Malicious Updates - CompTIA Security+ SY0-701 - 2.3 — Transcript
Full transcript
- 0:01you often hear myself and many other
- 0:04Security Professionals tell you to
- 0:05always keep your operating systems up to
- 0:07date make sure all of your applications
- 0:10have been patched and anytime a new set
- 0:12of updates comes through you should make
- 0:14sure that you patch your system as soon
- 0:15as possible this will make sure that
- 0:17you're able to avoid any type of
- 0:20vulnerabilities or security problems
- 0:22associated with this older code but of
- 0:24course when you're installing an
- 0:25application to a device there's always a
- 0:28concern that the application self might
- 0:30have malicious software inside of it and
- 0:32the same thing applies to these updates
- 0:35we're effectively installing a new
- 0:37application each time we install these
- 0:39updates and it may be possible for an
- 0:41attacker to find some way to get their
- 0:43malicious code embedded within the
- 0:46update itself and although we're telling
- 0:48you to update your system as quickly as
- 0:50possible when you find one of these
- 0:52security patches there are number of
- 0:54best practices that are associated with
- 0:56this update process first before you
- 0:58make any changes to any system you
- 1:01should have a backup this ensures that
- 1:03if something does go wrong during the
- 1:05update process you can revert back to
- 1:07the previous configuration and you'll be
- 1:09back up and running again you should
- 1:11also make sure that the sources that
- 1:13you're using for this update are trusted
- 1:16this means the software that you're
- 1:17using during this update is coming from
- 1:19a source that you commonly would use or
- 1:21one that is commonly associated with
- 1:24this update process and it's always
- 1:26worth mentioning again that your backup
- 1:28can solve a lot of problems for you if
- 1:30something does go wrong during the
- 1:32update process here's an example of a
- 1:35message that you might commonly see when
- 1:36an application needs to be updated this
- 1:38is for the Chrome browser and it says
- 1:40you're using an older version update now
- 1:43to keep your Chrome browser running
- 1:44smoothly and securely your download will
- 1:47begin automatically if not click here
- 1:49where it says update Chrome if this is a
- 1:51message that appears when you first
- 1:53start your browser before you visited
- 1:55any other websites then there is a
- 1:57reasonable amount of trust you can
- 1:58associate with this update message but
- 2:01what if this is a message that appears
- 2:02once you visit one of the links that's
- 2:04provided from a Google search there
- 2:07might be a question as to whether this
- 2:09particular update is legitimate and it
- 2:11may be something you want to perform a
- 2:13bit of extra checks before clicking that
- 2:15update Chrome button we're very often
- 2:18installing these updates from a file
- 2:20that has been downloaded from a
- 2:21thirdparty website so we need to look at
- 2:24where we're downloading this file from
- 2:26and we need to understand more about
- 2:28what might happen if we perform this
- 2:30update we should make sure that the
- 2:31source is one that is indeed trusted
- 2:34that we're going to a site that commonly
- 2:36hosts these types of patches if we're
- 2:38getting some random popup message during
- 2:40our normal web browsing session that
- 2:43tells us that we need to click here to
- 2:44update this might not be a legitimate
- 2:47update message and if you want to have a
- 2:49relatively high amount of trust
- 2:51regarding this particular patch you
- 2:53should download the update directly from
- 2:55the application developer site and many
- 2:57operating systems will only install
- 2:59install applications if they've been
- 3:01digitally signed that means that we'll
- 3:03get a message during the update process
- 3:05that tells us that this application is
- 3:07from Microsoft or adobe or Google and we
- 3:10can see the digital signature associated
- 3:13with that update because the digital
- 3:15signature is put there by the
- 3:16application developer and our operating
- 3:19system validates that digital signature
- 3:21we can have a high level of trust that
- 3:23this particular update is
- 3:25legitimate sometimes an application will
- 3:27have its own update process buil built
- 3:30into the app itself this usually does
- 3:32have Security checks and digital
- 3:34signatures built into this process and
- 3:36although you might not see the digital
- 3:38signature the update process of the
- 3:40application is automatically performing
- 3:42that verification this process has a
- 3:44high amount of trust because it's the
- 3:46application itself that is performing
- 3:48the update you don't have to download
- 3:50any files yourself and the update is
- 3:53being verified as coming from the
- 3:55manufacturer of the software however
- 3:58this process is not a 100% guarantee
- 4:01that the code that you're updating is
- 4:03indeed legitimate in December of 2020
- 4:06the company solar winds reported that
- 4:08their application Orion was performing
- 4:11updates for users but the update itself
- 4:14contained malicious software these
- 4:16updates followed the internal update
- 4:18process for the Orion application the
- 4:21update itself was digitally signed by
- 4:23the company and to anyone who's ever
- 4:25performed an update this looked like a
- 4:27normal update from a legitimate
- 4:29application developer unfortunately
- 4:31months earlier attackers had gained
- 4:33access to the development system in
- 4:36solar winds itself and put their own
- 4:38code into the solar wind software their
- 4:41malicious code was rolled up into the
- 4:43normal updates that were provided by
- 4:45other application developers within the
- 4:47company and the entire package was
- 4:50digitally signed and automatically
- 4:52distributed to their users this Orion
- 4:54software is high-end management software
- 4:57and some of the largest organizations in
- 4:59the world were running this software
- 5:02this allowed attackers to gain access to
- 5:04hundreds of large governmental agencies
- 5:06and companies and it allowed them to
- 5:09effectively have full rain to the entire
- 5:12system that was running this Orion
- 5:14software and from there they were able
- 5:16to jump from the Orion system to other
- 5:18unsecured systems within those
- 5:20organizations this type of attack is
- 5:22relatively rare but it does show that an
- 5:25attacker could use a trusted process to
- 5:28be able to automatically distribute
- 5:29their malicious code to hundreds or
- 5:32thousands of systems
- 5:43automatically
About this transcript
This page contains the full transcript of Malicious Updates - CompTIA Security+ SY0-701 - 2.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 979 words across 154 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.