meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, April 8th:

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 8 April 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, April 8th:

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, April 8th, 2025 edition of the Sands Internet Storm Center's Stormcast.

0:08.9

My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:13.9

Quick update from DDA today to answer a question actually that came up in a class

0:19.9

and that's regarding DDA's tool XOR search.

0:23.8

If you're not familiar with XOR search, it's one of DDA's famous Python scripts, and what it does

0:31.7

is it prud forces various XOR parameters to figure out if certain strings are present in a file.

0:42.1

So it assumes that the file is exhort with one particular byte value

0:47.0

and then tries all 255 and checks if any of the results contains a particular string.

0:53.6

Then, of course, can easily then be used to figure out

0:56.1

what is the right key here in order to decode the file.

1:01.9

The problem that came up in class is, well,

1:04.5

can you also search for a regular expression?

1:07.8

And the quick answer is no.

1:10.1

But DDA has a trick for you here, how you can still achieve

1:14.7

regular expression searches. The trick is that you're just dumping all the strings. There is a

1:20.8

mode in XOR search that will basically apply all the XOR values and then extract for each XO values any possible

1:29.4

printable string, similar to the strings command. And then you can take that list of strings

1:35.5

and apply your regular expression with a regular grep. Now, I hear that is working on a version

1:42.9

of XOR search that will officially support

1:46.2

regular expressions, but that's, as far as I know, not quite there yet.

1:51.2

But keep looking for it.

1:52.9

Maybe it'll be out by the time you listen to this podcast, given how fast DDA sometimes

...

Transcript will be available on the free plan in 3 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.