4.9 • 696 Ratings
🗓️ 16 July 2021
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, July 16th, 2021 edition of the Sands and it storms and as |
0:07.0 | Stormcast. My name is Johannes Ulrich and today I'm recording from Jackstable, Florida. Thursday, |
0:14.6 | I wrote up a fishing kit that I came across earlier this week. It was remarkable for sort of two reasons, really. |
0:22.6 | First of all, it did fish the United States Postal Service, which is not a very common |
0:29.2 | fishing target, but certainly does happen occasionally. In this case, the real goal was just |
0:35.0 | to get a credit card number out of the user. And the |
0:38.7 | rules here was that, well, you had to change an address for a package that was supposed to be |
0:44.0 | delivered. And yes, you used the credit card number to verify your identity. The fishing kit |
0:51.2 | came with some logs of victims, only about a dozen or so people apparently fell for it, but there was also plenty of evidence of researchers and such poking around. |
1:01.2 | So not sure how many of these victims were actual real. |
1:04.9 | The second sort of interesting part was that the data infiltration here, or really the reporting of the data back to the attacker, |
1:12.2 | happened via Telegram. A simple PHP script that did submit the data to a Telegram API, |
1:22.4 | which would then be received by the attacker. Overall, far from sophisticated, the fishing kit was hosted on a compromised |
1:32.5 | for a press site that was pretty much missing any kind of security feature. And Sonic Wall took |
1:40.5 | the little bit unusual step to warn its customers in a special notice that the |
1:46.1 | attackers are taking advantage of an unpatched flaw in the version 8 of the firmware, |
1:52.9 | affecting the SMA 100, an older SRA series devices. Version 8 of the firmware is end of life and there is no patch available for this version, |
2:04.8 | but you can update to version 9 or 10 of the firmware. |
2:09.2 | Of course, this may require that you do have a valid software subscription license for Sonic |
2:15.8 | Wall. |
2:16.6 | The vulnerabilities themselves have been known for quite a while, and they have been exploited |
2:20.5 | for quite a while. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.