meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, July 29th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 July 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Covert Bookmarks; SAMBA Bug; Apple BGP Hijack; Veritas and IBM Patches @sans_edu

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, July 29, 2020 edition of the Sands and the Storm Center's Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:13.5

I posted a quick diary earlier today, summarizing a research paper, one of the students at our Sands Technology Institute College

0:22.7

published earlier this week.

0:26.1

It actually takes a preliminary observation by Boyan from last year.

0:31.5

It was published as a diary back then.

0:34.3

The issue Boyan noted in last year's diary was that Google Chrome's extension sync

0:40.6

features was used as a cover channel by an extension installed into Google Chrome. Now, the student,

0:48.5

David Preffer, looked into this mechanism and how it can be exploited.

0:55.6

David noticed that even without having control over the browser itself via a plugin or an extension,

1:01.8

it is possible to just manipulate bookmarks and use the same sync channel that this plugin

1:08.9

used.

1:09.7

The cover channel David uncovered is quite capable and actually very

1:14.5

difficult to detect as it uses the normal requests to Google's API to synchronize these

1:22.0

malicious bookmarks. Basically, all he does is he takes any file on the system and then encodes it to work as a bookmark.

1:30.0

There is also quite a bit of bandwidth available here.

1:33.5

David showed that over 200,000 bookmarks actually may be used and the transfer rate is pretty high

1:41.2

and only being throttled after a few 10,000 of bookmarks have been synced.

1:48.5

Take a look at David's paper if you want to learn more about, isn't how to detect this particular

1:54.2

covert channel. David also published a GitHub repository with a tool that he created in order to experiment with this channel.

2:03.6

And maybe we'll have David on a future podcast to talk a little bit more about this work.

2:11.2

And Samba, the open source implementation of the S&B protocol, received a critical update that

2:17.2

you probably want to apply quickly in

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.