the mark of web |
1:07.2 | being set for all the components. |
1:09.0 | But again, the archive was created by the attacker, |
1:11.6 | so it's really up to the defender as they are unpacking these archives to properly set the mark |
1:19.6 | of the web on all files being extracted, so users will get the proper warning as they are then attempting to open any of the files. |
1:31.8 | Then we got an update from Apple for iOS and iPad OS. |
1:37.3 | This particular update fixes one single vulnerability, which already indicates it's important vulnerability. |
1:44.8 | It's one that's already being exploited in the wild. |
1:48.6 | Apparently, this vulnerability allows attackers to bypass USB restricted mode. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.