meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, April 3rd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 3 April 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Twitter Cache Bug; MSSQL Server; Zoom Again; Covid19 Scams; Safari Camera Access Bug

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, April 3, 2020 edition of the Sansonet Storm Center.

0:06.8

Stormcast, my name is Johannes, Ulrich, and then I'm recording from Jacksonville, Florida.

0:12.9

Running complex web applications on shared devices has always been a little bit tricky because a lot of modern web applications are storing

0:23.5

data on the client in order to achieve a more seamless and more responsive user experience.

0:32.2

Well, Twitter was no exception and apparently they didn't quite understand how Firefox is dealing with this data.

0:40.5

Now, the application of course can also delete data itself or it can rely on the browser to do so.

0:48.1

Apparently Firefox is keeping data that the application stored within the browser for seven days.

0:56.8

And in Twitter's case, this data included, for example, private messages.

1:03.1

So no big deal really if you are the only user of the particular computer, but if you're

1:08.0

sharing this computer and other authorized user would be able to retrieve

1:13.7

these messages from the cache on the system. It's actually an issue that we talk about in our

1:19.4

defending web application class, in particular when it comes to local storage, sort of a JavaScript

1:24.5

API that's quite often used for this kind of storage.

1:30.6

But then again, I believe there are plenty of applications other than Twitter out there

1:35.0

that are storing too much data on the browser.

1:38.5

And it's probably a good idea to occasionally just clear out the data.

1:43.6

This is data that's stored in addition to cookies.

1:46.9

So this does not necessarily mean just cookies, but definitely includes cookies as well.

1:53.3

And if you were around 17 years ago, you may remember SQL Slammer, one of the big warms

1:59.8

that, well, attacked Microsoft SQL Server.

2:03.4

Sadly, I guess we haven't learned since then, and people still expose Microsoft SQL server

2:09.9

to the internet.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.