Threat Level: green Handler on Duty: Remco Verhoef

SANS ISC: SANS Daily Network Security Podcast (Stormcast) for Monday, April 18th 2016 - SANS Internet Storm Center SANS Daily Network Security Podcast (Stormcast) for Monday, April 18th 2016


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Analyzing Malicious Documents and Why Password Change Policies Don't make sense

SANS Daily Network Security Podcast (Stormcast) for Monday, April 18th 2016
00:00

My Next Class

Intrusion Detection In-DepthMadridMar 25th - Mar 30th 2019
Defending Web Applications Security EssentialsSan DiegoMay 9th - May 14th 2019

… more classes

Implementing "bash_history" for cmd.exe
https://isc.sans.edu/forums/diary/Windows+Command+Line+Persistence/20949/

Mixed encoding in Malicious Documents
https://isc.sans.edu/forums/diary/VBS+VBE/20953/

Swedish Air Traffic Control Outage Result of Solar Flares
http://www.lfv.se/en/news/news-2016/full-capacity-after-90-minutes-radar-loss

Why you should not require password changes
https://www.cesg.gov.uk/articles/problems-forcing-regular-password-expiry

Bypassing Microsoft Edge XSS Filter
http://blog.portswigger.net/2016/04/edge-xss-filter-bypass.html



Get a free ISC sticker (login required):
https://isc.sans.edu/sticker.html
Spotify spotify logo

Discussion

In the podcast the comment is made about whether research is available making the case to not force timed password changes.

Lorrie Cranor (http://lorrie.cranor.org/) has done some interesting work in this area. https://www.cylab.cmu.edu/files/pdfs/tech_reports/CMUCyLab13013.pdf

https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-rethink-mandatory-password-changes

http://cups.cs.cmu.edu/passwords.html
https://www.ted.com/talks/lorrie_faith_cranor_what_s_wrong_with_your_pa_w0rd?language=en

Posted by BrianWGray on Tue Apr 19 2016, 14:37

New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form

Intrusion Detection In-DepthMadridMar 25th - Mar 30th 2019
Defending Web Applications Security EssentialsSan DiegoMay 9th - May 14th 2019
Intrusion Detection In-DepthSan AntonioMay 28th - Jun 2nd 2019
Defending Web Applications Security EssentialsMunichJul 1st - Jul 6th 2019
Intrusion Detection In-DepthLondonJul 8th - Jul 13th 2019
Intrusion Detection In-DepthBostonJul 29th - Aug 3rd 2019
Defending Web Applications Security EssentialsSan JoseAug 12th - Aug 17th 2019
Defending Web Applications Security EssentialsArlingtonAug 14th - Aug 19th 2019
Defending Web Applications Security EssentialsBrusselsSep 2nd - Sep 7th 2019
Intrusion Detection In-DepthLondonSep 23rd - Sep 28th 2019