SANS Stormcast Thursday, March 12th, 2026: Zombie Zip;
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 March 2026
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, March 12, 2006 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.2 | My name is Johannes Ulrich, recording day from Jacksonville, Florida. |
| 0:17.2 | And this episode is brought you by the Sands.edu graduate certificate program in incident response. |
| 0:24.6 | Well, let's get started with a vulnerability and a script by DDA. |
| 0:30.8 | So in DDA's diary today, DDA writes about Zombie SIP. |
| 0:35.3 | Zombie Sip has sort of made the news a little bit yesterday, today. |
| 0:39.8 | It's really a stupid vulnerability in something. |
| 0:42.0 | I'll explain a little bit why. |
| 0:44.0 | So the root issue here is when you're having a compressed file, like a SIP file, |
| 0:49.3 | you typically have, as an indicator, what kind of compression is being used and then the content. |
| 0:54.5 | Now, two of the methods that can be used with SIP is one is stored, which actually means |
| 0:59.8 | it's not compressed at all, and then you have deflated, which is, yes, it's compressed. |
| 1:07.5 | Well, what the attacker is doing here is just using the stored indicator and then still |
| 1:13.8 | including a deflated file, meaning that it's now an invalid SIP file and it cannot be opened |
| 1:21.1 | as is. That's really all it comes down to. Of course, since it can't be opened, antivirus tools |
| 1:27.4 | can't open it as well |
| 1:29.0 | and can not sort of by default and inspect the content of the file. |
| 1:35.0 | However, while this sounds cool overall, it's definitely nothing sort of new to concept. |
| 1:39.8 | We have seen this a lot with, you know, some of the compressed file formats and such being abused, |
| 1:47.7 | like with bad checksums and the like. That is like decades old. But this is actually sort of a |
| 1:54.0 | not very useful vulnerability in this particular case because no standard unsip program |
| 2:00.7 | will be able to actually unsip the file. So the attacker |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

