YouTube2Text

Malicious Updates - CompTIA Security+ SY0-701 - 2.3 — Transcript

by Professor Messer · 979 words · 154 segments · language en · Watch on YouTube

Full transcript

  1. 0:01you often hear myself and many other
  2. 0:04Security Professionals tell you to
  3. 0:05always keep your operating systems up to
  4. 0:07date make sure all of your applications
  5. 0:10have been patched and anytime a new set
  6. 0:12of updates comes through you should make
  7. 0:14sure that you patch your system as soon
  8. 0:15as possible this will make sure that
  9. 0:17you're able to avoid any type of
  10. 0:20vulnerabilities or security problems
  11. 0:22associated with this older code but of
  12. 0:24course when you're installing an
  13. 0:25application to a device there's always a
  14. 0:28concern that the application self might
  15. 0:30have malicious software inside of it and
  16. 0:32the same thing applies to these updates
  17. 0:35we're effectively installing a new
  18. 0:37application each time we install these
  19. 0:39updates and it may be possible for an
  20. 0:41attacker to find some way to get their
  21. 0:43malicious code embedded within the
  22. 0:46update itself and although we're telling
  23. 0:48you to update your system as quickly as
  24. 0:50possible when you find one of these
  25. 0:52security patches there are number of
  26. 0:54best practices that are associated with
  27. 0:56this update process first before you
  28. 0:58make any changes to any system you
  29. 1:01should have a backup this ensures that
  30. 1:03if something does go wrong during the
  31. 1:05update process you can revert back to
  32. 1:07the previous configuration and you'll be
  33. 1:09back up and running again you should
  34. 1:11also make sure that the sources that
  35. 1:13you're using for this update are trusted
  36. 1:16this means the software that you're
  37. 1:17using during this update is coming from
  38. 1:19a source that you commonly would use or
  39. 1:21one that is commonly associated with
  40. 1:24this update process and it's always
  41. 1:26worth mentioning again that your backup
  42. 1:28can solve a lot of problems for you if
  43. 1:30something does go wrong during the
  44. 1:32update process here's an example of a
  45. 1:35message that you might commonly see when
  46. 1:36an application needs to be updated this
  47. 1:38is for the Chrome browser and it says
  48. 1:40you're using an older version update now
  49. 1:43to keep your Chrome browser running
  50. 1:44smoothly and securely your download will
  51. 1:47begin automatically if not click here
  52. 1:49where it says update Chrome if this is a
  53. 1:51message that appears when you first
  54. 1:53start your browser before you visited
  55. 1:55any other websites then there is a
  56. 1:57reasonable amount of trust you can
  57. 1:58associate with this update message but
  58. 2:01what if this is a message that appears
  59. 2:02once you visit one of the links that's
  60. 2:04provided from a Google search there
  61. 2:07might be a question as to whether this
  62. 2:09particular update is legitimate and it
  63. 2:11may be something you want to perform a
  64. 2:13bit of extra checks before clicking that
  65. 2:15update Chrome button we're very often
  66. 2:18installing these updates from a file
  67. 2:20that has been downloaded from a
  68. 2:21thirdparty website so we need to look at
  69. 2:24where we're downloading this file from
  70. 2:26and we need to understand more about
  71. 2:28what might happen if we perform this
  72. 2:30update we should make sure that the
  73. 2:31source is one that is indeed trusted
  74. 2:34that we're going to a site that commonly
  75. 2:36hosts these types of patches if we're
  76. 2:38getting some random popup message during
  77. 2:40our normal web browsing session that
  78. 2:43tells us that we need to click here to
  79. 2:44update this might not be a legitimate
  80. 2:47update message and if you want to have a
  81. 2:49relatively high amount of trust
  82. 2:51regarding this particular patch you
  83. 2:53should download the update directly from
  84. 2:55the application developer site and many
  85. 2:57operating systems will only install
  86. 2:59install applications if they've been
  87. 3:01digitally signed that means that we'll
  88. 3:03get a message during the update process
  89. 3:05that tells us that this application is
  90. 3:07from Microsoft or adobe or Google and we
  91. 3:10can see the digital signature associated
  92. 3:13with that update because the digital
  93. 3:15signature is put there by the
  94. 3:16application developer and our operating
  95. 3:19system validates that digital signature
  96. 3:21we can have a high level of trust that
  97. 3:23this particular update is
  98. 3:25legitimate sometimes an application will
  99. 3:27have its own update process buil built
  100. 3:30into the app itself this usually does
  101. 3:32have Security checks and digital
  102. 3:34signatures built into this process and
  103. 3:36although you might not see the digital
  104. 3:38signature the update process of the
  105. 3:40application is automatically performing
  106. 3:42that verification this process has a
  107. 3:44high amount of trust because it's the
  108. 3:46application itself that is performing
  109. 3:48the update you don't have to download
  110. 3:50any files yourself and the update is
  111. 3:53being verified as coming from the
  112. 3:55manufacturer of the software however
  113. 3:58this process is not a 100% guarantee
  114. 4:01that the code that you're updating is
  115. 4:03indeed legitimate in December of 2020
  116. 4:06the company solar winds reported that
  117. 4:08their application Orion was performing
  118. 4:11updates for users but the update itself
  119. 4:14contained malicious software these
  120. 4:16updates followed the internal update
  121. 4:18process for the Orion application the
  122. 4:21update itself was digitally signed by
  123. 4:23the company and to anyone who's ever
  124. 4:25performed an update this looked like a
  125. 4:27normal update from a legitimate
  126. 4:29application developer unfortunately
  127. 4:31months earlier attackers had gained
  128. 4:33access to the development system in
  129. 4:36solar winds itself and put their own
  130. 4:38code into the solar wind software their
  131. 4:41malicious code was rolled up into the
  132. 4:43normal updates that were provided by
  133. 4:45other application developers within the
  134. 4:47company and the entire package was
  135. 4:50digitally signed and automatically
  136. 4:52distributed to their users this Orion
  137. 4:54software is high-end management software
  138. 4:57and some of the largest organizations in
  139. 4:59the world were running this software
  140. 5:02this allowed attackers to gain access to
  141. 5:04hundreds of large governmental agencies
  142. 5:06and companies and it allowed them to
  143. 5:09effectively have full rain to the entire
  144. 5:12system that was running this Orion
  145. 5:14software and from there they were able
  146. 5:16to jump from the Orion system to other
  147. 5:18unsecured systems within those
  148. 5:20organizations this type of attack is
  149. 5:22relatively rare but it does show that an
  150. 5:25attacker could use a trusted process to
  151. 5:28be able to automatically distribute
  152. 5:29their malicious code to hundreds or
  153. 5:32thousands of systems
  154. 5:43automatically

About this transcript

This page contains the full transcript of Malicious Updates - CompTIA Security+ SY0-701 - 2.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 979 words across 154 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.