ISC StormCast for Friday, June 11th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 June 2021
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, June 11, 2021 edition of the Sandsenet Storm Center's Stormcast. |
| 0:07.3 | My name is Johannes Ulrich, and the name am I'm recording from Jacksonville, Florida. |
| 0:12.4 | Quick diary today, just looking at some of these cookie warning banners. |
| 0:17.0 | You may have seen them in particular in Europe, where a website gives you the option to set cookies or not set cookies or even select what kind of cookies you are willing to accept. |
| 0:29.6 | Truth, however, is that these banners are often really more show than actual action, meaning that cookies are often being set before the banner |
| 0:40.3 | is even displayed. |
| 0:41.3 | And it's not just the websites that are to blame for this. Often these cookies come from |
| 0:46.3 | middle boxes, cond delivery networks, that add these cookies in order to, well, track users. |
| 0:53.3 | That's what cookies are typically used for |
| 0:55.8 | and to achieve some form of statefulness in requests being passed through the content |
| 1:02.9 | delivery network. I did a very quick and dirty test on the top 100 websites using curl |
| 1:09.2 | just to see how many of these websites are returning set cookie |
| 1:13.3 | headers to the first request they received and at least 30% of the websites did and a couple of |
| 1:22.4 | additional checks with the browser indicates that the real number is probably much higher. Well, is there |
| 1:28.7 | anything that you should do about this? Probably not just be aware of it. Yes, you are being |
| 1:34.9 | tracked and browser makers are actually sort of getting a little bit on top of this by restricting |
| 1:40.9 | what cookies can do and how they're being used. |
| 1:46.0 | Well, it's time to update your Citrix appliances again. |
| 1:51.0 | Citrix Application Delivery Controller, ADC, Citrix Gateway, as well as Citrix SD-WANWANOP, |
| 1:59.0 | need to be updated to fix two vulnerabilities that Citrix rated as high. |
| 2:05.3 | The first one I don't think is actually such a big deal. |
| 2:08.3 | It's denial of service vulnerability. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

