ISC StormCast for Friday, January 21st, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 January 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 21st, 2022 edition of the Sandsenet Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.4 | Good old FTP, the file transfer protocol, is, in my opinion, luckily, on its way out. And, well, browsers stopped supporting it. |
| 0:23.1 | With that, of course, there are not a lot of legitimate users |
| 0:27.1 | typically left for a user to use FTP. |
| 0:30.9 | So Xavier came across a Python script |
| 0:33.1 | that actually uses FTP to download Redline Steeler. |
| 0:37.6 | It does inject Redline Steeler into its own process, which is sort of interesting, but just |
| 0:43.6 | a good lesson here that you probably should watch out for FTP connections. |
| 0:48.4 | They are often these days malicious. |
| 0:51.1 | If they're not malicious, you probably should find a way to switch to a different |
| 0:56.6 | protocol. SEP sort of comes to mind maybe HTPs in order to avoid the problems that come with |
| 1:04.6 | the clear text FTP protocol. And German IT website, Heise, has an interesting article about how Google's camera implemented |
| 1:15.5 | in Android, does misread QR codes. |
| 1:19.5 | Now, this is interesting because, well, QR codes were specifically designed to be read |
| 1:24.5 | automatically and have some error correction built in to actually be readable, |
| 1:30.5 | even if the QR code isn't displayed very well, but I guess that wasn't good enough for Google, |
| 1:36.6 | so Google sent its machine learning algorithms after the URLs that are being extracted, |
| 1:43.3 | and apparently certain URLs are misread as a result. |
| 1:49.3 | In particular, Google does appear to insert random dots. |
| 1:54.0 | For example, if the top-level domain is a country-level domain, but the domain name includes like the string com or |
| 2:03.6 | a CEO, it may add a dot com dot and then the respective country level domain because I guess it feels |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

