WEBVTT
1
00:00:00.200 --> 00:00:03.960
I told you guys, I started running, right, No? Yeah, yeah,
2
00:00:03.960 --> 00:00:05.440
I told you last week I was running.
3
00:00:05.480 --> 00:00:07.280
You did, Yeah, last week you said you were running?
4
00:00:07.320 --> 00:00:08.599
Yeah? Remember I got hit with the Mayo?
5
00:00:08.880 --> 00:00:09.480
Yeah?
6
00:00:09.480 --> 00:00:10.759
What the hell? Man? Right?
7
00:00:10.880 --> 00:00:11.759
That was okay?
8
00:00:11.839 --> 00:00:12.880
Yeah that was last week.
9
00:00:12.960 --> 00:00:16.160
That was last week. Yeah. Yeah. So what I didn't
10
00:00:16.199 --> 00:00:18.480
tell you is my mother started running when she was
11
00:00:18.519 --> 00:00:19.199
seventy five.
12
00:00:19.440 --> 00:00:20.440
Wow, good for her.
13
00:00:20.519 --> 00:00:22.480
Yeah, she's eighty nine. Now we don't know where the
14
00:00:22.519 --> 00:00:23.120
hell she is.
15
00:00:24.320 --> 00:00:27.640
She just keeps keiths on going.
16
00:00:34.759 --> 00:00:38.640
All right, so we got six stories today. We're going
17
00:00:38.719 --> 00:00:42.399
to start with what I think is the most awesome story,
18
00:00:42.600 --> 00:00:45.759
and not in a Dwayne sense and then literal sense.
19
00:00:46.439 --> 00:00:51.640
Massive data breach at known SEC exposes China's state sponsored
20
00:00:51.679 --> 00:00:56.600
hacking tools and global targets. The hackers have been hacked.
21
00:00:56.799 --> 00:01:00.960
Oh no, this is the inversion of Equation Groups. So
22
00:01:01.000 --> 00:01:03.079
back when we first started the podcast, there was a
23
00:01:03.119 --> 00:01:07.760
hack against an organization called Equation Group that supposedly revealed
24
00:01:07.799 --> 00:01:10.359
a whole bunch of tools that the NSA had been using. Yeah,
25
00:01:10.400 --> 00:01:13.680
and this is the Chinese version of that. Basically, yeah,
26
00:01:13.760 --> 00:01:16.359
I agree, this is this is I have schadenfreude.
27
00:01:16.560 --> 00:01:19.319
I serious shotenfreuda.
28
00:01:19.799 --> 00:01:22.879
So what are the ramifications here, Like they're a legit
29
00:01:23.040 --> 00:01:27.799
company and legit country I guess you could say in
30
00:01:27.840 --> 00:01:28.719
an actual country.
31
00:01:28.840 --> 00:01:31.760
Yeah, but it basically China has tipped their hands. So
32
00:01:31.840 --> 00:01:35.000
now we're seeing more about how they're The Chinese opsect
33
00:01:35.000 --> 00:01:38.040
has been violated, their operational security has been bad.
34
00:01:38.280 --> 00:01:42.040
Yeah, state sponsored hacking tools and global surveillance targets have
35
00:01:42.159 --> 00:01:46.159
been uncovered. So basically, now we know what they do
36
00:01:46.439 --> 00:01:49.680
and the tools that they use to hack what, you know,
37
00:01:49.959 --> 00:01:50.879
all the rest of the world.
38
00:01:51.000 --> 00:01:53.359
It's a snapshot into what they're using right now.
39
00:01:53.560 --> 00:01:57.200
I guess for me, I'm not surprised. This was like, oh,
40
00:01:57.239 --> 00:01:59.519
by the way, like if the ozone goes away, we'll
41
00:01:59.519 --> 00:02:01.920
all get cut. Like I'm like, yeah, okay, cool, I've
42
00:02:01.920 --> 00:02:05.239
seen this forever. This makes sense, right, that they're state
43
00:02:05.319 --> 00:02:09.400
sponsored Chinese hackers that are legit companies. So yeah, I
44
00:02:09.400 --> 00:02:11.800
don't know. I wasn't surprised, but yes, but.
45
00:02:11.879 --> 00:02:15.680
You don't have a little delight in the misery of
46
00:02:15.840 --> 00:02:18.840
these of the China state sponsored hacks. I have.
47
00:02:19.240 --> 00:02:20.159
I always have delight.
48
00:02:21.080 --> 00:02:24.680
Yeah, Okay, so you have shadenfreude like Patrick and I do.
49
00:02:25.159 --> 00:02:27.879
Yes, yes, yeah, yes.
50
00:02:27.840 --> 00:02:30.159
Well, and it also kind of diffuses the idea that
51
00:02:30.280 --> 00:02:34.800
you know, they're they're super men. I don't think China
52
00:02:34.840 --> 00:02:37.759
has volume. They have mass, they have a lot of people,
53
00:02:38.199 --> 00:02:42.400
but I think that they're probably at the level of
54
00:02:42.439 --> 00:02:46.199
the NSA roughly because of that mass, but not because
55
00:02:46.199 --> 00:02:47.840
of quality. So I think the US st leads in
56
00:02:47.919 --> 00:02:50.360
quality and the Chinese quantity.
57
00:02:50.560 --> 00:02:52.719
And as we said before, there's a difference between China
58
00:02:52.759 --> 00:02:54.240
and Russia, right.
59
00:02:54.439 --> 00:02:55.599
It's about a thousand miles.
60
00:02:55.759 --> 00:02:59.680
Yeah, I know, but okay to che I thought I
61
00:02:59.800 --> 00:03:00.960
was joke maker here.
62
00:03:02.479 --> 00:03:03.960
Well, based on that one, you still are.
63
00:03:04.080 --> 00:03:08.360
All right. So, but China's Internet has grown up from
64
00:03:08.360 --> 00:03:13.759
the very beginning to be state controlled right right, whereas
65
00:03:13.840 --> 00:03:17.800
Russia was open for a while and then they started
66
00:03:17.800 --> 00:03:20.319
plugging the holes or trying to plug the holes, and
67
00:03:20.719 --> 00:03:23.560
you know, so there you go. So we have more
68
00:03:23.599 --> 00:03:27.080
to fear from China and their use of the Internet
69
00:03:27.120 --> 00:03:31.639
against nation states than we do Russia. I think, Yeah, I.
70
00:03:31.560 --> 00:03:34.400
Think the argument or maybe there's just I could I know,
71
00:03:34.479 --> 00:03:35.639
I buy that. I buy that.
72
00:03:35.680 --> 00:03:37.919
I think maybe there's just not as many holes in
73
00:03:38.199 --> 00:03:41.400
China's armor as there are in Russia's. Maybe that's it.
74
00:03:41.479 --> 00:03:44.520
Well, and I think Russia is pretty open about the
75
00:03:44.520 --> 00:03:47.919
fact that like, oh yeah, absolutely, we use third party
76
00:03:48.240 --> 00:03:52.080
you know, brought teams to create all of these cyber
77
00:03:52.159 --> 00:03:54.479
weapons and just let them release them as long as
78
00:03:54.479 --> 00:03:55.680
they're not on Russian So well.
79
00:03:55.639 --> 00:03:57.840
Yeah, yeah, as long as I don't use a Russian keyboard.
80
00:03:57.800 --> 00:04:01.159
Where is that? Whereas most other nations go, oh my god,
81
00:04:01.199 --> 00:04:03.360
that's terrible, we'd never do that, and then they do
82
00:04:03.400 --> 00:04:04.159
it in secret.
83
00:04:05.360 --> 00:04:07.879
I wonder if you loaded a Russian keyboard in whether
84
00:04:07.879 --> 00:04:09.599
you'd get a little extra protection.
85
00:04:10.840 --> 00:04:13.800
Sometimes. Yes, actually, that's a great that's a great point.
86
00:04:14.000 --> 00:04:18.360
There was a version of ransomware that would detect either
87
00:04:18.519 --> 00:04:22.040
a your time zone or b whether you were using
88
00:04:22.160 --> 00:04:25.600
a cyrillic keyboard, and if you were, it would just
89
00:04:25.639 --> 00:04:26.399
disarm itself.
90
00:04:26.560 --> 00:04:26.839
Wow.
91
00:04:27.120 --> 00:04:30.439
Yeah. So so there have been known cases of them
92
00:04:30.519 --> 00:04:33.480
going oh are bad, sorry we infected you and just ditching.
93
00:04:33.639 --> 00:04:35.839
Excuse me, mister Putin, I didn't know it was you.
94
00:04:35.959 --> 00:04:42.759
Yeah, all right, so smart good news. We've talked about
95
00:04:42.759 --> 00:04:47.319
pone to own before, which is a great gathering of
96
00:04:47.360 --> 00:04:51.480
people who try to hack things and find bugs, right,
97
00:04:52.240 --> 00:04:55.519
and so this story is from Bleeping Computer. Q NAP
98
00:04:55.600 --> 00:05:00.560
fixes seven NASS zero day flaws exploited at to own
99
00:05:00.839 --> 00:05:01.319
fairy good.
100
00:05:01.519 --> 00:05:03.720
So I like this. Yeah, I mean we've seen that,
101
00:05:03.720 --> 00:05:05.680
We've talked about pone to own this, like the the
102
00:05:05.720 --> 00:05:10.120
nerd super Bowl for for hackers. I actually really I
103
00:05:10.680 --> 00:05:13.439
find it cool. I actually watched the stream and popcorn
104
00:05:13.519 --> 00:05:15.720
and wow, like, wooe here on the teams?
105
00:05:18.079 --> 00:05:19.920
Is that on? I think that conflicts with the World
106
00:05:20.040 --> 00:05:21.360
Grass Growing Championships.
107
00:05:23.759 --> 00:05:25.600
You're like, I'm sorry, I'm out, I'm out.
108
00:05:25.759 --> 00:05:27.920
Is that the Mayo chucking Contest?
109
00:05:29.959 --> 00:05:32.720
Yeah? That's uh. I don't know what what channel of
110
00:05:32.800 --> 00:05:36.079
TV that would be on ESPN X Games Maybe No,
111
00:05:36.240 --> 00:05:39.199
I don't think so. No, it's actually it's really cool
112
00:05:39.240 --> 00:05:42.639
to see, Uh, these types of devices that obviously, like
113
00:05:42.680 --> 00:05:46.759
a q NAP is more geared towards home users or
114
00:05:46.839 --> 00:05:51.399
either that or small really small medium businesses. Right, So
115
00:05:52.279 --> 00:05:54.759
generally the people who are implementing these devices don't have
116
00:05:55.319 --> 00:05:57.839
millions of dollars to put towards cybersecurity or have their
117
00:05:57.839 --> 00:06:00.879
own cybersecurity team. Some of them wouldn't even have their
118
00:06:00.879 --> 00:06:05.199
own technical folks in house, right, They'd either have a
119
00:06:05.279 --> 00:06:07.560
hired team or they'd have a nephew that they'd torture
120
00:06:07.639 --> 00:06:12.759
and have come fixed prints. Nice niece couldn't be open absolutely,
121
00:06:13.560 --> 00:06:15.199
so in this case, I mean, I think it's great
122
00:06:15.199 --> 00:06:18.680
that that you see pon to own, not just focusing
123
00:06:18.720 --> 00:06:21.199
on like, oh, let's take a look at the you know,
124
00:06:21.439 --> 00:06:25.879
brand new CMC like whatever. Right, it's nice that you
125
00:06:25.879 --> 00:06:27.600
look at those, and it's important and it's a big
126
00:06:27.639 --> 00:06:29.439
surface of attack. But I love it when they focus
127
00:06:29.480 --> 00:06:31.560
on really kind of more of the home user stuff.
128
00:06:32.160 --> 00:06:34.959
Net app doesn't need their help. They have their own budgets.
129
00:06:35.079 --> 00:06:36.800
No, they have. I mean they have enough money they
130
00:06:36.800 --> 00:06:39.920
can spend, right, and even Tesla, like I get it,
131
00:06:39.720 --> 00:06:43.360
it affects the population. But and somebody who buys the
132
00:06:43.399 --> 00:06:45.160
Tesla is not obviously going to tear it apart to
133
00:06:45.160 --> 00:06:48.600
see if there's vulnerabilities. But let's be clear, Tesla has
134
00:06:48.680 --> 00:06:52.439
enough money to pay for vulnerabilities right to be checked
135
00:06:52.600 --> 00:06:55.600
and so whatever. But yeah, no, I actually really like
136
00:06:55.639 --> 00:06:57.680
Bono's It's a great competition.
137
00:06:57.759 --> 00:06:58.000
Cool.
138
00:06:58.040 --> 00:07:02.879
So they as we said, they have these vulnerabilities, and
139
00:07:02.920 --> 00:07:07.000
they weren't. It wasn't like somebody got into their system
140
00:07:07.120 --> 00:07:10.879
and implanted malware or something like that or spyware. They
141
00:07:10.879 --> 00:07:12.519
were just vulnerabilities. Yeah.
142
00:07:12.560 --> 00:07:17.480
Yeah, and everything has vulnerabilities. Let's not get all high
143
00:07:17.480 --> 00:07:20.360
and mighty. There's no Yeah, there's no software. There's no
144
00:07:20.439 --> 00:07:22.879
component that you're using that doesn't have a vulnerability that
145
00:07:22.959 --> 00:07:26.800
may never get discovered or might not get discovered, you know,
146
00:07:26.959 --> 00:07:29.959
till next year or next next decade. Many of the
147
00:07:30.040 --> 00:07:33.759
vulnerabilities that we know about, and there are tens of
148
00:07:33.839 --> 00:07:36.920
thousands of them, were there a long time before they
149
00:07:36.959 --> 00:07:37.519
were discovered.
150
00:07:37.560 --> 00:07:40.160
All right. Yeah, and now I'll tell you there was
151
00:07:40.199 --> 00:07:42.800
a new patch just this week released by a major
152
00:07:42.879 --> 00:07:47.759
firewall vendor, and we happened to have a couple free seconds,
153
00:07:47.759 --> 00:07:50.639
so we downloaded the binaries for the firmware, took a
154
00:07:50.639 --> 00:07:52.959
look at it, and there's three vulnerabilities in the new
155
00:07:52.959 --> 00:07:55.839
piece of suftware. So wow, and it just came out
156
00:07:55.839 --> 00:07:59.560
this week, so you know what. Yeah, absolutely, and these
157
00:07:59.600 --> 00:08:01.279
these people no security.
158
00:08:00.920 --> 00:08:02.680
So we just got to keep on top of it,
159
00:08:02.720 --> 00:08:03.519
that's all right.
160
00:08:03.639 --> 00:08:07.959
Yeah, it's never going to be over. Yeah, it's over
161
00:08:08.040 --> 00:08:11.000
when you know, when Skynet really does go online soon.
162
00:08:11.360 --> 00:08:15.279
Other than that, as long as there's people to be
163
00:08:15.399 --> 00:08:17.480
exploiting these things, they're going to get.
164
00:08:17.319 --> 00:08:22.319
Exploited, all right. So this one had me go patch NPM, right,
165
00:08:22.360 --> 00:08:28.240
away critical NPM library flaw, risks AI and NLP apps
166
00:08:28.519 --> 00:08:33.360
urgent patch urged, urgent patch, urged.
167
00:08:33.240 --> 00:08:34.440
Urgent, urged.
168
00:08:34.519 --> 00:08:36.840
It's a lot of urging to prevent. We can't urge
169
00:08:36.879 --> 00:08:41.240
it enough to prevent RCE remote control execution. So, for
170
00:08:41.279 --> 00:08:45.000
those who don't know, NPM is like new Get for JavaScript,
171
00:08:45.120 --> 00:08:47.440
and you probably know what MPM is. It's a very
172
00:08:47.559 --> 00:08:51.639
very popular package management tool for JavaScript packages.
173
00:08:51.879 --> 00:08:53.480
Yeah, but an RC is nothing else.
174
00:08:53.519 --> 00:08:56.600
Sneeze at no remote control execution is a serious thing.
175
00:08:57.039 --> 00:08:59.159
Yeah. So the issue here is the library they're talking
176
00:08:59.159 --> 00:09:02.080
about has a part sure out to valuate method that
177
00:09:02.159 --> 00:09:07.679
lets attackers actually inject objects through the context argument not
178
00:09:07.799 --> 00:09:12.879
good passed to their to that parameter enable, enabling obviously
179
00:09:13.080 --> 00:09:15.200
a remote code execution, which is you know, I always
180
00:09:15.240 --> 00:09:18.960
find awesome when you can just randomly take an object
181
00:09:19.039 --> 00:09:20.919
you want and toss it in a parameter and oh,
182
00:09:20.919 --> 00:09:24.159
by the way, I get a prompt somewhere, so it's
183
00:09:24.240 --> 00:09:26.399
it's kind of cool. But in this, you know, according
184
00:09:26.440 --> 00:09:28.679
to this article is a CV twenty twenty five one
185
00:09:28.759 --> 00:09:31.360
two seven three five. A significant security flaw has been
186
00:09:31.399 --> 00:09:37.440
identified widely utilized Java script library e xpr EVL as
187
00:09:37.480 --> 00:09:40.720
well as UH which is a natural language processing application.
188
00:09:40.799 --> 00:09:43.600
So yeah, it's in. It's an interesting flaw, and I
189
00:09:43.600 --> 00:09:45.919
think a lot of a lot of developers don't. This
190
00:09:46.000 --> 00:09:48.360
is a good point to just point out, like a
191
00:09:48.360 --> 00:09:51.200
lot of developers aren't security developers, Right, those are two
192
00:09:51.279 --> 00:09:58.840
very different things, Right, one exists and one doesn't. Ait
193
00:09:58.879 --> 00:10:01.240
a second, maybe Patrick is the jokes drew on here
194
00:10:02.080 --> 00:10:03.840
sadly give up.
195
00:10:05.399 --> 00:10:06.080
Today.
196
00:10:07.240 --> 00:10:09.919
Yeah, it's but it's it's Unfortunately a lot of times
197
00:10:10.120 --> 00:10:12.279
I see will like when we're doing a pen test
198
00:10:12.320 --> 00:10:15.679
web application pen test or even a static applications standalone
199
00:10:15.679 --> 00:10:19.679
application pen test. You know, we'll deliver our report and
200
00:10:19.720 --> 00:10:21.799
they will be like, oh, there's thirty five you know,
201
00:10:21.960 --> 00:10:25.720
critical remote code execution bugs blah blah blah whatever. Right,
202
00:10:26.440 --> 00:10:28.759
and we get to that conversation with the company and
203
00:10:28.759 --> 00:10:32.000
the company's always like our developers just terrible. But they're
204
00:10:32.039 --> 00:10:34.840
just horrible. We're like, no, they actually, you know, they
205
00:10:34.840 --> 00:10:37.000
have an application. It works really well, it does, it's
206
00:10:37.039 --> 00:10:41.200
what it's supposed to do. They just don't. Developers aren't
207
00:10:41.279 --> 00:10:45.360
classically trained in cybersecurity. They don't know what they're looking for. Right.
208
00:10:46.120 --> 00:10:48.799
And we've even had some customers that you know, the
209
00:10:48.919 --> 00:10:51.320
same issues show up over and over and over again.
210
00:10:51.720 --> 00:10:54.320
And even there, it's like they haven't been trained what
211
00:10:54.639 --> 00:10:58.840
not to do right, to look for this pattern. So yeah,
212
00:10:58.879 --> 00:11:03.399
it's even even you may have fantastic developers and that's great,
213
00:11:03.720 --> 00:11:06.080
but if they're not trained to look for these patterns. Yeah,
214
00:11:06.120 --> 00:11:08.000
you know, I always liking it too. You're looking for
215
00:11:08.039 --> 00:11:10.440
something that's not there. It's not like you're looking through
216
00:11:10.440 --> 00:11:12.320
code and looking for a bug and it has that
217
00:11:12.399 --> 00:11:14.679
red squiggly and you go, of course, this is your bug.
218
00:11:15.039 --> 00:11:18.039
You're actually looking for the logic that you didn't implement
219
00:11:18.120 --> 00:11:20.240
that you should have that would have protected you. And
220
00:11:20.279 --> 00:11:21.440
that's a lot harder to find.
221
00:11:21.559 --> 00:11:22.879
So you have to know how to read code and
222
00:11:22.960 --> 00:11:25.919
understand what a programmer is doing and then notice that
223
00:11:25.960 --> 00:11:26.799
they're doing.
224
00:11:26.879 --> 00:11:29.759
Well, you have to understand how it could be abused. Yes,
225
00:11:30.000 --> 00:11:32.519
and that's a different thought process. That's not even it
226
00:11:32.559 --> 00:11:36.279
is the same as And then there's levels to it. Yes,
227
00:11:36.320 --> 00:11:38.759
there's total different levels to it. So you know this
228
00:11:38.919 --> 00:11:41.840
data code analysis, which is like, oh, well, this is
229
00:11:41.879 --> 00:11:45.720
a common mistake, and then there as well, the person's
230
00:11:45.759 --> 00:11:47.120
going to take the thing and use it in a
231
00:11:47.159 --> 00:11:50.360
way that was never intended and is in most people's
232
00:11:50.360 --> 00:11:54.399
cases not imagined. Yes, and it may might not even
233
00:11:54.720 --> 00:11:57.080
be Well you might go, well, you can't do anything
234
00:11:57.159 --> 00:11:59.120
with that. No, you can't do anything with that, but
235
00:11:59.159 --> 00:12:01.200
it's a stepping stone. I'm going to change seven of
236
00:12:01.240 --> 00:12:04.960
these little things together, and with them I can do something.
237
00:12:05.080 --> 00:12:05.360
Yeah.
238
00:12:05.480 --> 00:12:09.240
Yeah. We've definitely seen a chain of attack where it's like, well,
239
00:12:09.279 --> 00:12:12.000
I have no privilege, but I can, I can, I can,
240
00:12:12.240 --> 00:12:14.360
I can see which tokens are in use, and you're like, well,
241
00:12:14.360 --> 00:12:16.559
who cares? Right, It's like, okay, but if I couple
242
00:12:16.639 --> 00:12:20.759
that with this particular attack or this email where somebody
243
00:12:20.799 --> 00:12:22.759
clicks on a link or whatever, right, and now you're
244
00:12:22.919 --> 00:12:26.039
you're you're chaining those together, and we definitely see the
245
00:12:26.120 --> 00:12:28.279
chained attacks are very hard to find in the static
246
00:12:28.279 --> 00:12:31.120
code analysis. So even in dynamic code analysis, you need
247
00:12:31.120 --> 00:12:32.039
to know what you're looking for.
248
00:12:32.120 --> 00:12:35.360
Even AI is going to have trouble Yeah that stuff, yeah, yep,
249
00:12:35.799 --> 00:12:37.559
until you tell it about it, and then it goes,
250
00:12:37.600 --> 00:12:40.039
oh my god, you're right, right.
251
00:12:40.240 --> 00:12:43.879
I'm not going to fix it, but it's right, you're right, right, Yeah,
252
00:12:43.919 --> 00:12:46.759
I'm not going to change it to be real, right.
253
00:12:47.000 --> 00:12:47.639
But you're right.
254
00:12:47.960 --> 00:12:51.879
Think about the TV show Mcgiver Love All the situation
255
00:12:52.000 --> 00:12:56.039
mcgiver mcgroover is also good, but Mcgiver's really much more effective.
256
00:12:56.279 --> 00:12:58.759
Guver's way better. Richard Dean Anderson.
257
00:12:58.360 --> 00:13:02.519
Mcgiver was an engineer. Here is an engineer version of
258
00:13:02.600 --> 00:13:03.360
Magnum p I.
259
00:13:03.480 --> 00:13:05.639
Right, yes, yes, mcg was awesome.
260
00:13:05.759 --> 00:13:09.440
So if you you mcgiver found himself in a hangar
261
00:13:09.759 --> 00:13:12.639
and or some you know, or a machine shop or
262
00:13:12.919 --> 00:13:15.600
a chemistry lab or something like that, and the bad
263
00:13:15.600 --> 00:13:17.519
guy said, oh, we got them, we got them locked up.
264
00:13:17.519 --> 00:13:21.000
He can't go anywhere, not realizing he's gonna take these things,
265
00:13:21.039 --> 00:13:25.720
make some hydrogen, you know, magnesium off.
266
00:13:25.600 --> 00:13:30.600
Of em glue and a rubber band and C for J.
267
00:13:31.279 --> 00:13:34.480
Is kind of the way most people think about hacks.
268
00:13:34.519 --> 00:13:37.080
Oh so there's a vulnerability, and I can give it
269
00:13:37.159 --> 00:13:39.600
something and I can abuse its interface and I can
270
00:13:39.679 --> 00:13:42.720
make it through something even that wasn't obvious to the
271
00:13:42.759 --> 00:13:43.399
average user.
272
00:13:43.879 --> 00:13:47.240
Right, But then wait to give you an analogy of that,
273
00:13:47.279 --> 00:13:49.360
Patrick log for J was like, oh, so you're saying
274
00:13:49.399 --> 00:13:51.919
I can pick up this handgun and I can shoot
275
00:13:51.919 --> 00:13:54.440
somebody with it. That's cool. We never even thought about,
276
00:13:54.480 --> 00:13:56.840
like yeah, exactly.
277
00:13:59.320 --> 00:14:02.279
And then but we get to manipulation and the next level,
278
00:14:03.000 --> 00:14:06.919
we're in a very different world that the average developer
279
00:14:07.320 --> 00:14:09.480
can't be. If you try to train developers to do that,
280
00:14:10.840 --> 00:14:14.200
you're probably going to break the developers. Yeah, and so
281
00:14:14.519 --> 00:14:17.919
we're stuck in this world of even security companies companies
282
00:14:18.039 --> 00:14:21.840
whose job is security. They're developers, aren't security experts. They're
283
00:14:21.879 --> 00:14:25.879
aware of security, and their code gets checked more often.
284
00:14:26.240 --> 00:14:28.639
That's the reason that you're less likely to get a
285
00:14:28.679 --> 00:14:32.600
security company's code. But that doesn't mean they're invulnerable to vulnerabilities.
286
00:14:33.039 --> 00:14:36.159
And then there's also so we're all old enough to remember,
287
00:14:36.279 --> 00:14:38.639
I'm outing us on age. We're old enough to remember
288
00:14:38.879 --> 00:14:41.360
before there was a sequel injection, before there was a
289
00:14:41.440 --> 00:14:45.440
concept called sequel injection. I remember all the code in
290
00:14:45.519 --> 00:14:47.720
the world written at that time it was vulnerable to
291
00:14:47.720 --> 00:14:50.840
sequel injection. Yeah, because no one knew that was a thing, right,
292
00:14:50.919 --> 00:14:53.360
No one invented it, right, No one had invented it yet.
293
00:14:53.279 --> 00:14:54.919
Until Rainforest Puppy came out with it.
294
00:14:55.000 --> 00:14:57.559
I remember seeing at a tech at a Microsoft guy
295
00:14:57.720 --> 00:15:02.080
introduced SQL injection the the first time, and like twenty
296
00:15:02.080 --> 00:15:04.240
people just got up and ran out of it exactly.
297
00:15:04.399 --> 00:15:06.399
I've had that I remember doing that.
298
00:15:06.399 --> 00:15:06.879
That was fun.
299
00:15:06.960 --> 00:15:12.000
Yeah, but we have the same kinds of vulnerabilities someday
300
00:15:12.039 --> 00:15:13.840
that we'll find out. And like, I can't believe people
301
00:15:13.879 --> 00:15:16.279
use variables. I mean, Christ, you know what.
302
00:15:17.799 --> 00:15:22.000
So to get back to this NPM thing, yeah, sorry, yeah,
303
00:15:22.080 --> 00:15:25.759
So they don't have a score listed in this article.
304
00:15:25.799 --> 00:15:27.000
I think this one goes to eleven.
305
00:15:27.120 --> 00:15:30.159
But I would say if it says urgent patch urged,
306
00:15:30.879 --> 00:15:36.600
I'm thinking that it's eleven, maybe go patch. So do
307
00:15:36.679 --> 00:15:39.799
you need to just update your version of NPM or
308
00:15:39.879 --> 00:15:45.000
if you're using this library expression evaluator expert evail, is
309
00:15:45.039 --> 00:15:47.840
that the thing you should also update that if there's
310
00:15:47.840 --> 00:15:48.600
a new patch or what.
311
00:15:48.759 --> 00:15:51.240
Here's what I would tell you, go update everything that's
312
00:15:51.320 --> 00:15:55.720
that's there and m the visual studio that's running like whatever. Like,
313
00:15:55.759 --> 00:15:58.519
if there's an update, go update everything. However, if you
314
00:15:58.519 --> 00:16:01.799
you just specifically for some reason, let's say you're in
315
00:16:01.799 --> 00:16:03.960
a production environment and there's change control and blah blah
316
00:16:03.960 --> 00:16:06.720
blah whatever, then you just want to update this library.
317
00:16:06.840 --> 00:16:10.799
Okay, all right, good with that. We'll take a little break.
318
00:16:10.960 --> 00:16:14.159
We'll be right back after these messages or no messages,
319
00:16:14.240 --> 00:16:17.759
as the case may be, but we'll be right back.
320
00:16:22.320 --> 00:16:25.200
All right, we're back. It's security this week. I'm Carl
321
00:16:25.240 --> 00:16:29.759
Franklin's Patrick Hines and Dwayne Laflotte. Hey guys, and we
322
00:16:29.879 --> 00:16:33.000
got a couple more stories to go through here. Microsoft
323
00:16:33.080 --> 00:16:37.120
patches actively exploited Windows kernel zero.
324
00:16:37.000 --> 00:16:39.120
Day Yeah, also known as Tuesday.
325
00:16:39.320 --> 00:16:43.039
So if it's actively exploited, is it a zero day?
326
00:16:43.919 --> 00:16:46.799
Yeah, only if it hasn't been patched, although this I
327
00:16:46.879 --> 00:16:48.679
believe by now has been patched.
328
00:16:48.840 --> 00:16:51.840
I mean, anybody, anybody who has a zero day and
329
00:16:51.919 --> 00:16:54.080
uses it for a year is actively exploiting it. It's
330
00:16:54.080 --> 00:16:56.399
just not publicly known, right, So it has nothing to
331
00:16:56.440 --> 00:16:58.159
do with the fact that whether it's exploited or not
332
00:16:58.759 --> 00:16:59.720
with whether it's been patched.
333
00:16:59.840 --> 00:17:03.799
So this ends up being one of the big issues here,
334
00:17:04.440 --> 00:17:10.680
is a privileged escalation with super duper level privileges, right,
335
00:17:10.920 --> 00:17:12.359
because we have kernel level issues.
336
00:17:12.359 --> 00:17:14.079
But I like technical term it is.
337
00:17:14.240 --> 00:17:17.960
But I absolutely love the last sentence, the last sentence
338
00:17:17.960 --> 00:17:23.359
of this article. Casually the article says, you know, so overall,
339
00:17:23.839 --> 00:17:26.920
more than thirty vulnerabilities fixed this month twenty two allow
340
00:17:27.000 --> 00:17:30.279
remote code execution and a bunch of other weaknesses like spoofing,
341
00:17:31.000 --> 00:17:35.160
denial of service, security, bypass information disclosure, you know, just
342
00:17:35.319 --> 00:17:37.480
back just kind of day like.
343
00:17:37.519 --> 00:17:40.559
How much good news though? Because they fixed them?
344
00:17:41.119 --> 00:17:45.000
Right, But how is it in today's day? Like ten
345
00:17:45.119 --> 00:17:47.519
years ago if you had an article that listed out
346
00:17:48.039 --> 00:17:51.599
fifty plus vulnerabilities and a piece of software, like people
347
00:17:51.640 --> 00:17:54.200
be like I'm never using this thing now We're like, yeah, whatever,
348
00:17:54.279 --> 00:17:57.400
it's a Tuesday, just go apply a pad Tuesday, and
349
00:17:57.799 --> 00:17:58.279
that's fine.
350
00:17:58.519 --> 00:18:01.640
It's a lot of products though, it's it's Asure monitor Agent,
351
00:18:01.799 --> 00:18:06.839
it's Dynamics third sixty five, it's office, it's one drive, SharePoint,
352
00:18:06.960 --> 00:18:11.559
Edge Office, some studio windows. It's a lot of different things.
353
00:18:11.599 --> 00:18:15.400
So yeah, okay, on average is probably one or two vulnerabilities.
354
00:18:15.400 --> 00:18:16.880
And again these are big products. Some of them have
355
00:18:16.960 --> 00:18:18.039
millions of lines of code.
356
00:18:18.440 --> 00:18:20.160
The good news is they found them and fix them.
357
00:18:20.160 --> 00:18:21.960
Oh yeah, yeah, absolutely it is.
358
00:18:22.240 --> 00:18:26.039
The bad news is that there's sixty opportunities because there's
359
00:18:26.039 --> 00:18:30.160
like sixty patches on this thing where one days can
360
00:18:30.200 --> 00:18:32.920
become a thing where where there's hackers out there racing
361
00:18:33.000 --> 00:18:36.079
to look at those those patches to figure out what
362
00:18:36.119 --> 00:18:38.240
they fixed and then go after the people who haven't
363
00:18:38.240 --> 00:18:41.880
patched yet. And so what's the lag? How long one
364
00:18:41.920 --> 00:18:44.240
of the questions our listeners should be listening to be
365
00:18:44.279 --> 00:18:47.319
thinking about, is what's the lag between a patch coming
366
00:18:47.319 --> 00:18:50.119
out and your company implementing it. If the answer is
367
00:18:50.119 --> 00:18:52.240
in months, you're screwed. If the answers in weeks, you
368
00:18:52.319 --> 00:18:53.319
might still be in trouble.
369
00:18:53.519 --> 00:18:56.039
Yep, it should be that day asap.
370
00:18:56.440 --> 00:18:59.920
I mean, yeah, absolutely, it's becoming more and more urgent.
371
00:19:00.440 --> 00:19:03.319
I mean it's becoming more and more like almost it's
372
00:19:03.359 --> 00:19:04.880
gonna have to be instantaneous by the end of the
373
00:19:04.880 --> 00:19:05.400
deck game, right.
374
00:19:05.440 --> 00:19:07.200
But I think a lot of people fall behind the
375
00:19:07.400 --> 00:19:12.319
you know, our standard operating procedure is we take a patch,
376
00:19:12.400 --> 00:19:14.839
we put it in the lab, we install the patch,
377
00:19:14.920 --> 00:19:17.920
We then run it through testing, we do full regression testing,
378
00:19:18.039 --> 00:19:21.039
then we roll it into you know QA, We then
379
00:19:21.119 --> 00:19:22.880
run it there, burn it in for a little bit,
380
00:19:22.880 --> 00:19:24.519
and then we put it in production right to make
381
00:19:24.559 --> 00:19:26.960
sure it's stable and working blow or whatever. I think
382
00:19:27.039 --> 00:19:30.599
the problem there is that Paradigm worked really well from
383
00:19:30.880 --> 00:19:34.680
nineteen ninety seven to about two thousand and three. Yeah, right,
384
00:19:34.799 --> 00:19:38.519
that was a perfect process of rollout. But we're not
385
00:19:38.599 --> 00:19:45.240
seeing BCDR plans actually updated for for nowadays. And you know, unless.
386
00:19:44.880 --> 00:19:47.240
Business continuity disaster recovery.
387
00:19:47.440 --> 00:19:50.039
Yeah, unless you're talking about you know, the people who
388
00:19:50.079 --> 00:19:53.480
have really gone deep into adopting like cloud and multiple
389
00:19:53.480 --> 00:19:56.640
cloud zones in replication and like where they're you know, listen,
390
00:19:56.680 --> 00:19:58.920
we're up all the time, like your Netflix and that
391
00:19:59.000 --> 00:20:01.240
sort of stuff. Like one issue is not going to
392
00:20:01.319 --> 00:20:04.880
drop Netflix. So yeah, it's I think we need to
393
00:20:04.960 --> 00:20:09.079
reevaluate how we handle patching and how we handle servers
394
00:20:09.079 --> 00:20:10.880
to make sure that they're up and running, but not
395
00:20:11.200 --> 00:20:11.880
the vulnerable.
396
00:20:12.079 --> 00:20:16.240
We talked about this before too, that AI bot nets
397
00:20:16.319 --> 00:20:23.559
or bots are now downloading these you know, updates notices,
398
00:20:23.920 --> 00:20:28.119
going and figuring them out and then immediately like deploying.
399
00:20:28.279 --> 00:20:32.279
That's the one day hacks against the Yeah, so that's
400
00:20:32.319 --> 00:20:36.240
one day. So it's not that you know, you're somebody
401
00:20:36.680 --> 00:20:41.119
in their office is going to get that stuff and
402
00:20:41.160 --> 00:20:43.400
then put something together and figure out how to hack
403
00:20:43.480 --> 00:20:45.920
and maybe a couple of days later you might be
404
00:20:46.000 --> 00:20:49.119
the unlucky recipient of that. Like the bots are out there.
405
00:20:48.960 --> 00:20:51.680
Now, oh yeah, well, but then they're being they're being
406
00:20:51.720 --> 00:20:54.480
driven by the people who used to do that by hand, right,
407
00:20:54.559 --> 00:20:57.279
you know, it's still not easy to get AI to
408
00:20:57.279 --> 00:21:00.680
do this kind of stuff. It's it sounds easy, sounds trivial,
409
00:21:00.920 --> 00:21:02.119
but it's not that easy.
410
00:21:02.400 --> 00:21:04.960
Just like us developers, you know, we're more productive using
411
00:21:05.000 --> 00:21:08.240
AI to help us do things, so they're the hackers
412
00:21:08.240 --> 00:21:11.000
are using it to be more productive to hack.
413
00:21:11.119 --> 00:21:13.200
They are, But but again the same thing. You can't
414
00:21:13.400 --> 00:21:15.720
take somebody who doesn't know how to program and say, oh,
415
00:21:15.759 --> 00:21:19.400
go and write clients are Yeah, the same is true
416
00:21:19.440 --> 00:21:21.720
with the hackers. So we're not seeing script kitties yet
417
00:21:21.839 --> 00:21:24.400
able to take these patches and reverse them as far
418
00:21:24.400 --> 00:21:25.680
as I can tell, yeah.
419
00:21:25.519 --> 00:21:26.839
Not yet, give it a week.
420
00:21:27.000 --> 00:21:30.799
But people what people who could do it or we're
421
00:21:30.880 --> 00:21:32.440
close to being able to do it on their own,
422
00:21:32.480 --> 00:21:35.440
could certainly do it much can do it fast. There's
423
00:21:35.440 --> 00:21:36.519
not a lot of those people.
424
00:21:36.599 --> 00:21:38.759
No, you're right, well, and you kind of hit the
425
00:21:39.319 --> 00:21:41.759
nail on the head there, Patrick. We're noticing, especially in
426
00:21:41.880 --> 00:21:44.319
the where we are in AI right now, which may
427
00:21:44.319 --> 00:21:47.559
be different by the time this podcast drops, but where
428
00:21:47.599 --> 00:21:50.759
we are right now, experts in the field can leverage
429
00:21:50.759 --> 00:21:56.160
AI to do amazing and great things faster, and entry
430
00:21:56.200 --> 00:21:58.480
level people in the field are using AI to do
431
00:21:58.559 --> 00:22:01.039
a whole lot of nothing faster. Right So we're seeing
432
00:22:01.160 --> 00:22:03.200
you know, if you don't if you're not if you
433
00:22:03.240 --> 00:22:05.720
don't understand code, AI is not going to write you
434
00:22:05.799 --> 00:22:08.279
amazing code. Yeah right, and you don't know enough to
435
00:22:08.440 --> 00:22:12.319
know it's not great. Right, But as a senior developer
436
00:22:12.400 --> 00:22:15.200
like Carl right, he could ask an AI to do
437
00:22:15.240 --> 00:22:16.559
something and he can look at it and go, I
438
00:22:16.559 --> 00:22:18.240
tweak that, I tweak that, I tweaked that. But it
439
00:22:18.240 --> 00:22:20.119
did all this Scott work for me, right, and it's
440
00:22:20.119 --> 00:22:21.000
making it much better.
441
00:22:21.039 --> 00:22:25.240
So yeah, absolutely, Okay, So let's talk about phishing tool
442
00:22:25.319 --> 00:22:30.160
that uses smart redirects to bypass detection. All right, oh no,
443
00:22:30.440 --> 00:22:31.359
oh no.
444
00:22:31.519 --> 00:22:34.079
Well this is this is actually something that we're seeing
445
00:22:34.079 --> 00:22:38.319
at multiple levels. So in the lower level we're getting
446
00:22:38.319 --> 00:22:42.599
conditional logic and emails so that depending on what agent
447
00:22:42.960 --> 00:22:47.079
is used to read it, it displays the good link
448
00:22:47.160 --> 00:22:51.960
or the bad link. And so literally, if it's if
449
00:22:52.000 --> 00:22:55.279
it's the agent they expect the user to use, they'll
450
00:22:55.319 --> 00:22:58.119
display the bad link, so the user clicks on it
451
00:22:58.160 --> 00:23:00.240
to go to the bad place. But if they don't
452
00:23:00.279 --> 00:23:03.359
get that agent or they detect that it's a faked agent,
453
00:23:04.119 --> 00:23:06.599
it's the good link like Bank of America or whatever,
454
00:23:07.079 --> 00:23:10.279
and that way it doesn't get detected by the filters
455
00:23:10.640 --> 00:23:12.839
because they know that these filters are looking at and
456
00:23:12.839 --> 00:23:15.680
this is just a different level. It just goes down
457
00:23:15.759 --> 00:23:20.640
the campaigns of conditional logic in the email so that
458
00:23:20.720 --> 00:23:23.680
it looks at oh, well, if you're using this user agent,
459
00:23:23.759 --> 00:23:26.200
let's let's show you this link, and if you're using
460
00:23:26.200 --> 00:23:28.319
that user agent, will use that link. And so they're
461
00:23:28.319 --> 00:23:32.480
trying to not get caught by yeah the ais basically.
462
00:23:32.279 --> 00:23:35.960
Yeah, I love the photo in this article. It's a
463
00:23:36.119 --> 00:23:39.039
close up of a fish hook with a line around it,
464
00:23:39.119 --> 00:23:41.960
sitting on top of the enter key on a keyboard.
465
00:23:42.599 --> 00:23:45.559
Yeah, first off, as a person who's fished quite a bit,
466
00:23:45.640 --> 00:23:49.920
what kind of crappy knot is totally not even honestly
467
00:23:50.279 --> 00:23:50.599
on now.
468
00:23:50.680 --> 00:23:51.839
They just don't want to lose their hook.
469
00:23:52.119 --> 00:23:54.559
And and what is he using twine on that? It
470
00:23:54.599 --> 00:23:57.759
looks like you should be fishing line, But you know whatever,
471
00:23:57.880 --> 00:23:58.319
it's fine.
472
00:23:58.359 --> 00:24:01.359
It does look like a big hook. It's not something
473
00:24:01.359 --> 00:24:02.599
you're going to get a perch with.
474
00:24:02.880 --> 00:24:05.279
You wouldn't catch a bass with that. You could catch
475
00:24:05.319 --> 00:24:12.519
an information workers. Fine, you put some twine hook and
476
00:24:12.559 --> 00:24:14.400
catch you.
477
00:24:17.720 --> 00:24:21.720
So we've seen these types of tactics though used before
478
00:24:21.839 --> 00:24:25.720
for malware. So in this particular case, if somebody clicks
479
00:24:25.720 --> 00:24:27.880
on a link, could they go to a page? Also,
480
00:24:28.079 --> 00:24:32.079
if it detects that it is a scanner, it doesn't redirect,
481
00:24:32.119 --> 00:24:34.279
It just leaves the page where it is. If it
482
00:24:34.319 --> 00:24:37.359
detects it's a user, then it actually will redirect them
483
00:24:37.400 --> 00:24:39.000
in a couple of seconds to a new page. And
484
00:24:39.039 --> 00:24:41.000
the way it's detecting that is by mouse movement. There's
485
00:24:41.039 --> 00:24:44.039
all sorts of other things. We've seen this with malware
486
00:24:44.359 --> 00:24:46.319
where if you run a piece of malware, the first
487
00:24:46.400 --> 00:24:47.880
thing defender is going to do is put it in
488
00:24:47.920 --> 00:24:50.039
the cloud and it's going to try and sandbox it
489
00:24:50.079 --> 00:24:52.079
and see whether it's malicious or not before it allows
490
00:24:52.119 --> 00:24:54.640
it to run it on your on your computer. So
491
00:24:54.680 --> 00:24:59.000
we've seen malware detect the sandbox, look for APIs that
492
00:24:59.039 --> 00:25:01.599
would exist on a normal computer that aren't in the sandbox.
493
00:25:02.440 --> 00:25:05.839
Try and you know, sleep for four hours and wake
494
00:25:05.920 --> 00:25:08.240
up and do some things and realize if four hours
495
00:25:08.279 --> 00:25:13.200
haven't passed. The sandboxes accelerated time, do massive amounts of
496
00:25:13.240 --> 00:25:15.359
calculations that they know are going to take an hour
497
00:25:15.880 --> 00:25:21.000
before they deploy malware, but the sandbox speeds past that calculation,
498
00:25:21.200 --> 00:25:24.039
so go, okay, Well, the time hasn't changed, so I'm
499
00:25:24.079 --> 00:25:25.839
not going to execute. So there's a lot of really
500
00:25:25.839 --> 00:25:29.240
interesting tactics we've seen in the in the malware world
501
00:25:29.279 --> 00:25:31.839
that we're now seeing applied to to phishing, which is
502
00:25:31.920 --> 00:25:32.599
kind of interesting.
503
00:25:32.720 --> 00:25:35.359
So what I described was in the email itself, the
504
00:25:35.480 --> 00:25:39.440
HL email Dwayne's describing like at the I got them
505
00:25:39.480 --> 00:25:42.000
to click on the link, right, is it really a
506
00:25:42.079 --> 00:25:44.000
victim or is it somebody trying to see if it's
507
00:25:44.000 --> 00:25:46.039
safe so they can pass it to my victim. Yeah,
508
00:25:46.079 --> 00:25:49.559
and so we're moving up that chain, and so we
509
00:25:49.599 --> 00:25:51.599
should see we'll see this in more and more places.
510
00:25:52.039 --> 00:25:53.400
M M yeah, okay.
511
00:25:53.839 --> 00:25:56.559
Quantum route redirection thought I did like that.
512
00:25:56.960 --> 00:25:59.079
You know, the NSA had a tool called Quantum insert.
513
00:25:59.200 --> 00:26:01.440
Did you guys hear that? No, No, it was I
514
00:26:01.519 --> 00:26:05.480
think it was leaked with the Shadow Brokers drops. That's
515
00:26:05.519 --> 00:26:06.920
the whole Snowden deal.
516
00:26:07.039 --> 00:26:09.720
But it wasn't really quantum, just a just a cool name.
517
00:26:09.799 --> 00:26:12.440
No, No, it was actually so it was called quantum insert
518
00:26:12.440 --> 00:26:15.599
because the belief was you could never insert yourself into
519
00:26:15.640 --> 00:26:20.720
the key exchange in an SSL conversation. And what the
520
00:26:20.880 --> 00:26:23.920
NSA found is if you're fast enough, you can, so
521
00:26:23.920 --> 00:26:28.039
if you're sitting at the ISP that the user is using,
522
00:26:28.319 --> 00:26:31.039
you can insert yourself into encrypted comms.
523
00:26:31.039 --> 00:26:32.640
Is that why most of the hackers we know work
524
00:26:32.680 --> 00:26:34.799
for eyes probably?
525
00:26:35.200 --> 00:26:39.039
Heah, they're all telcos. Yeah. So anyways, yeah, no, needless
526
00:26:39.039 --> 00:26:41.680
to say, lots of people using quantum wrong, Patrick.
527
00:26:41.599 --> 00:26:46.319
All right, and here's the feature story. Hackers weaponize Windows
528
00:26:46.400 --> 00:26:51.200
hyper v to hide Linux VM and evade EDR detection.
529
00:26:51.599 --> 00:26:56.119
Ed R is what endpoint detection and response e ed R. Okay,
530
00:26:56.640 --> 00:26:59.839
so think like anti virus, but with teeth right. Antivirus
531
00:26:59.839 --> 00:27:05.559
just usually disables and executable quarantine or or will either
532
00:27:05.599 --> 00:27:08.079
through heuristics but generally just through pattern matching on the
533
00:27:08.119 --> 00:27:11.079
file will remove it. And EDER is a little bit
534
00:27:11.119 --> 00:27:13.519
more sophisticated. It will watch how that file is moving
535
00:27:13.519 --> 00:27:15.039
and hooking and that sort of stuff. But then it
536
00:27:15.039 --> 00:27:18.519
will also respond in that it can notify a knock,
537
00:27:18.599 --> 00:27:20.640
or it can send log data or whatever.
538
00:27:20.839 --> 00:27:24.559
I think of it as an anti virus is signature based,
539
00:27:24.599 --> 00:27:27.480
which you described, and an EDR is behavior based.
540
00:27:27.720 --> 00:27:29.640
Yeah. Yeah, that's a good way to think about it.
541
00:27:29.759 --> 00:27:31.319
Yeah, but I like the t thing.
542
00:27:31.200 --> 00:27:35.480
Too, So before you get into this, I have questions
543
00:27:35.480 --> 00:27:39.279
about hyper v on Windows and Linux because Windows has
544
00:27:39.319 --> 00:27:45.279
this Linux subsystem for Windows, right or Windows NL. Yeah yeah, yeah,
545
00:27:45.400 --> 00:27:47.480
Windows Subsystem for Linux. That's what it is.
546
00:27:47.599 --> 00:27:49.480
Do you hear how happy Dwayne is about that.
547
00:27:49.559 --> 00:27:52.680
I love wslh Yeah yeah yeah.
548
00:27:51.359 --> 00:27:56.519
So this is so that you can run Linux things
549
00:27:56.559 --> 00:27:59.160
like bash shells and other Linux commands on Windows, and
550
00:27:59.200 --> 00:28:01.359
it's a wonderful thing for hackers like Dwayne. But it's
551
00:28:01.359 --> 00:28:06.599
also I'm wondering what the relationship is between WSL and
552
00:28:06.680 --> 00:28:10.799
hyper V. So I went looking and I'll post a fact,
553
00:28:10.839 --> 00:28:15.119
a Microsoft fact about WSL, and in that they say
554
00:28:15.880 --> 00:28:20.960
WSL one doesn't use anything like hyper V, and WSL
555
00:28:21.000 --> 00:28:26.240
two uses the same kind of technology, but it doesn't
556
00:28:26.319 --> 00:28:29.839
require hyper V to be enabled. So I think what
557
00:28:29.920 --> 00:28:32.720
we're going to find out in this story, guys, and
558
00:28:32.880 --> 00:28:36.400
your think we've even talked about it before, is if
559
00:28:36.400 --> 00:28:39.200
you don't need hyper V, turn it off. Right.
560
00:28:39.240 --> 00:28:41.440
That's true of everything, But that's true of everything, right,
561
00:28:41.480 --> 00:28:43.519
But you know you're right hundred percent. Yeah, if you're
562
00:28:43.559 --> 00:28:45.599
not using hyper V, why is it on?
563
00:28:45.920 --> 00:28:46.039
Right?
564
00:28:46.160 --> 00:28:48.319
It's like my father used to say, shut that light off.
565
00:28:48.680 --> 00:28:51.839
Yeah, back then it used the lights used to cost more.
566
00:28:52.039 --> 00:28:53.119
Shut that candle off.
567
00:28:54.119 --> 00:29:00.640
But yeah, control program control panel, programs and applications and
568
00:29:00.680 --> 00:29:03.640
then turn Windows features on or off. Go there right now.
569
00:29:04.400 --> 00:29:07.359
And if you don't have any vms running on your machine,
570
00:29:07.440 --> 00:29:09.359
or you don't have any other reason to use hyper V,
571
00:29:10.839 --> 00:29:14.400
you know, I can think of if you're a zamorin developer,
572
00:29:14.640 --> 00:29:16.839
you know, yeah, you're gonna need it.
573
00:29:17.240 --> 00:29:22.000
Yeah, yeah, absolutely. Any of the Android vms would use it.
574
00:29:23.200 --> 00:29:26.079
You can download things for WSL that may use it,
575
00:29:26.279 --> 00:29:29.599
although generally not. Docker may use it. There's anytime you're
576
00:29:29.599 --> 00:29:32.279
doing virtualization, it may actually use some of the libraries
577
00:29:32.319 --> 00:29:37.079
inside of HYPERV to virtualize those processes. But in reality,
578
00:29:37.160 --> 00:29:39.440
if you're not doing any of the things we're talking about,
579
00:29:39.440 --> 00:29:42.200
you should shut it off. And by defaults it's on.
580
00:29:42.319 --> 00:29:44.839
This is a classic living off the land. Yeah, if
581
00:29:44.880 --> 00:29:47.400
you have hyper V turned on, Now, what's the odds
582
00:29:47.400 --> 00:29:50.079
that the hacker is going to have purchase to turn
583
00:29:50.200 --> 00:29:52.960
on hyper V. Well, then they have control of the
584
00:29:53.000 --> 00:29:55.920
system anyways, and they're using the hyper V to hide.
585
00:29:56.039 --> 00:29:58.000
They're doing it for persistence.
586
00:29:58.319 --> 00:30:01.759
Now you got ninety nine problems, Yeah, yeah, and hyper
587
00:30:01.839 --> 00:30:02.680
V A one.
588
00:30:04.599 --> 00:30:09.359
Hyper v's one get one and yeah, so in this
589
00:30:09.519 --> 00:30:11.519
in this case, like Dwayne one of the things that
590
00:30:11.559 --> 00:30:14.400
we try to achieve is persistence, which is you get
591
00:30:14.519 --> 00:30:16.559
in and you might get in on something that's not
592
00:30:16.640 --> 00:30:20.160
a stable, that doesn't survive reboots, and you're like, oh,
593
00:30:20.200 --> 00:30:22.079
they got hyper v installed, or if they don't have
594
00:30:22.119 --> 00:30:24.640
it enabled, maybe I will enable it, right if I
595
00:30:24.680 --> 00:30:26.160
have that kind of permission.
596
00:30:25.960 --> 00:30:28.519
Yeah, yeah, And there's all sorts of other reasons why
597
00:30:28.519 --> 00:30:30.640
I might want to do that too. By default, it
598
00:30:30.720 --> 00:30:34.519
is enabled, so that does allow me to avoid antivirus
599
00:30:34.519 --> 00:30:37.359
detection and dr detection. Right defender can't see what's inside
600
00:30:37.359 --> 00:30:42.240
of a uh Linux VM running, you know, on your
601
00:30:42.640 --> 00:30:46.519
Windows workstation. But the other thing is there's a lot
602
00:30:46.559 --> 00:30:48.240
of things I can't do as a hacker on a
603
00:30:48.279 --> 00:30:51.880
Windows box. So for example, if I want to redirect
604
00:30:51.920 --> 00:30:55.319
authentication from a server out to the internet to steal
605
00:30:55.319 --> 00:30:57.160
a HASH, I can't do that on a Windows box
606
00:30:57.519 --> 00:31:00.519
because the Windows computer is listening on that port innately.
607
00:31:01.119 --> 00:31:04.480
You can't shut it off. I can't. I can't say, oh, Windows,
608
00:31:04.559 --> 00:31:08.279
can you allow NTLM relay x to run on four
609
00:31:08.319 --> 00:31:10.000
four five just for a couple of minutes so I
610
00:31:10.000 --> 00:31:13.799
can steal credentials. Windows goes no, this is a privileged port.
611
00:31:14.039 --> 00:31:14.240
Right.
612
00:31:14.640 --> 00:31:19.039
Was that a backhand career criminal career advice that you
613
00:31:19.160 --> 00:31:19.759
just gave there?
614
00:31:19.880 --> 00:31:21.759
You know, I was, I was trying. I was trying
615
00:31:21.799 --> 00:31:24.559
to see if I could bypass the song. Apparently not.
616
00:31:24.799 --> 00:31:27.599
Apparently I got caught by this song ed R and
617
00:31:27.720 --> 00:31:29.119
it's it's gonna play.
618
00:31:29.960 --> 00:31:32.319
So is it a good idea then too? If you
619
00:31:32.359 --> 00:31:34.079
don't know if you need it or not, just turn
620
00:31:34.160 --> 00:31:36.400
it off and then go about your business. And if
621
00:31:36.400 --> 00:31:39.559
something complains, yeah, absolutely that you need hyper V, then
622
00:31:39.599 --> 00:31:40.319
you turn it back on.
623
00:31:40.519 --> 00:31:40.680
Yep.
624
00:31:40.880 --> 00:31:44.200
Absolutely, there's no downside to turning it off. And then
625
00:31:44.200 --> 00:31:46.920
if you if you like you're you're absolutely right, Carl,
626
00:31:47.039 --> 00:31:49.160
Like you're a zamorin developer and you jump into the
627
00:31:49.160 --> 00:31:51.440
tool set and you fire up, you know, an application
628
00:31:51.480 --> 00:31:53.119
and you're looking to do some testing on you know
629
00:31:53.160 --> 00:31:56.480
whatever mobile platform and it doesn't spin up. You know,
630
00:31:56.519 --> 00:31:58.519
heads up, you probably need to turn hyper V back on.
631
00:31:58.920 --> 00:32:00.880
Well, it'll probably tell you will you know this? Ye,
632
00:32:01.000 --> 00:32:02.400
this feature requires hyper.
633
00:32:02.240 --> 00:32:05.680
V yep, And honestly I will tell you this. There's
634
00:32:05.759 --> 00:32:09.319
no downside to shutting it off. Afterwards, just when you're
635
00:32:09.319 --> 00:32:11.640
in done development, shut it off. I know most people
636
00:32:11.680 --> 00:32:15.799
probably won't, but you know less surface of attack is better.
637
00:32:15.640 --> 00:32:17.759
All right, So now let's talk about the attack itself.
638
00:32:18.079 --> 00:32:21.319
Yeah, so the attack itself, I mean, luckily in this
639
00:32:21.319 --> 00:32:23.400
early comrade curR of Comra.
640
00:32:23.119 --> 00:32:25.759
The three stooges of attacks here.
641
00:32:27.160 --> 00:32:31.799
Yeah, so the attack itself. If you're not where was it?
642
00:32:31.880 --> 00:32:33.839
I know there's a list in here. If you're not
643
00:32:34.359 --> 00:32:38.920
Georgia or Moldova, you're probably okay, this is where these are.
644
00:32:38.960 --> 00:32:42.759
Now the initial targets were Yeah, ok so it's interesting
645
00:32:42.839 --> 00:32:45.680
to see. It's interesting to see these types of tactics,
646
00:32:46.480 --> 00:32:48.680
but for the most part they're very, very targeted.
647
00:32:48.759 --> 00:32:50.839
Is just to clarify that Georgia you mean, is not
648
00:32:50.880 --> 00:32:54.519
where Atlanta sits. It's the one between the Caspian and
649
00:32:54.559 --> 00:32:56.240
Black Seas up by Russia.
650
00:32:56.319 --> 00:32:59.480
So one the Beatles sang about it back in the Usso.
651
00:32:59.359 --> 00:33:04.920
Wait, they weren't singing where Stalin's from? Stalin's hometown Stalin.
652
00:33:05.079 --> 00:33:06.400
You know that guy, Mike.
653
00:33:06.359 --> 00:33:09.680
Tie was Stalin When I was in Boston the other day, Patrick.
654
00:33:12.720 --> 00:33:18.680
Stalin on that note, Yeah, keep trying, you might get
655
00:33:18.680 --> 00:33:22.160
your crown back. Keep trying, all right, I'm working on it.
656
00:33:25.079 --> 00:33:26.880
So sorry, tom So.
657
00:33:27.039 --> 00:33:29.680
The reason I said curly comrades is. That's the name
658
00:33:29.880 --> 00:33:31.799
that has been given to the threat actor because of
659
00:33:31.839 --> 00:33:36.119
where they're operating. They're operating in former Soviet states. Moldava
660
00:33:36.160 --> 00:33:38.039
and Georgia are both former Soviet states.
661
00:33:38.279 --> 00:33:41.400
So they enable the hyper v roll on a selected
662
00:33:41.519 --> 00:33:46.799
Victims system to deploy a minimalistic Alpine Linux based virtual
663
00:33:46.880 --> 00:33:50.720
machine and from there they they have control.
664
00:33:50.839 --> 00:33:52.079
Right, Yes, it's very small.
665
00:33:52.319 --> 00:33:53.839
Yeah, they have curly shell.
666
00:33:53.920 --> 00:33:56.440
Yeah, and they get they can get a reverse shell. Yeah,
667
00:33:56.440 --> 00:33:58.599
that curly shell is a reverse shell. So I can
668
00:33:58.799 --> 00:34:00.960
command control, I can control the PC, I can be
669
00:34:00.960 --> 00:34:03.359
on the network, I can do whatever. I avoid endpoint
670
00:34:03.400 --> 00:34:07.799
detection unless you had a firewall inspecting traffic on the
671
00:34:07.839 --> 00:34:11.320
way out of the network. And even then those are
672
00:34:11.360 --> 00:34:13.360
those are bypassable in a lot of ways as well.
673
00:34:13.440 --> 00:34:15.679
So yeah, it's once it's in there, it's hard. You
674
00:34:15.679 --> 00:34:18.039
would notice you're missing hopefully you'd notice you're missing some
675
00:34:18.159 --> 00:34:21.480
resources on your computer. It's just not that much memory.
676
00:34:21.519 --> 00:34:24.159
But it's it's not that much. A couple hundred meg
677
00:34:24.199 --> 00:34:25.000
I think is what they said.
678
00:34:25.039 --> 00:34:27.239
It's two hundred and fifty six Mega ram.
679
00:34:27.320 --> 00:34:29.800
Is this a physical hack? Did that? Did the hackers
680
00:34:29.840 --> 00:34:32.400
have to get control of the machine to install this thing.
681
00:34:32.679 --> 00:34:35.760
Nah, you can just this can this could have been
682
00:34:35.800 --> 00:34:38.800
a fishing okay, you know attack where they send uh,
683
00:34:39.360 --> 00:34:41.920
you know, a best buyer receipt that's in an ISO,
684
00:34:42.039 --> 00:34:44.719
that's in a password protected ZIP that you need to
685
00:34:44.760 --> 00:34:46.239
open up and then run an MSI.
686
00:34:46.480 --> 00:34:48.519
I mean, I imagine if you if you ran a
687
00:34:48.519 --> 00:34:50.880
PowerShell set of commands, you could set this all up.
688
00:34:51.440 --> 00:34:53.119
You could yep, yep.
689
00:34:53.440 --> 00:34:55.800
The hardest part would probably be getting them to download
690
00:34:55.840 --> 00:35:01.239
the the the VM, but it's probably it's tiny one
691
00:35:01.559 --> 00:35:02.239
and twenty megs.
692
00:35:02.400 --> 00:35:04.280
Yeah, and even that's not that hard.
693
00:35:05.000 --> 00:35:07.239
And also they don't have best Buy in the Soviet
694
00:35:07.320 --> 00:35:11.000
in former Soviet states, so probably not going to see
695
00:35:11.079 --> 00:35:14.119
best Buy in Georgia or best Buy them, although the
696
00:35:14.519 --> 00:35:17.480
you don't thinks, although I know, what do I know?
697
00:35:19.400 --> 00:35:21.119
Do they have Worst Buy?
698
00:35:21.559 --> 00:35:23.480
Is that that's in Germany?
699
00:35:23.559 --> 00:35:26.519
All right? Never mind anything that I just said in
700
00:35:26.559 --> 00:35:27.679
the last five minutes.
701
00:35:27.719 --> 00:35:32.559
It was just stupid, so needy.
702
00:35:34.400 --> 00:35:36.599
I think we are And on that stupid note, I
703
00:35:36.599 --> 00:35:38.320
think we're done. Is there anything else you want to
704
00:35:38.320 --> 00:35:40.519
say about this other than it's probably not going to
705
00:35:40.559 --> 00:35:43.480
apply to you, but it's a good idea to disable
706
00:35:43.519 --> 00:35:44.559
things that aren't in use.
707
00:35:44.719 --> 00:35:48.360
Well, so I'd say I agree with you, Carl. I
708
00:35:48.400 --> 00:35:50.679
think a lot of people don't think about what we
709
00:35:50.760 --> 00:35:53.599
call surface of attack. The more things you have on
710
00:35:53.760 --> 00:35:57.719
and open, the more vulnerable you are. That's just fact. Yeah,
711
00:35:57.800 --> 00:35:59.760
So if you can turn something off you're not using,
712
00:36:00.199 --> 00:36:02.960
you should. And this is one example of why that matters.
713
00:36:03.039 --> 00:36:05.599
Rather than just the STW guys saying turn off for
714
00:36:05.599 --> 00:36:08.920
everything you're not using, right, and we become the you know,
715
00:36:08.960 --> 00:36:11.639
the town crier who cries wolf. This is an example
716
00:36:11.679 --> 00:36:15.960
of if you left it on, you could be exploited
717
00:36:16.000 --> 00:36:17.480
by this particular.
718
00:36:17.159 --> 00:36:22.039
There's a historical story here about that everybody used to
719
00:36:22.159 --> 00:36:28.679
use Internet information server. Iis on Windows server. Dwayne's lighting up.
720
00:36:28.760 --> 00:36:30.880
He's like, oh, it's so full of.
721
00:36:30.880 --> 00:36:34.000
Holes, love, iis. Oh my god. There used to be
722
00:36:34.039 --> 00:36:37.679
an index server tumor index server came with is There
723
00:36:37.760 --> 00:36:40.000
used to be an index server exploit that was so
724
00:36:40.039 --> 00:36:42.320
simple two hundred and fifty a's at the end of
725
00:36:42.360 --> 00:36:45.760
any URL and it popped the stack and then you
726
00:36:45.800 --> 00:36:49.039
could just run code directly on any is server. It's awesome.
727
00:36:49.159 --> 00:36:52.360
So the story is no JS came along and it
728
00:36:52.440 --> 00:36:56.280
had one function, Web server, right, iis. On the other
729
00:36:56.519 --> 00:36:59.199
this Dwayne was just saying, was like a Swiss army
730
00:36:59.239 --> 00:37:02.440
knife with all the blame. It's out by default, and
731
00:37:02.519 --> 00:37:04.840
so now you have to go and turn things off.
732
00:37:04.920 --> 00:37:09.440
But the Microsoft quickly realize, hey, we should be off
733
00:37:09.519 --> 00:37:12.199
by default, and if you want things, you turn them on.
734
00:37:12.400 --> 00:37:15.239
And so that's been the mantra ever since then.
735
00:37:15.599 --> 00:37:18.920
Yeah, Carl, I actually love that. I love that analogy.
736
00:37:19.000 --> 00:37:21.559
It's a Swiss army knife with all the blades out
737
00:37:21.599 --> 00:37:25.199
and just thinking about the danger of somebody running.
738
00:37:24.960 --> 00:37:26.880
And someone threw it at you with like all of
739
00:37:26.920 --> 00:37:27.920
the blades out.
740
00:37:27.960 --> 00:37:30.480
Like I can't take credit for that. That's Richard Campbell.
741
00:37:30.599 --> 00:37:32.280
He came up with it.
742
00:37:32.519 --> 00:37:35.760
That's awesome, Richard. Nice job. Yeah, nice job.
743
00:37:36.760 --> 00:37:40.239
Okay, we will see you next week on Security this
744
00:37:40.320 --> 00:37:41.559
week next week.
745
00:37:42.360 --> 00:37:54.559
Bye.
1
00:00:00.200 --> 00:00:03.960
I told you guys, I started running, right, No? Yeah, yeah,
2
00:00:03.960 --> 00:00:05.440
I told you last week I was running.
3
00:00:05.480 --> 00:00:07.280
You did, Yeah, last week you said you were running?
4
00:00:07.320 --> 00:00:08.599
Yeah? Remember I got hit with the Mayo?
5
00:00:08.880 --> 00:00:09.480
Yeah?
6
00:00:09.480 --> 00:00:10.759
What the hell? Man? Right?
7
00:00:10.880 --> 00:00:11.759
That was okay?
8
00:00:11.839 --> 00:00:12.880
Yeah that was last week.
9
00:00:12.960 --> 00:00:16.160
That was last week. Yeah. Yeah. So what I didn't
10
00:00:16.199 --> 00:00:18.480
tell you is my mother started running when she was
11
00:00:18.519 --> 00:00:19.199
seventy five.
12
00:00:19.440 --> 00:00:20.440
Wow, good for her.
13
00:00:20.519 --> 00:00:22.480
Yeah, she's eighty nine. Now we don't know where the
14
00:00:22.519 --> 00:00:23.120
hell she is.
15
00:00:24.320 --> 00:00:27.640
She just keeps keiths on going.
16
00:00:34.759 --> 00:00:38.640
All right, so we got six stories today. We're going
17
00:00:38.719 --> 00:00:42.399
to start with what I think is the most awesome story,
18
00:00:42.600 --> 00:00:45.759
and not in a Dwayne sense and then literal sense.
19
00:00:46.439 --> 00:00:51.640
Massive data breach at known SEC exposes China's state sponsored
20
00:00:51.679 --> 00:00:56.600
hacking tools and global targets. The hackers have been hacked.
21
00:00:56.799 --> 00:01:00.960
Oh no, this is the inversion of Equation Groups. So
22
00:01:01.000 --> 00:01:03.079
back when we first started the podcast, there was a
23
00:01:03.119 --> 00:01:07.760
hack against an organization called Equation Group that supposedly revealed
24
00:01:07.799 --> 00:01:10.359
a whole bunch of tools that the NSA had been using. Yeah,
25
00:01:10.400 --> 00:01:13.680
and this is the Chinese version of that. Basically, yeah,
26
00:01:13.760 --> 00:01:16.359
I agree, this is this is I have schadenfreude.
27
00:01:16.560 --> 00:01:19.319
I serious shotenfreuda.
28
00:01:19.799 --> 00:01:22.879
So what are the ramifications here, Like they're a legit
29
00:01:23.040 --> 00:01:27.799
company and legit country I guess you could say in
30
00:01:27.840 --> 00:01:28.719
an actual country.
31
00:01:28.840 --> 00:01:31.760
Yeah, but it basically China has tipped their hands. So
32
00:01:31.840 --> 00:01:35.000
now we're seeing more about how they're The Chinese opsect
33
00:01:35.000 --> 00:01:38.040
has been violated, their operational security has been bad.
34
00:01:38.280 --> 00:01:42.040
Yeah, state sponsored hacking tools and global surveillance targets have
35
00:01:42.159 --> 00:01:46.159
been uncovered. So basically, now we know what they do
36
00:01:46.439 --> 00:01:49.680
and the tools that they use to hack what, you know,
37
00:01:49.959 --> 00:01:50.879
all the rest of the world.
38
00:01:51.000 --> 00:01:53.359
It's a snapshot into what they're using right now.
39
00:01:53.560 --> 00:01:57.200
I guess for me, I'm not surprised. This was like, oh,
40
00:01:57.239 --> 00:01:59.519
by the way, like if the ozone goes away, we'll
41
00:01:59.519 --> 00:02:01.920
all get cut. Like I'm like, yeah, okay, cool, I've
42
00:02:01.920 --> 00:02:05.239
seen this forever. This makes sense, right, that they're state
43
00:02:05.319 --> 00:02:09.400
sponsored Chinese hackers that are legit companies. So yeah, I
44
00:02:09.400 --> 00:02:11.800
don't know. I wasn't surprised, but yes, but.
45
00:02:11.879 --> 00:02:15.680
You don't have a little delight in the misery of
46
00:02:15.840 --> 00:02:18.840
these of the China state sponsored hacks. I have.
47
00:02:19.240 --> 00:02:20.159
I always have delight.
48
00:02:21.080 --> 00:02:24.680
Yeah, Okay, so you have shadenfreude like Patrick and I do.
49
00:02:25.159 --> 00:02:27.879
Yes, yes, yeah, yes.
50
00:02:27.840 --> 00:02:30.159
Well, and it also kind of diffuses the idea that
51
00:02:30.280 --> 00:02:34.800
you know, they're they're super men. I don't think China
52
00:02:34.840 --> 00:02:37.759
has volume. They have mass, they have a lot of people,
53
00:02:38.199 --> 00:02:42.400
but I think that they're probably at the level of
54
00:02:42.439 --> 00:02:46.199
the NSA roughly because of that mass, but not because
55
00:02:46.199 --> 00:02:47.840
of quality. So I think the US st leads in
56
00:02:47.919 --> 00:02:50.360
quality and the Chinese quantity.
57
00:02:50.560 --> 00:02:52.719
And as we said before, there's a difference between China
58
00:02:52.759 --> 00:02:54.240
and Russia, right.
59
00:02:54.439 --> 00:02:55.599
It's about a thousand miles.
60
00:02:55.759 --> 00:02:59.680
Yeah, I know, but okay to che I thought I
61
00:02:59.800 --> 00:03:00.960
was joke maker here.
62
00:03:02.479 --> 00:03:03.960
Well, based on that one, you still are.
63
00:03:04.080 --> 00:03:08.360
All right. So, but China's Internet has grown up from
64
00:03:08.360 --> 00:03:13.759
the very beginning to be state controlled right right, whereas
65
00:03:13.840 --> 00:03:17.800
Russia was open for a while and then they started
66
00:03:17.800 --> 00:03:20.319
plugging the holes or trying to plug the holes, and
67
00:03:20.719 --> 00:03:23.560
you know, so there you go. So we have more
68
00:03:23.599 --> 00:03:27.080
to fear from China and their use of the Internet
69
00:03:27.120 --> 00:03:31.639
against nation states than we do Russia. I think, Yeah, I.
70
00:03:31.560 --> 00:03:34.400
Think the argument or maybe there's just I could I know,
71
00:03:34.479 --> 00:03:35.639
I buy that. I buy that.
72
00:03:35.680 --> 00:03:37.919
I think maybe there's just not as many holes in
73
00:03:38.199 --> 00:03:41.400
China's armor as there are in Russia's. Maybe that's it.
74
00:03:41.479 --> 00:03:44.520
Well, and I think Russia is pretty open about the
75
00:03:44.520 --> 00:03:47.919
fact that like, oh yeah, absolutely, we use third party
76
00:03:48.240 --> 00:03:52.080
you know, brought teams to create all of these cyber
77
00:03:52.159 --> 00:03:54.479
weapons and just let them release them as long as
78
00:03:54.479 --> 00:03:55.680
they're not on Russian So well.
79
00:03:55.639 --> 00:03:57.840
Yeah, yeah, as long as I don't use a Russian keyboard.
80
00:03:57.800 --> 00:04:01.159
Where is that? Whereas most other nations go, oh my god,
81
00:04:01.199 --> 00:04:03.360
that's terrible, we'd never do that, and then they do
82
00:04:03.400 --> 00:04:04.159
it in secret.
83
00:04:05.360 --> 00:04:07.879
I wonder if you loaded a Russian keyboard in whether
84
00:04:07.879 --> 00:04:09.599
you'd get a little extra protection.
85
00:04:10.840 --> 00:04:13.800
Sometimes. Yes, actually, that's a great that's a great point.
86
00:04:14.000 --> 00:04:18.360
There was a version of ransomware that would detect either
87
00:04:18.519 --> 00:04:22.040
a your time zone or b whether you were using
88
00:04:22.160 --> 00:04:25.600
a cyrillic keyboard, and if you were, it would just
89
00:04:25.639 --> 00:04:26.399
disarm itself.
90
00:04:26.560 --> 00:04:26.839
Wow.
91
00:04:27.120 --> 00:04:30.439
Yeah. So so there have been known cases of them
92
00:04:30.519 --> 00:04:33.480
going oh are bad, sorry we infected you and just ditching.
93
00:04:33.639 --> 00:04:35.839
Excuse me, mister Putin, I didn't know it was you.
94
00:04:35.959 --> 00:04:42.759
Yeah, all right, so smart good news. We've talked about
95
00:04:42.759 --> 00:04:47.319
pone to own before, which is a great gathering of
96
00:04:47.360 --> 00:04:51.480
people who try to hack things and find bugs, right,
97
00:04:52.240 --> 00:04:55.519
and so this story is from Bleeping Computer. Q NAP
98
00:04:55.600 --> 00:05:00.560
fixes seven NASS zero day flaws exploited at to own
99
00:05:00.839 --> 00:05:01.319
fairy good.
100
00:05:01.519 --> 00:05:03.720
So I like this. Yeah, I mean we've seen that,
101
00:05:03.720 --> 00:05:05.680
We've talked about pone to own this, like the the
102
00:05:05.720 --> 00:05:10.120
nerd super Bowl for for hackers. I actually really I
103
00:05:10.680 --> 00:05:13.439
find it cool. I actually watched the stream and popcorn
104
00:05:13.519 --> 00:05:15.720
and wow, like, wooe here on the teams?
105
00:05:18.079 --> 00:05:19.920
Is that on? I think that conflicts with the World
106
00:05:20.040 --> 00:05:21.360
Grass Growing Championships.
107
00:05:23.759 --> 00:05:25.600
You're like, I'm sorry, I'm out, I'm out.
108
00:05:25.759 --> 00:05:27.920
Is that the Mayo chucking Contest?
109
00:05:29.959 --> 00:05:32.720
Yeah? That's uh. I don't know what what channel of
110
00:05:32.800 --> 00:05:36.079
TV that would be on ESPN X Games Maybe No,
111
00:05:36.240 --> 00:05:39.199
I don't think so. No, it's actually it's really cool
112
00:05:39.240 --> 00:05:42.639
to see, Uh, these types of devices that obviously, like
113
00:05:42.680 --> 00:05:46.759
a q NAP is more geared towards home users or
114
00:05:46.839 --> 00:05:51.399
either that or small really small medium businesses. Right, So
115
00:05:52.279 --> 00:05:54.759
generally the people who are implementing these devices don't have
116
00:05:55.319 --> 00:05:57.839
millions of dollars to put towards cybersecurity or have their
117
00:05:57.839 --> 00:06:00.879
own cybersecurity team. Some of them wouldn't even have their
118
00:06:00.879 --> 00:06:05.199
own technical folks in house, right, They'd either have a
119
00:06:05.279 --> 00:06:07.560
hired team or they'd have a nephew that they'd torture
120
00:06:07.639 --> 00:06:12.759
and have come fixed prints. Nice niece couldn't be open absolutely,
121
00:06:13.560 --> 00:06:15.199
so in this case, I mean, I think it's great
122
00:06:15.199 --> 00:06:18.680
that that you see pon to own, not just focusing
123
00:06:18.720 --> 00:06:21.199
on like, oh, let's take a look at the you know,
124
00:06:21.439 --> 00:06:25.879
brand new CMC like whatever. Right, it's nice that you
125
00:06:25.879 --> 00:06:27.600
look at those, and it's important and it's a big
126
00:06:27.639 --> 00:06:29.439
surface of attack. But I love it when they focus
127
00:06:29.480 --> 00:06:31.560
on really kind of more of the home user stuff.
128
00:06:32.160 --> 00:06:34.959
Net app doesn't need their help. They have their own budgets.
129
00:06:35.079 --> 00:06:36.800
No, they have. I mean they have enough money they
130
00:06:36.800 --> 00:06:39.920
can spend, right, and even Tesla, like I get it,
131
00:06:39.720 --> 00:06:43.360
it affects the population. But and somebody who buys the
132
00:06:43.399 --> 00:06:45.160
Tesla is not obviously going to tear it apart to
133
00:06:45.160 --> 00:06:48.600
see if there's vulnerabilities. But let's be clear, Tesla has
134
00:06:48.680 --> 00:06:52.439
enough money to pay for vulnerabilities right to be checked
135
00:06:52.600 --> 00:06:55.600
and so whatever. But yeah, no, I actually really like
136
00:06:55.639 --> 00:06:57.680
Bono's It's a great competition.
137
00:06:57.759 --> 00:06:58.000
Cool.
138
00:06:58.040 --> 00:07:02.879
So they as we said, they have these vulnerabilities, and
139
00:07:02.920 --> 00:07:07.000
they weren't. It wasn't like somebody got into their system
140
00:07:07.120 --> 00:07:10.879
and implanted malware or something like that or spyware. They
141
00:07:10.879 --> 00:07:12.519
were just vulnerabilities. Yeah.
142
00:07:12.560 --> 00:07:17.480
Yeah, and everything has vulnerabilities. Let's not get all high
143
00:07:17.480 --> 00:07:20.360
and mighty. There's no Yeah, there's no software. There's no
144
00:07:20.439 --> 00:07:22.879
component that you're using that doesn't have a vulnerability that
145
00:07:22.959 --> 00:07:26.800
may never get discovered or might not get discovered, you know,
146
00:07:26.959 --> 00:07:29.959
till next year or next next decade. Many of the
147
00:07:30.040 --> 00:07:33.759
vulnerabilities that we know about, and there are tens of
148
00:07:33.839 --> 00:07:36.920
thousands of them, were there a long time before they
149
00:07:36.959 --> 00:07:37.519
were discovered.
150
00:07:37.560 --> 00:07:40.160
All right. Yeah, and now I'll tell you there was
151
00:07:40.199 --> 00:07:42.800
a new patch just this week released by a major
152
00:07:42.879 --> 00:07:47.759
firewall vendor, and we happened to have a couple free seconds,
153
00:07:47.759 --> 00:07:50.639
so we downloaded the binaries for the firmware, took a
154
00:07:50.639 --> 00:07:52.959
look at it, and there's three vulnerabilities in the new
155
00:07:52.959 --> 00:07:55.839
piece of suftware. So wow, and it just came out
156
00:07:55.839 --> 00:07:59.560
this week, so you know what. Yeah, absolutely, and these
157
00:07:59.600 --> 00:08:01.279
these people no security.
158
00:08:00.920 --> 00:08:02.680
So we just got to keep on top of it,
159
00:08:02.720 --> 00:08:03.519
that's all right.
160
00:08:03.639 --> 00:08:07.959
Yeah, it's never going to be over. Yeah, it's over
161
00:08:08.040 --> 00:08:11.000
when you know, when Skynet really does go online soon.
162
00:08:11.360 --> 00:08:15.279
Other than that, as long as there's people to be
163
00:08:15.399 --> 00:08:17.480
exploiting these things, they're going to get.
164
00:08:17.319 --> 00:08:22.319
Exploited, all right. So this one had me go patch NPM, right,
165
00:08:22.360 --> 00:08:28.240
away critical NPM library flaw, risks AI and NLP apps
166
00:08:28.519 --> 00:08:33.360
urgent patch urged, urgent patch, urged.
167
00:08:33.240 --> 00:08:34.440
Urgent, urged.
168
00:08:34.519 --> 00:08:36.840
It's a lot of urging to prevent. We can't urge
169
00:08:36.879 --> 00:08:41.240
it enough to prevent RCE remote control execution. So, for
170
00:08:41.279 --> 00:08:45.000
those who don't know, NPM is like new Get for JavaScript,
171
00:08:45.120 --> 00:08:47.440
and you probably know what MPM is. It's a very
172
00:08:47.559 --> 00:08:51.639
very popular package management tool for JavaScript packages.
173
00:08:51.879 --> 00:08:53.480
Yeah, but an RC is nothing else.
174
00:08:53.519 --> 00:08:56.600
Sneeze at no remote control execution is a serious thing.
175
00:08:57.039 --> 00:08:59.159
Yeah. So the issue here is the library they're talking
176
00:08:59.159 --> 00:09:02.080
about has a part sure out to valuate method that
177
00:09:02.159 --> 00:09:07.679
lets attackers actually inject objects through the context argument not
178
00:09:07.799 --> 00:09:12.879
good passed to their to that parameter enable, enabling obviously
179
00:09:13.080 --> 00:09:15.200
a remote code execution, which is you know, I always
180
00:09:15.240 --> 00:09:18.960
find awesome when you can just randomly take an object
181
00:09:19.039 --> 00:09:20.919
you want and toss it in a parameter and oh,
182
00:09:20.919 --> 00:09:24.159
by the way, I get a prompt somewhere, so it's
183
00:09:24.240 --> 00:09:26.399
it's kind of cool. But in this, you know, according
184
00:09:26.440 --> 00:09:28.679
to this article is a CV twenty twenty five one
185
00:09:28.759 --> 00:09:31.360
two seven three five. A significant security flaw has been
186
00:09:31.399 --> 00:09:37.440
identified widely utilized Java script library e xpr EVL as
187
00:09:37.480 --> 00:09:40.720
well as UH which is a natural language processing application.
188
00:09:40.799 --> 00:09:43.600
So yeah, it's in. It's an interesting flaw, and I
189
00:09:43.600 --> 00:09:45.919
think a lot of a lot of developers don't. This
190
00:09:46.000 --> 00:09:48.360
is a good point to just point out, like a
191
00:09:48.360 --> 00:09:51.200
lot of developers aren't security developers, Right, those are two
192
00:09:51.279 --> 00:09:58.840
very different things, Right, one exists and one doesn't. Ait
193
00:09:58.879 --> 00:10:01.240
a second, maybe Patrick is the jokes drew on here
194
00:10:02.080 --> 00:10:03.840
sadly give up.
195
00:10:05.399 --> 00:10:06.080
Today.
196
00:10:07.240 --> 00:10:09.919
Yeah, it's but it's it's Unfortunately a lot of times
197
00:10:10.120 --> 00:10:12.279
I see will like when we're doing a pen test
198
00:10:12.320 --> 00:10:15.679
web application pen test or even a static applications standalone
199
00:10:15.679 --> 00:10:19.679
application pen test. You know, we'll deliver our report and
200
00:10:19.720 --> 00:10:21.799
they will be like, oh, there's thirty five you know,
201
00:10:21.960 --> 00:10:25.720
critical remote code execution bugs blah blah blah whatever. Right,
202
00:10:26.440 --> 00:10:28.759
and we get to that conversation with the company and
203
00:10:28.759 --> 00:10:32.000
the company's always like our developers just terrible. But they're
204
00:10:32.039 --> 00:10:34.840
just horrible. We're like, no, they actually, you know, they
205
00:10:34.840 --> 00:10:37.000
have an application. It works really well, it does, it's
206
00:10:37.039 --> 00:10:41.200
what it's supposed to do. They just don't. Developers aren't
207
00:10:41.279 --> 00:10:45.360
classically trained in cybersecurity. They don't know what they're looking for. Right.
208
00:10:46.120 --> 00:10:48.799
And we've even had some customers that you know, the
209
00:10:48.919 --> 00:10:51.320
same issues show up over and over and over again.
210
00:10:51.720 --> 00:10:54.320
And even there, it's like they haven't been trained what
211
00:10:54.639 --> 00:10:58.840
not to do right, to look for this pattern. So yeah,
212
00:10:58.879 --> 00:11:03.399
it's even even you may have fantastic developers and that's great,
213
00:11:03.720 --> 00:11:06.080
but if they're not trained to look for these patterns. Yeah,
214
00:11:06.120 --> 00:11:08.000
you know, I always liking it too. You're looking for
215
00:11:08.039 --> 00:11:10.440
something that's not there. It's not like you're looking through
216
00:11:10.440 --> 00:11:12.320
code and looking for a bug and it has that
217
00:11:12.399 --> 00:11:14.679
red squiggly and you go, of course, this is your bug.
218
00:11:15.039 --> 00:11:18.039
You're actually looking for the logic that you didn't implement
219
00:11:18.120 --> 00:11:20.240
that you should have that would have protected you. And
220
00:11:20.279 --> 00:11:21.440
that's a lot harder to find.
221
00:11:21.559 --> 00:11:22.879
So you have to know how to read code and
222
00:11:22.960 --> 00:11:25.919
understand what a programmer is doing and then notice that
223
00:11:25.960 --> 00:11:26.799
they're doing.
224
00:11:26.879 --> 00:11:29.759
Well, you have to understand how it could be abused. Yes,
225
00:11:30.000 --> 00:11:32.519
and that's a different thought process. That's not even it
226
00:11:32.559 --> 00:11:36.279
is the same as And then there's levels to it. Yes,
227
00:11:36.320 --> 00:11:38.759
there's total different levels to it. So you know this
228
00:11:38.919 --> 00:11:41.840
data code analysis, which is like, oh, well, this is
229
00:11:41.879 --> 00:11:45.720
a common mistake, and then there as well, the person's
230
00:11:45.759 --> 00:11:47.120
going to take the thing and use it in a
231
00:11:47.159 --> 00:11:50.360
way that was never intended and is in most people's
232
00:11:50.360 --> 00:11:54.399
cases not imagined. Yes, and it may might not even
233
00:11:54.720 --> 00:11:57.080
be Well you might go, well, you can't do anything
234
00:11:57.159 --> 00:11:59.120
with that. No, you can't do anything with that, but
235
00:11:59.159 --> 00:12:01.200
it's a stepping stone. I'm going to change seven of
236
00:12:01.240 --> 00:12:04.960
these little things together, and with them I can do something.
237
00:12:05.080 --> 00:12:05.360
Yeah.
238
00:12:05.480 --> 00:12:09.240
Yeah. We've definitely seen a chain of attack where it's like, well,
239
00:12:09.279 --> 00:12:12.000
I have no privilege, but I can, I can, I can,
240
00:12:12.240 --> 00:12:14.360
I can see which tokens are in use, and you're like, well,
241
00:12:14.360 --> 00:12:16.559
who cares? Right, It's like, okay, but if I couple
242
00:12:16.639 --> 00:12:20.759
that with this particular attack or this email where somebody
243
00:12:20.799 --> 00:12:22.759
clicks on a link or whatever, right, and now you're
244
00:12:22.919 --> 00:12:26.039
you're you're chaining those together, and we definitely see the
245
00:12:26.120 --> 00:12:28.279
chained attacks are very hard to find in the static
246
00:12:28.279 --> 00:12:31.120
code analysis. So even in dynamic code analysis, you need
247
00:12:31.120 --> 00:12:32.039
to know what you're looking for.
248
00:12:32.120 --> 00:12:35.360
Even AI is going to have trouble Yeah that stuff, yeah, yep,
249
00:12:35.799 --> 00:12:37.559
until you tell it about it, and then it goes,
250
00:12:37.600 --> 00:12:40.039
oh my god, you're right, right.
251
00:12:40.240 --> 00:12:43.879
I'm not going to fix it, but it's right, you're right, right, Yeah,
252
00:12:43.919 --> 00:12:46.759
I'm not going to change it to be real, right.
253
00:12:47.000 --> 00:12:47.639
But you're right.
254
00:12:47.960 --> 00:12:51.879
Think about the TV show Mcgiver Love All the situation
255
00:12:52.000 --> 00:12:56.039
mcgiver mcgroover is also good, but Mcgiver's really much more effective.
256
00:12:56.279 --> 00:12:58.759
Guver's way better. Richard Dean Anderson.
257
00:12:58.360 --> 00:13:02.519
Mcgiver was an engineer. Here is an engineer version of
258
00:13:02.600 --> 00:13:03.360
Magnum p I.
259
00:13:03.480 --> 00:13:05.639
Right, yes, yes, mcg was awesome.
260
00:13:05.759 --> 00:13:09.440
So if you you mcgiver found himself in a hangar
261
00:13:09.759 --> 00:13:12.639
and or some you know, or a machine shop or
262
00:13:12.919 --> 00:13:15.600
a chemistry lab or something like that, and the bad
263
00:13:15.600 --> 00:13:17.519
guy said, oh, we got them, we got them locked up.
264
00:13:17.519 --> 00:13:21.000
He can't go anywhere, not realizing he's gonna take these things,
265
00:13:21.039 --> 00:13:25.720
make some hydrogen, you know, magnesium off.
266
00:13:25.600 --> 00:13:30.600
Of em glue and a rubber band and C for J.
267
00:13:31.279 --> 00:13:34.480
Is kind of the way most people think about hacks.
268
00:13:34.519 --> 00:13:37.080
Oh so there's a vulnerability, and I can give it
269
00:13:37.159 --> 00:13:39.600
something and I can abuse its interface and I can
270
00:13:39.679 --> 00:13:42.720
make it through something even that wasn't obvious to the
271
00:13:42.759 --> 00:13:43.399
average user.
272
00:13:43.879 --> 00:13:47.240
Right, But then wait to give you an analogy of that,
273
00:13:47.279 --> 00:13:49.360
Patrick log for J was like, oh, so you're saying
274
00:13:49.399 --> 00:13:51.919
I can pick up this handgun and I can shoot
275
00:13:51.919 --> 00:13:54.440
somebody with it. That's cool. We never even thought about,
276
00:13:54.480 --> 00:13:56.840
like yeah, exactly.
277
00:13:59.320 --> 00:14:02.279
And then but we get to manipulation and the next level,
278
00:14:03.000 --> 00:14:06.919
we're in a very different world that the average developer
279
00:14:07.320 --> 00:14:09.480
can't be. If you try to train developers to do that,
280
00:14:10.840 --> 00:14:14.200
you're probably going to break the developers. Yeah, and so
281
00:14:14.519 --> 00:14:17.919
we're stuck in this world of even security companies companies
282
00:14:18.039 --> 00:14:21.840
whose job is security. They're developers, aren't security experts. They're
283
00:14:21.879 --> 00:14:25.879
aware of security, and their code gets checked more often.
284
00:14:26.240 --> 00:14:28.639
That's the reason that you're less likely to get a
285
00:14:28.679 --> 00:14:32.600
security company's code. But that doesn't mean they're invulnerable to vulnerabilities.
286
00:14:33.039 --> 00:14:36.159
And then there's also so we're all old enough to remember,
287
00:14:36.279 --> 00:14:38.639
I'm outing us on age. We're old enough to remember
288
00:14:38.879 --> 00:14:41.360
before there was a sequel injection, before there was a
289
00:14:41.440 --> 00:14:45.440
concept called sequel injection. I remember all the code in
290
00:14:45.519 --> 00:14:47.720
the world written at that time it was vulnerable to
291
00:14:47.720 --> 00:14:50.840
sequel injection. Yeah, because no one knew that was a thing, right,
292
00:14:50.919 --> 00:14:53.360
No one invented it, right, No one had invented it yet.
293
00:14:53.279 --> 00:14:54.919
Until Rainforest Puppy came out with it.
294
00:14:55.000 --> 00:14:57.559
I remember seeing at a tech at a Microsoft guy
295
00:14:57.720 --> 00:15:02.080
introduced SQL injection the the first time, and like twenty
296
00:15:02.080 --> 00:15:04.240
people just got up and ran out of it exactly.
297
00:15:04.399 --> 00:15:06.399
I've had that I remember doing that.
298
00:15:06.399 --> 00:15:06.879
That was fun.
299
00:15:06.960 --> 00:15:12.000
Yeah, but we have the same kinds of vulnerabilities someday
300
00:15:12.039 --> 00:15:13.840
that we'll find out. And like, I can't believe people
301
00:15:13.879 --> 00:15:16.279
use variables. I mean, Christ, you know what.
302
00:15:17.799 --> 00:15:22.000
So to get back to this NPM thing, yeah, sorry, yeah,
303
00:15:22.080 --> 00:15:25.759
So they don't have a score listed in this article.
304
00:15:25.799 --> 00:15:27.000
I think this one goes to eleven.
305
00:15:27.120 --> 00:15:30.159
But I would say if it says urgent patch urged,
306
00:15:30.879 --> 00:15:36.600
I'm thinking that it's eleven, maybe go patch. So do
307
00:15:36.679 --> 00:15:39.799
you need to just update your version of NPM or
308
00:15:39.879 --> 00:15:45.000
if you're using this library expression evaluator expert evail, is
309
00:15:45.039 --> 00:15:47.840
that the thing you should also update that if there's
310
00:15:47.840 --> 00:15:48.600
a new patch or what.
311
00:15:48.759 --> 00:15:51.240
Here's what I would tell you, go update everything that's
312
00:15:51.320 --> 00:15:55.720
that's there and m the visual studio that's running like whatever. Like,
313
00:15:55.759 --> 00:15:58.519
if there's an update, go update everything. However, if you
314
00:15:58.519 --> 00:16:01.799
you just specifically for some reason, let's say you're in
315
00:16:01.799 --> 00:16:03.960
a production environment and there's change control and blah blah
316
00:16:03.960 --> 00:16:06.720
blah whatever, then you just want to update this library.
317
00:16:06.840 --> 00:16:10.799
Okay, all right, good with that. We'll take a little break.
318
00:16:10.960 --> 00:16:14.159
We'll be right back after these messages or no messages,
319
00:16:14.240 --> 00:16:17.759
as the case may be, but we'll be right back.
320
00:16:22.320 --> 00:16:25.200
All right, we're back. It's security this week. I'm Carl
321
00:16:25.240 --> 00:16:29.759
Franklin's Patrick Hines and Dwayne Laflotte. Hey guys, and we
322
00:16:29.879 --> 00:16:33.000
got a couple more stories to go through here. Microsoft
323
00:16:33.080 --> 00:16:37.120
patches actively exploited Windows kernel zero.
324
00:16:37.000 --> 00:16:39.120
Day Yeah, also known as Tuesday.
325
00:16:39.320 --> 00:16:43.039
So if it's actively exploited, is it a zero day?
326
00:16:43.919 --> 00:16:46.799
Yeah, only if it hasn't been patched, although this I
327
00:16:46.879 --> 00:16:48.679
believe by now has been patched.
328
00:16:48.840 --> 00:16:51.840
I mean, anybody, anybody who has a zero day and
329
00:16:51.919 --> 00:16:54.080
uses it for a year is actively exploiting it. It's
330
00:16:54.080 --> 00:16:56.399
just not publicly known, right, So it has nothing to
331
00:16:56.440 --> 00:16:58.159
do with the fact that whether it's exploited or not
332
00:16:58.759 --> 00:16:59.720
with whether it's been patched.
333
00:16:59.840 --> 00:17:03.799
So this ends up being one of the big issues here,
334
00:17:04.440 --> 00:17:10.680
is a privileged escalation with super duper level privileges, right,
335
00:17:10.920 --> 00:17:12.359
because we have kernel level issues.
336
00:17:12.359 --> 00:17:14.079
But I like technical term it is.
337
00:17:14.240 --> 00:17:17.960
But I absolutely love the last sentence, the last sentence
338
00:17:17.960 --> 00:17:23.359
of this article. Casually the article says, you know, so overall,
339
00:17:23.839 --> 00:17:26.920
more than thirty vulnerabilities fixed this month twenty two allow
340
00:17:27.000 --> 00:17:30.279
remote code execution and a bunch of other weaknesses like spoofing,
341
00:17:31.000 --> 00:17:35.160
denial of service, security, bypass information disclosure, you know, just
342
00:17:35.319 --> 00:17:37.480
back just kind of day like.
343
00:17:37.519 --> 00:17:40.559
How much good news though? Because they fixed them?
344
00:17:41.119 --> 00:17:45.000
Right, But how is it in today's day? Like ten
345
00:17:45.119 --> 00:17:47.519
years ago if you had an article that listed out
346
00:17:48.039 --> 00:17:51.599
fifty plus vulnerabilities and a piece of software, like people
347
00:17:51.640 --> 00:17:54.200
be like I'm never using this thing now We're like, yeah, whatever,
348
00:17:54.279 --> 00:17:57.400
it's a Tuesday, just go apply a pad Tuesday, and
349
00:17:57.799 --> 00:17:58.279
that's fine.
350
00:17:58.519 --> 00:18:01.640
It's a lot of products though, it's it's Asure monitor Agent,
351
00:18:01.799 --> 00:18:06.839
it's Dynamics third sixty five, it's office, it's one drive, SharePoint,
352
00:18:06.960 --> 00:18:11.559
Edge Office, some studio windows. It's a lot of different things.
353
00:18:11.599 --> 00:18:15.400
So yeah, okay, on average is probably one or two vulnerabilities.
354
00:18:15.400 --> 00:18:16.880
And again these are big products. Some of them have
355
00:18:16.960 --> 00:18:18.039
millions of lines of code.
356
00:18:18.440 --> 00:18:20.160
The good news is they found them and fix them.
357
00:18:20.160 --> 00:18:21.960
Oh yeah, yeah, absolutely it is.
358
00:18:22.240 --> 00:18:26.039
The bad news is that there's sixty opportunities because there's
359
00:18:26.039 --> 00:18:30.160
like sixty patches on this thing where one days can
360
00:18:30.200 --> 00:18:32.920
become a thing where where there's hackers out there racing
361
00:18:33.000 --> 00:18:36.079
to look at those those patches to figure out what
362
00:18:36.119 --> 00:18:38.240
they fixed and then go after the people who haven't
363
00:18:38.240 --> 00:18:41.880
patched yet. And so what's the lag? How long one
364
00:18:41.920 --> 00:18:44.240
of the questions our listeners should be listening to be
365
00:18:44.279 --> 00:18:47.319
thinking about, is what's the lag between a patch coming
366
00:18:47.319 --> 00:18:50.119
out and your company implementing it. If the answer is
367
00:18:50.119 --> 00:18:52.240
in months, you're screwed. If the answers in weeks, you
368
00:18:52.319 --> 00:18:53.319
might still be in trouble.
369
00:18:53.519 --> 00:18:56.039
Yep, it should be that day asap.
370
00:18:56.440 --> 00:18:59.920
I mean, yeah, absolutely, it's becoming more and more urgent.
371
00:19:00.440 --> 00:19:03.319
I mean it's becoming more and more like almost it's
372
00:19:03.359 --> 00:19:04.880
gonna have to be instantaneous by the end of the
373
00:19:04.880 --> 00:19:05.400
deck game, right.
374
00:19:05.440 --> 00:19:07.200
But I think a lot of people fall behind the
375
00:19:07.400 --> 00:19:12.319
you know, our standard operating procedure is we take a patch,
376
00:19:12.400 --> 00:19:14.839
we put it in the lab, we install the patch,
377
00:19:14.920 --> 00:19:17.920
We then run it through testing, we do full regression testing,
378
00:19:18.039 --> 00:19:21.039
then we roll it into you know QA, We then
379
00:19:21.119 --> 00:19:22.880
run it there, burn it in for a little bit,
380
00:19:22.880 --> 00:19:24.519
and then we put it in production right to make
381
00:19:24.559 --> 00:19:26.960
sure it's stable and working blow or whatever. I think
382
00:19:27.039 --> 00:19:30.599
the problem there is that Paradigm worked really well from
383
00:19:30.880 --> 00:19:34.680
nineteen ninety seven to about two thousand and three. Yeah, right,
384
00:19:34.799 --> 00:19:38.519
that was a perfect process of rollout. But we're not
385
00:19:38.599 --> 00:19:45.240
seeing BCDR plans actually updated for for nowadays. And you know, unless.
386
00:19:44.880 --> 00:19:47.240
Business continuity disaster recovery.
387
00:19:47.440 --> 00:19:50.039
Yeah, unless you're talking about you know, the people who
388
00:19:50.079 --> 00:19:53.480
have really gone deep into adopting like cloud and multiple
389
00:19:53.480 --> 00:19:56.640
cloud zones in replication and like where they're you know, listen,
390
00:19:56.680 --> 00:19:58.920
we're up all the time, like your Netflix and that
391
00:19:59.000 --> 00:20:01.240
sort of stuff. Like one issue is not going to
392
00:20:01.319 --> 00:20:04.880
drop Netflix. So yeah, it's I think we need to
393
00:20:04.960 --> 00:20:09.079
reevaluate how we handle patching and how we handle servers
394
00:20:09.079 --> 00:20:10.880
to make sure that they're up and running, but not
395
00:20:11.200 --> 00:20:11.880
the vulnerable.
396
00:20:12.079 --> 00:20:16.240
We talked about this before too, that AI bot nets
397
00:20:16.319 --> 00:20:23.559
or bots are now downloading these you know, updates notices,
398
00:20:23.920 --> 00:20:28.119
going and figuring them out and then immediately like deploying.
399
00:20:28.279 --> 00:20:32.279
That's the one day hacks against the Yeah, so that's
400
00:20:32.319 --> 00:20:36.240
one day. So it's not that you know, you're somebody
401
00:20:36.680 --> 00:20:41.119
in their office is going to get that stuff and
402
00:20:41.160 --> 00:20:43.400
then put something together and figure out how to hack
403
00:20:43.480 --> 00:20:45.920
and maybe a couple of days later you might be
404
00:20:46.000 --> 00:20:49.119
the unlucky recipient of that. Like the bots are out there.
405
00:20:48.960 --> 00:20:51.680
Now, oh yeah, well, but then they're being they're being
406
00:20:51.720 --> 00:20:54.480
driven by the people who used to do that by hand, right,
407
00:20:54.559 --> 00:20:57.279
you know, it's still not easy to get AI to
408
00:20:57.279 --> 00:21:00.680
do this kind of stuff. It's it sounds easy, sounds trivial,
409
00:21:00.920 --> 00:21:02.119
but it's not that easy.
410
00:21:02.400 --> 00:21:04.960
Just like us developers, you know, we're more productive using
411
00:21:05.000 --> 00:21:08.240
AI to help us do things, so they're the hackers
412
00:21:08.240 --> 00:21:11.000
are using it to be more productive to hack.
413
00:21:11.119 --> 00:21:13.200
They are, But but again the same thing. You can't
414
00:21:13.400 --> 00:21:15.720
take somebody who doesn't know how to program and say, oh,
415
00:21:15.759 --> 00:21:19.400
go and write clients are Yeah, the same is true
416
00:21:19.440 --> 00:21:21.720
with the hackers. So we're not seeing script kitties yet
417
00:21:21.839 --> 00:21:24.400
able to take these patches and reverse them as far
418
00:21:24.400 --> 00:21:25.680
as I can tell, yeah.
419
00:21:25.519 --> 00:21:26.839
Not yet, give it a week.
420
00:21:27.000 --> 00:21:30.799
But people what people who could do it or we're
421
00:21:30.880 --> 00:21:32.440
close to being able to do it on their own,
422
00:21:32.480 --> 00:21:35.440
could certainly do it much can do it fast. There's
423
00:21:35.440 --> 00:21:36.519
not a lot of those people.
424
00:21:36.599 --> 00:21:38.759
No, you're right, well, and you kind of hit the
425
00:21:39.319 --> 00:21:41.759
nail on the head there, Patrick. We're noticing, especially in
426
00:21:41.880 --> 00:21:44.319
the where we are in AI right now, which may
427
00:21:44.319 --> 00:21:47.559
be different by the time this podcast drops, but where
428
00:21:47.599 --> 00:21:50.759
we are right now, experts in the field can leverage
429
00:21:50.759 --> 00:21:56.160
AI to do amazing and great things faster, and entry
430
00:21:56.200 --> 00:21:58.480
level people in the field are using AI to do
431
00:21:58.559 --> 00:22:01.039
a whole lot of nothing faster. Right So we're seeing
432
00:22:01.160 --> 00:22:03.200
you know, if you don't if you're not if you
433
00:22:03.240 --> 00:22:05.720
don't understand code, AI is not going to write you
434
00:22:05.799 --> 00:22:08.279
amazing code. Yeah right, and you don't know enough to
435
00:22:08.440 --> 00:22:12.319
know it's not great. Right, But as a senior developer
436
00:22:12.400 --> 00:22:15.200
like Carl right, he could ask an AI to do
437
00:22:15.240 --> 00:22:16.559
something and he can look at it and go, I
438
00:22:16.559 --> 00:22:18.240
tweak that, I tweak that, I tweaked that. But it
439
00:22:18.240 --> 00:22:20.119
did all this Scott work for me, right, and it's
440
00:22:20.119 --> 00:22:21.000
making it much better.
441
00:22:21.039 --> 00:22:25.240
So yeah, absolutely, Okay, So let's talk about phishing tool
442
00:22:25.319 --> 00:22:30.160
that uses smart redirects to bypass detection. All right, oh no,
443
00:22:30.440 --> 00:22:31.359
oh no.
444
00:22:31.519 --> 00:22:34.079
Well this is this is actually something that we're seeing
445
00:22:34.079 --> 00:22:38.319
at multiple levels. So in the lower level we're getting
446
00:22:38.319 --> 00:22:42.599
conditional logic and emails so that depending on what agent
447
00:22:42.960 --> 00:22:47.079
is used to read it, it displays the good link
448
00:22:47.160 --> 00:22:51.960
or the bad link. And so literally, if it's if
449
00:22:52.000 --> 00:22:55.279
it's the agent they expect the user to use, they'll
450
00:22:55.319 --> 00:22:58.119
display the bad link, so the user clicks on it
451
00:22:58.160 --> 00:23:00.240
to go to the bad place. But if they don't
452
00:23:00.279 --> 00:23:03.359
get that agent or they detect that it's a faked agent,
453
00:23:04.119 --> 00:23:06.599
it's the good link like Bank of America or whatever,
454
00:23:07.079 --> 00:23:10.279
and that way it doesn't get detected by the filters
455
00:23:10.640 --> 00:23:12.839
because they know that these filters are looking at and
456
00:23:12.839 --> 00:23:15.680
this is just a different level. It just goes down
457
00:23:15.759 --> 00:23:20.640
the campaigns of conditional logic in the email so that
458
00:23:20.720 --> 00:23:23.680
it looks at oh, well, if you're using this user agent,
459
00:23:23.759 --> 00:23:26.200
let's let's show you this link, and if you're using
460
00:23:26.200 --> 00:23:28.319
that user agent, will use that link. And so they're
461
00:23:28.319 --> 00:23:32.480
trying to not get caught by yeah the ais basically.
462
00:23:32.279 --> 00:23:35.960
Yeah, I love the photo in this article. It's a
463
00:23:36.119 --> 00:23:39.039
close up of a fish hook with a line around it,
464
00:23:39.119 --> 00:23:41.960
sitting on top of the enter key on a keyboard.
465
00:23:42.599 --> 00:23:45.559
Yeah, first off, as a person who's fished quite a bit,
466
00:23:45.640 --> 00:23:49.920
what kind of crappy knot is totally not even honestly
467
00:23:50.279 --> 00:23:50.599
on now.
468
00:23:50.680 --> 00:23:51.839
They just don't want to lose their hook.
469
00:23:52.119 --> 00:23:54.559
And and what is he using twine on that? It
470
00:23:54.599 --> 00:23:57.759
looks like you should be fishing line, But you know whatever,
471
00:23:57.880 --> 00:23:58.319
it's fine.
472
00:23:58.359 --> 00:24:01.359
It does look like a big hook. It's not something
473
00:24:01.359 --> 00:24:02.599
you're going to get a perch with.
474
00:24:02.880 --> 00:24:05.279
You wouldn't catch a bass with that. You could catch
475
00:24:05.319 --> 00:24:12.519
an information workers. Fine, you put some twine hook and
476
00:24:12.559 --> 00:24:14.400
catch you.
477
00:24:17.720 --> 00:24:21.720
So we've seen these types of tactics though used before
478
00:24:21.839 --> 00:24:25.720
for malware. So in this particular case, if somebody clicks
479
00:24:25.720 --> 00:24:27.880
on a link, could they go to a page? Also,
480
00:24:28.079 --> 00:24:32.079
if it detects that it is a scanner, it doesn't redirect,
481
00:24:32.119 --> 00:24:34.279
It just leaves the page where it is. If it
482
00:24:34.319 --> 00:24:37.359
detects it's a user, then it actually will redirect them
483
00:24:37.400 --> 00:24:39.000
in a couple of seconds to a new page. And
484
00:24:39.039 --> 00:24:41.000
the way it's detecting that is by mouse movement. There's
485
00:24:41.039 --> 00:24:44.039
all sorts of other things. We've seen this with malware
486
00:24:44.359 --> 00:24:46.319
where if you run a piece of malware, the first
487
00:24:46.400 --> 00:24:47.880
thing defender is going to do is put it in
488
00:24:47.920 --> 00:24:50.039
the cloud and it's going to try and sandbox it
489
00:24:50.079 --> 00:24:52.079
and see whether it's malicious or not before it allows
490
00:24:52.119 --> 00:24:54.640
it to run it on your on your computer. So
491
00:24:54.680 --> 00:24:59.000
we've seen malware detect the sandbox, look for APIs that
492
00:24:59.039 --> 00:25:01.599
would exist on a normal computer that aren't in the sandbox.
493
00:25:02.440 --> 00:25:05.839
Try and you know, sleep for four hours and wake
494
00:25:05.920 --> 00:25:08.240
up and do some things and realize if four hours
495
00:25:08.279 --> 00:25:13.200
haven't passed. The sandboxes accelerated time, do massive amounts of
496
00:25:13.240 --> 00:25:15.359
calculations that they know are going to take an hour
497
00:25:15.880 --> 00:25:21.000
before they deploy malware, but the sandbox speeds past that calculation,
498
00:25:21.200 --> 00:25:24.039
so go, okay, Well, the time hasn't changed, so I'm
499
00:25:24.079 --> 00:25:25.839
not going to execute. So there's a lot of really
500
00:25:25.839 --> 00:25:29.240
interesting tactics we've seen in the in the malware world
501
00:25:29.279 --> 00:25:31.839
that we're now seeing applied to to phishing, which is
502
00:25:31.920 --> 00:25:32.599
kind of interesting.
503
00:25:32.720 --> 00:25:35.359
So what I described was in the email itself, the
504
00:25:35.480 --> 00:25:39.440
HL email Dwayne's describing like at the I got them
505
00:25:39.480 --> 00:25:42.000
to click on the link, right, is it really a
506
00:25:42.079 --> 00:25:44.000
victim or is it somebody trying to see if it's
507
00:25:44.000 --> 00:25:46.039
safe so they can pass it to my victim. Yeah,
508
00:25:46.079 --> 00:25:49.559
and so we're moving up that chain, and so we
509
00:25:49.599 --> 00:25:51.599
should see we'll see this in more and more places.
510
00:25:52.039 --> 00:25:53.400
M M yeah, okay.
511
00:25:53.839 --> 00:25:56.559
Quantum route redirection thought I did like that.
512
00:25:56.960 --> 00:25:59.079
You know, the NSA had a tool called Quantum insert.
513
00:25:59.200 --> 00:26:01.440
Did you guys hear that? No, No, it was I
514
00:26:01.519 --> 00:26:05.480
think it was leaked with the Shadow Brokers drops. That's
515
00:26:05.519 --> 00:26:06.920
the whole Snowden deal.
516
00:26:07.039 --> 00:26:09.720
But it wasn't really quantum, just a just a cool name.
517
00:26:09.799 --> 00:26:12.440
No, No, it was actually so it was called quantum insert
518
00:26:12.440 --> 00:26:15.599
because the belief was you could never insert yourself into
519
00:26:15.640 --> 00:26:20.720
the key exchange in an SSL conversation. And what the
520
00:26:20.880 --> 00:26:23.920
NSA found is if you're fast enough, you can, so
521
00:26:23.920 --> 00:26:28.039
if you're sitting at the ISP that the user is using,
522
00:26:28.319 --> 00:26:31.039
you can insert yourself into encrypted comms.
523
00:26:31.039 --> 00:26:32.640
Is that why most of the hackers we know work
524
00:26:32.680 --> 00:26:34.799
for eyes probably?
525
00:26:35.200 --> 00:26:39.039
Heah, they're all telcos. Yeah. So anyways, yeah, no, needless
526
00:26:39.039 --> 00:26:41.680
to say, lots of people using quantum wrong, Patrick.
527
00:26:41.599 --> 00:26:46.319
All right, and here's the feature story. Hackers weaponize Windows
528
00:26:46.400 --> 00:26:51.200
hyper v to hide Linux VM and evade EDR detection.
529
00:26:51.599 --> 00:26:56.119
Ed R is what endpoint detection and response e ed R. Okay,
530
00:26:56.640 --> 00:26:59.839
so think like anti virus, but with teeth right. Antivirus
531
00:26:59.839 --> 00:27:05.559
just usually disables and executable quarantine or or will either
532
00:27:05.599 --> 00:27:08.079
through heuristics but generally just through pattern matching on the
533
00:27:08.119 --> 00:27:11.079
file will remove it. And EDER is a little bit
534
00:27:11.119 --> 00:27:13.519
more sophisticated. It will watch how that file is moving
535
00:27:13.519 --> 00:27:15.039
and hooking and that sort of stuff. But then it
536
00:27:15.039 --> 00:27:18.519
will also respond in that it can notify a knock,
537
00:27:18.599 --> 00:27:20.640
or it can send log data or whatever.
538
00:27:20.839 --> 00:27:24.559
I think of it as an anti virus is signature based,
539
00:27:24.599 --> 00:27:27.480
which you described, and an EDR is behavior based.
540
00:27:27.720 --> 00:27:29.640
Yeah. Yeah, that's a good way to think about it.
541
00:27:29.759 --> 00:27:31.319
Yeah, but I like the t thing.
542
00:27:31.200 --> 00:27:35.480
Too, So before you get into this, I have questions
543
00:27:35.480 --> 00:27:39.279
about hyper v on Windows and Linux because Windows has
544
00:27:39.319 --> 00:27:45.279
this Linux subsystem for Windows, right or Windows NL. Yeah yeah, yeah,
545
00:27:45.400 --> 00:27:47.480
Windows Subsystem for Linux. That's what it is.
546
00:27:47.599 --> 00:27:49.480
Do you hear how happy Dwayne is about that.
547
00:27:49.559 --> 00:27:52.680
I love wslh Yeah yeah yeah.
548
00:27:51.359 --> 00:27:56.519
So this is so that you can run Linux things
549
00:27:56.559 --> 00:27:59.160
like bash shells and other Linux commands on Windows, and
550
00:27:59.200 --> 00:28:01.359
it's a wonderful thing for hackers like Dwayne. But it's
551
00:28:01.359 --> 00:28:06.599
also I'm wondering what the relationship is between WSL and
552
00:28:06.680 --> 00:28:10.799
hyper V. So I went looking and I'll post a fact,
553
00:28:10.839 --> 00:28:15.119
a Microsoft fact about WSL, and in that they say
554
00:28:15.880 --> 00:28:20.960
WSL one doesn't use anything like hyper V, and WSL
555
00:28:21.000 --> 00:28:26.240
two uses the same kind of technology, but it doesn't
556
00:28:26.319 --> 00:28:29.839
require hyper V to be enabled. So I think what
557
00:28:29.920 --> 00:28:32.720
we're going to find out in this story, guys, and
558
00:28:32.880 --> 00:28:36.400
your think we've even talked about it before, is if
559
00:28:36.400 --> 00:28:39.200
you don't need hyper V, turn it off. Right.
560
00:28:39.240 --> 00:28:41.440
That's true of everything, But that's true of everything, right,
561
00:28:41.480 --> 00:28:43.519
But you know you're right hundred percent. Yeah, if you're
562
00:28:43.559 --> 00:28:45.599
not using hyper V, why is it on?
563
00:28:45.920 --> 00:28:46.039
Right?
564
00:28:46.160 --> 00:28:48.319
It's like my father used to say, shut that light off.
565
00:28:48.680 --> 00:28:51.839
Yeah, back then it used the lights used to cost more.
566
00:28:52.039 --> 00:28:53.119
Shut that candle off.
567
00:28:54.119 --> 00:29:00.640
But yeah, control program control panel, programs and applications and
568
00:29:00.680 --> 00:29:03.640
then turn Windows features on or off. Go there right now.
569
00:29:04.400 --> 00:29:07.359
And if you don't have any vms running on your machine,
570
00:29:07.440 --> 00:29:09.359
or you don't have any other reason to use hyper V,
571
00:29:10.839 --> 00:29:14.400
you know, I can think of if you're a zamorin developer,
572
00:29:14.640 --> 00:29:16.839
you know, yeah, you're gonna need it.
573
00:29:17.240 --> 00:29:22.000
Yeah, yeah, absolutely. Any of the Android vms would use it.
574
00:29:23.200 --> 00:29:26.079
You can download things for WSL that may use it,
575
00:29:26.279 --> 00:29:29.599
although generally not. Docker may use it. There's anytime you're
576
00:29:29.599 --> 00:29:32.279
doing virtualization, it may actually use some of the libraries
577
00:29:32.319 --> 00:29:37.079
inside of HYPERV to virtualize those processes. But in reality,
578
00:29:37.160 --> 00:29:39.440
if you're not doing any of the things we're talking about,
579
00:29:39.440 --> 00:29:42.200
you should shut it off. And by defaults it's on.
580
00:29:42.319 --> 00:29:44.839
This is a classic living off the land. Yeah, if
581
00:29:44.880 --> 00:29:47.400
you have hyper V turned on, Now, what's the odds
582
00:29:47.400 --> 00:29:50.079
that the hacker is going to have purchase to turn
583
00:29:50.200 --> 00:29:52.960
on hyper V. Well, then they have control of the
584
00:29:53.000 --> 00:29:55.920
system anyways, and they're using the hyper V to hide.
585
00:29:56.039 --> 00:29:58.000
They're doing it for persistence.
586
00:29:58.319 --> 00:30:01.759
Now you got ninety nine problems, Yeah, yeah, and hyper
587
00:30:01.839 --> 00:30:02.680
V A one.
588
00:30:04.599 --> 00:30:09.359
Hyper v's one get one and yeah, so in this
589
00:30:09.519 --> 00:30:11.519
in this case, like Dwayne one of the things that
590
00:30:11.559 --> 00:30:14.400
we try to achieve is persistence, which is you get
591
00:30:14.519 --> 00:30:16.559
in and you might get in on something that's not
592
00:30:16.640 --> 00:30:20.160
a stable, that doesn't survive reboots, and you're like, oh,
593
00:30:20.200 --> 00:30:22.079
they got hyper v installed, or if they don't have
594
00:30:22.119 --> 00:30:24.640
it enabled, maybe I will enable it, right if I
595
00:30:24.680 --> 00:30:26.160
have that kind of permission.
596
00:30:25.960 --> 00:30:28.519
Yeah, yeah, And there's all sorts of other reasons why
597
00:30:28.519 --> 00:30:30.640
I might want to do that too. By default, it
598
00:30:30.720 --> 00:30:34.519
is enabled, so that does allow me to avoid antivirus
599
00:30:34.519 --> 00:30:37.359
detection and dr detection. Right defender can't see what's inside
600
00:30:37.359 --> 00:30:42.240
of a uh Linux VM running, you know, on your
601
00:30:42.640 --> 00:30:46.519
Windows workstation. But the other thing is there's a lot
602
00:30:46.559 --> 00:30:48.240
of things I can't do as a hacker on a
603
00:30:48.279 --> 00:30:51.880
Windows box. So for example, if I want to redirect
604
00:30:51.920 --> 00:30:55.319
authentication from a server out to the internet to steal
605
00:30:55.319 --> 00:30:57.160
a HASH, I can't do that on a Windows box
606
00:30:57.519 --> 00:31:00.519
because the Windows computer is listening on that port innately.
607
00:31:01.119 --> 00:31:04.480
You can't shut it off. I can't. I can't say, oh, Windows,
608
00:31:04.559 --> 00:31:08.279
can you allow NTLM relay x to run on four
609
00:31:08.319 --> 00:31:10.000
four five just for a couple of minutes so I
610
00:31:10.000 --> 00:31:13.799
can steal credentials. Windows goes no, this is a privileged port.
611
00:31:14.039 --> 00:31:14.240
Right.
612
00:31:14.640 --> 00:31:19.039
Was that a backhand career criminal career advice that you
613
00:31:19.160 --> 00:31:19.759
just gave there?
614
00:31:19.880 --> 00:31:21.759
You know, I was, I was trying. I was trying
615
00:31:21.799 --> 00:31:24.559
to see if I could bypass the song. Apparently not.
616
00:31:24.799 --> 00:31:27.599
Apparently I got caught by this song ed R and
617
00:31:27.720 --> 00:31:29.119
it's it's gonna play.
618
00:31:29.960 --> 00:31:32.319
So is it a good idea then too? If you
619
00:31:32.359 --> 00:31:34.079
don't know if you need it or not, just turn
620
00:31:34.160 --> 00:31:36.400
it off and then go about your business. And if
621
00:31:36.400 --> 00:31:39.559
something complains, yeah, absolutely that you need hyper V, then
622
00:31:39.599 --> 00:31:40.319
you turn it back on.
623
00:31:40.519 --> 00:31:40.680
Yep.
624
00:31:40.880 --> 00:31:44.200
Absolutely, there's no downside to turning it off. And then
625
00:31:44.200 --> 00:31:46.920
if you if you like you're you're absolutely right, Carl,
626
00:31:47.039 --> 00:31:49.160
Like you're a zamorin developer and you jump into the
627
00:31:49.160 --> 00:31:51.440
tool set and you fire up, you know, an application
628
00:31:51.480 --> 00:31:53.119
and you're looking to do some testing on you know
629
00:31:53.160 --> 00:31:56.480
whatever mobile platform and it doesn't spin up. You know,
630
00:31:56.519 --> 00:31:58.519
heads up, you probably need to turn hyper V back on.
631
00:31:58.920 --> 00:32:00.880
Well, it'll probably tell you will you know this? Ye,
632
00:32:01.000 --> 00:32:02.400
this feature requires hyper.
633
00:32:02.240 --> 00:32:05.680
V yep, And honestly I will tell you this. There's
634
00:32:05.759 --> 00:32:09.319
no downside to shutting it off. Afterwards, just when you're
635
00:32:09.319 --> 00:32:11.640
in done development, shut it off. I know most people
636
00:32:11.680 --> 00:32:15.799
probably won't, but you know less surface of attack is better.
637
00:32:15.640 --> 00:32:17.759
All right, So now let's talk about the attack itself.
638
00:32:18.079 --> 00:32:21.319
Yeah, so the attack itself, I mean, luckily in this
639
00:32:21.319 --> 00:32:23.400
early comrade curR of Comra.
640
00:32:23.119 --> 00:32:25.759
The three stooges of attacks here.
641
00:32:27.160 --> 00:32:31.799
Yeah, so the attack itself. If you're not where was it?
642
00:32:31.880 --> 00:32:33.839
I know there's a list in here. If you're not
643
00:32:34.359 --> 00:32:38.920
Georgia or Moldova, you're probably okay, this is where these are.
644
00:32:38.960 --> 00:32:42.759
Now the initial targets were Yeah, ok so it's interesting
645
00:32:42.839 --> 00:32:45.680
to see. It's interesting to see these types of tactics,
646
00:32:46.480 --> 00:32:48.680
but for the most part they're very, very targeted.
647
00:32:48.759 --> 00:32:50.839
Is just to clarify that Georgia you mean, is not
648
00:32:50.880 --> 00:32:54.519
where Atlanta sits. It's the one between the Caspian and
649
00:32:54.559 --> 00:32:56.240
Black Seas up by Russia.
650
00:32:56.319 --> 00:32:59.480
So one the Beatles sang about it back in the Usso.
651
00:32:59.359 --> 00:33:04.920
Wait, they weren't singing where Stalin's from? Stalin's hometown Stalin.
652
00:33:05.079 --> 00:33:06.400
You know that guy, Mike.
653
00:33:06.359 --> 00:33:09.680
Tie was Stalin When I was in Boston the other day, Patrick.
654
00:33:12.720 --> 00:33:18.680
Stalin on that note, Yeah, keep trying, you might get
655
00:33:18.680 --> 00:33:22.160
your crown back. Keep trying, all right, I'm working on it.
656
00:33:25.079 --> 00:33:26.880
So sorry, tom So.
657
00:33:27.039 --> 00:33:29.680
The reason I said curly comrades is. That's the name
658
00:33:29.880 --> 00:33:31.799
that has been given to the threat actor because of
659
00:33:31.839 --> 00:33:36.119
where they're operating. They're operating in former Soviet states. Moldava
660
00:33:36.160 --> 00:33:38.039
and Georgia are both former Soviet states.
661
00:33:38.279 --> 00:33:41.400
So they enable the hyper v roll on a selected
662
00:33:41.519 --> 00:33:46.799
Victims system to deploy a minimalistic Alpine Linux based virtual
663
00:33:46.880 --> 00:33:50.720
machine and from there they they have control.
664
00:33:50.839 --> 00:33:52.079
Right, Yes, it's very small.
665
00:33:52.319 --> 00:33:53.839
Yeah, they have curly shell.
666
00:33:53.920 --> 00:33:56.440
Yeah, and they get they can get a reverse shell. Yeah,
667
00:33:56.440 --> 00:33:58.599
that curly shell is a reverse shell. So I can
668
00:33:58.799 --> 00:34:00.960
command control, I can control the PC, I can be
669
00:34:00.960 --> 00:34:03.359
on the network, I can do whatever. I avoid endpoint
670
00:34:03.400 --> 00:34:07.799
detection unless you had a firewall inspecting traffic on the
671
00:34:07.839 --> 00:34:11.320
way out of the network. And even then those are
672
00:34:11.360 --> 00:34:13.360
those are bypassable in a lot of ways as well.
673
00:34:13.440 --> 00:34:15.679
So yeah, it's once it's in there, it's hard. You
674
00:34:15.679 --> 00:34:18.039
would notice you're missing hopefully you'd notice you're missing some
675
00:34:18.159 --> 00:34:21.480
resources on your computer. It's just not that much memory.
676
00:34:21.519 --> 00:34:24.159
But it's it's not that much. A couple hundred meg
677
00:34:24.199 --> 00:34:25.000
I think is what they said.
678
00:34:25.039 --> 00:34:27.239
It's two hundred and fifty six Mega ram.
679
00:34:27.320 --> 00:34:29.800
Is this a physical hack? Did that? Did the hackers
680
00:34:29.840 --> 00:34:32.400
have to get control of the machine to install this thing.
681
00:34:32.679 --> 00:34:35.760
Nah, you can just this can this could have been
682
00:34:35.800 --> 00:34:38.800
a fishing okay, you know attack where they send uh,
683
00:34:39.360 --> 00:34:41.920
you know, a best buyer receipt that's in an ISO,
684
00:34:42.039 --> 00:34:44.719
that's in a password protected ZIP that you need to
685
00:34:44.760 --> 00:34:46.239
open up and then run an MSI.
686
00:34:46.480 --> 00:34:48.519
I mean, I imagine if you if you ran a
687
00:34:48.519 --> 00:34:50.880
PowerShell set of commands, you could set this all up.
688
00:34:51.440 --> 00:34:53.119
You could yep, yep.
689
00:34:53.440 --> 00:34:55.800
The hardest part would probably be getting them to download
690
00:34:55.840 --> 00:35:01.239
the the the VM, but it's probably it's tiny one
691
00:35:01.559 --> 00:35:02.239
and twenty megs.
692
00:35:02.400 --> 00:35:04.280
Yeah, and even that's not that hard.
693
00:35:05.000 --> 00:35:07.239
And also they don't have best Buy in the Soviet
694
00:35:07.320 --> 00:35:11.000
in former Soviet states, so probably not going to see
695
00:35:11.079 --> 00:35:14.119
best Buy in Georgia or best Buy them, although the
696
00:35:14.519 --> 00:35:17.480
you don't thinks, although I know, what do I know?
697
00:35:19.400 --> 00:35:21.119
Do they have Worst Buy?
698
00:35:21.559 --> 00:35:23.480
Is that that's in Germany?
699
00:35:23.559 --> 00:35:26.519
All right? Never mind anything that I just said in
700
00:35:26.559 --> 00:35:27.679
the last five minutes.
701
00:35:27.719 --> 00:35:32.559
It was just stupid, so needy.
702
00:35:34.400 --> 00:35:36.599
I think we are And on that stupid note, I
703
00:35:36.599 --> 00:35:38.320
think we're done. Is there anything else you want to
704
00:35:38.320 --> 00:35:40.519
say about this other than it's probably not going to
705
00:35:40.559 --> 00:35:43.480
apply to you, but it's a good idea to disable
706
00:35:43.519 --> 00:35:44.559
things that aren't in use.
707
00:35:44.719 --> 00:35:48.360
Well, so I'd say I agree with you, Carl. I
708
00:35:48.400 --> 00:35:50.679
think a lot of people don't think about what we
709
00:35:50.760 --> 00:35:53.599
call surface of attack. The more things you have on
710
00:35:53.760 --> 00:35:57.719
and open, the more vulnerable you are. That's just fact. Yeah,
711
00:35:57.800 --> 00:35:59.760
So if you can turn something off you're not using,
712
00:36:00.199 --> 00:36:02.960
you should. And this is one example of why that matters.
713
00:36:03.039 --> 00:36:05.599
Rather than just the STW guys saying turn off for
714
00:36:05.599 --> 00:36:08.920
everything you're not using, right, and we become the you know,
715
00:36:08.960 --> 00:36:11.639
the town crier who cries wolf. This is an example
716
00:36:11.679 --> 00:36:15.960
of if you left it on, you could be exploited
717
00:36:16.000 --> 00:36:17.480
by this particular.
718
00:36:17.159 --> 00:36:22.039
There's a historical story here about that everybody used to
719
00:36:22.159 --> 00:36:28.679
use Internet information server. Iis on Windows server. Dwayne's lighting up.
720
00:36:28.760 --> 00:36:30.880
He's like, oh, it's so full of.
721
00:36:30.880 --> 00:36:34.000
Holes, love, iis. Oh my god. There used to be
722
00:36:34.039 --> 00:36:37.679
an index server tumor index server came with is There
723
00:36:37.760 --> 00:36:40.000
used to be an index server exploit that was so
724
00:36:40.039 --> 00:36:42.320
simple two hundred and fifty a's at the end of
725
00:36:42.360 --> 00:36:45.760
any URL and it popped the stack and then you
726
00:36:45.800 --> 00:36:49.039
could just run code directly on any is server. It's awesome.
727
00:36:49.159 --> 00:36:52.360
So the story is no JS came along and it
728
00:36:52.440 --> 00:36:56.280
had one function, Web server, right, iis. On the other
729
00:36:56.519 --> 00:36:59.199
this Dwayne was just saying, was like a Swiss army
730
00:36:59.239 --> 00:37:02.440
knife with all the blame. It's out by default, and
731
00:37:02.519 --> 00:37:04.840
so now you have to go and turn things off.
732
00:37:04.920 --> 00:37:09.440
But the Microsoft quickly realize, hey, we should be off
733
00:37:09.519 --> 00:37:12.199
by default, and if you want things, you turn them on.
734
00:37:12.400 --> 00:37:15.239
And so that's been the mantra ever since then.
735
00:37:15.599 --> 00:37:18.920
Yeah, Carl, I actually love that. I love that analogy.
736
00:37:19.000 --> 00:37:21.559
It's a Swiss army knife with all the blades out
737
00:37:21.599 --> 00:37:25.199
and just thinking about the danger of somebody running.
738
00:37:24.960 --> 00:37:26.880
And someone threw it at you with like all of
739
00:37:26.920 --> 00:37:27.920
the blades out.
740
00:37:27.960 --> 00:37:30.480
Like I can't take credit for that. That's Richard Campbell.
741
00:37:30.599 --> 00:37:32.280
He came up with it.
742
00:37:32.519 --> 00:37:35.760
That's awesome, Richard. Nice job. Yeah, nice job.
743
00:37:36.760 --> 00:37:40.239
Okay, we will see you next week on Security this
744
00:37:40.320 --> 00:37:41.559
week next week.
745
00:37:42.360 --> 00:37:54.559
Bye.