4.9 • 696 Ratings
🗓️ 26 June 2020
⏱️ 17 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Friday, June 26th, 2020 edition of the Sandtonet Storm Center's Stormcast. |
0:07.4 | My name is Johannes Ulrich. |
0:08.9 | And today I'm recording from Jacksonville, Florida. |
0:12.3 | And a couple of you asked for recordings of the Tech Tuesday workshop. |
0:17.0 | Well, we are not recording these workshops because there are these breaks for exercises and such, |
0:22.6 | but what I'm doing instead is I'm recording the content of the workshop in three separate |
0:29.6 | videos. |
0:30.6 | Meet the first one live today that explains how to install the honeypot. |
0:35.6 | Was hoping to get the second one live today as well. |
0:39.0 | Well, if not today, then maybe tomorrow I'll make the two other videos live. |
0:46.1 | And those two other videos will go over how to use our data and also a video about a little bit |
0:53.1 | of the background of Internet Storm Center and D. Shield. |
0:57.7 | And yes, XIF data is back. |
1:00.1 | XIF data is comments and other associated data that you often find in image files. |
1:08.3 | Now, this type of data has been abused heavily in the past to smuggle data across |
1:15.0 | networks. The latest example was found by Malabites, and they found that favorite icon, |
1:22.7 | these FAF icon files that you often see displayed in your browser's toolbar are being used to actually |
1:31.5 | transmit code. |
1:33.6 | They found some credit card skimming JavaScript that by itself actually doesn't look all |
1:40.1 | that malicious. |
1:41.1 | At least you don't really know what it's doing, but it is loading a remote |
1:45.7 | Fav icon file, then parse it for XF data. And for example, the copyright field in the XF data |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.