4.9 • 696 Ratings
🗓️ 1 July 2016
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, July 1st, 2016 edition of the Sansonet Storm Center's Stormcast. |
| 0:06.9 | My name is Johannes Ulrich, and it am recording from Salt Lake City, Utah. |
| 0:11.4 | Often it doesn't take a new fancy technical exploit in order to convince users to give up their username and password. |
| 0:20.2 | Some basic social engineering tricks is usually all it takes in order to get a pretty |
| 0:26.8 | decent response rate. |
| 0:29.1 | To illustrate this point, Xavier wrote up an interesting diary about some spam that he has |
| 0:34.3 | been seen recently where the spam delivers a blurred document and then overlays |
| 0:40.3 | a login dialogue to the document, claiming that if the user enters their email, username, |
| 0:46.3 | and password, it will unlock this document for them. |
| 0:51.3 | Now, this of course then entices users to enter their credentials, thinking that they |
| 0:56.7 | already see sort of this blurt document. They really would like to see what it's all about |
| 1:02.0 | and sounds kind of reasonable that a sender would password protect these type of documents. |
| 1:15.6 | So neat little trick and of course not really all that easy to defend against because no real malver in this sense is actually delivered. |
| 1:19.6 | Now Xavier goes on to look at the actual command control channel that's then being used to submit |
| 1:25.6 | the username and password. So if you're interested in some indicators of compromise, you can certainly check out what he learned about these particular exploits. |
| 1:35.3 | Now there are many users who have given up somewhat on Adobe's PDF reader due to all of the vulnerabilities being reported in that particular piece of software |
| 1:46.0 | and have switched to the alternative written by Fox IT. |
| 1:50.0 | Well, Fox IT and Fox IT Fandem PDF also have vulnerabilities and Fox ID |
| 1:58.0 | just this week released patches for them. |
| 2:01.6 | So if you are using Fox IT, make sure you're up to date. |
| 2:06.6 | And security researcher, Christian Otto, did find a pretty basic vulnerability in |
| 2:14.6 | STARTSEL's Start Encrypt API. I mentioned this API before, it does allow you |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.