Handler on Duty: Johannes Ullrich
Threat Level: green
Podcast Detail
ISC StormCast for Thursday, December 17th 2015
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/4789.mp3
SANS Daily Network Security Podcast (Stormcast) for Thursday, December 17th 2015
00:00
My Next Class
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
Configuring a Plausible Sandbox
https://isc.sans.edu/forums/diary/Playing+With+Sandboxes+Like+a+Boss/20501/
Grub2 Exploit
http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html#exploit
Outlook Exploit
https://0b3dcaf9-a-62cb3a1a-s-sites.googlegroups.com/site/zerodayresearch/BadWinmail.pdf
(I removed the link about the LinkedIn password leak. it looks like this was an old story from 2012. Thanks to those noticing it.)
https://isc.sans.edu/forums/diary/Playing+With+Sandboxes+Like+a+Boss/20501/
Grub2 Exploit
http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html#exploit
Outlook Exploit
https://0b3dcaf9-a-62cb3a1a-s-sites.googlegroups.com/site/zerodayresearch/BadWinmail.pdf
(I removed the link about the LinkedIn password leak. it looks like this was an old story from 2012. Thanks to those noticing it.)
Discussion
Hi Johannes, is that an just an update on the old 2012 breach for Linkedin?
Posted by seano on Thu Dec 17 2015, 11:34
Thanks seano! I just went back and double checked, and that was indeed an old story.
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Network Monitoring and Threat Detection In-Depth | Baltimore | Mar 3rd - Mar 8th 2025 |
Application Security: Securing Web Apps, APIs, and Microservices | Orlando | Apr 13th - Apr 18th 2025 |