Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
RTF Files With Hancitor; Electron Dev Tool Creates Vulnerable Windows Apps;
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/5841.mp3
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
RTF Files For Hancitor Utilize Exploit for CVE-2017-11882
https://isc.sans.edu/forums/diary/RTF+files+for+Hancitor+utilize+exploit+for+CVE201711882/23271/
Electron Fixes Protocol Handlers Flaw
https://electronjs.org/blog/protocol-handler-fix
Xerox Workcenters Fudge Numbers
http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_are_switching_written_numbers_when_scanning?
Tracking Users Using CSS
https://github.com/jbtronics/CrookedStyleSheets
https://isc.sans.edu/forums/diary/RTF+files+for+Hancitor+utilize+exploit+for+CVE201711882/23271/
Electron Fixes Protocol Handlers Flaw
https://electronjs.org/blog/protocol-handler-fix
Xerox Workcenters Fudge Numbers
http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_are_switching_written_numbers_when_scanning?
Tracking Users Using CSS
https://github.com/jbtronics/CrookedStyleSheets
Discussion
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form