meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 4 March 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, March 4th, 2025 edition of the Sands Inundit Storm Center's Stormgast.

0:08.1

My name is Johannes Ulrich and today I'm recording from Baltimore, Maryland.

0:13.3

Well, and today we have a great diary by DDA showing some of the details of the mark of the web.

0:19.8

That's a feature that we have covered a few times already in the podcast,

0:24.6

usually because it didn't get properly propagated to different file formats,

0:29.1

depending on, for example, SIP file extraction software,

0:33.2

things like ISO images and the like,

0:35.8

where the mark of the web is lost in transfer. So the purpose where the mark of the web is lost in transfer.

0:39.7

So the purpose of the mark of the web is to indicate to the system that this file has been

0:45.5

downloaded from the internet, so the user can be presented with a warning if this file

0:51.6

is executable and the user is attempting to execute it.

0:55.9

On Windows, the mark of the web is implemented as an alternate data stream, which is supported

1:01.7

by the NTFS file system, but not all file systems, and with that not all archive utilities

1:08.5

do properly support alternate data streams,

1:12.2

which explains some of the limitations around the mark of the web implementation on Windows.

1:19.4

DDA also shows a little bit the details here.

1:22.4

So first of all, the mark of the web is essentially a little text file, like that alternate data stream,

1:28.5

and it includes, first of all,

1:30.3

zone information that indicates where the file came from.

1:34.9

So there are zones one through four that will then tell you.

1:38.9

Three, for example, would be this was downloaded from an external website.

1:43.0

In addition, you may find things like the URL.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.