meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, May 14th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 14 May 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cross Browser Tracking; Cisco AnyConnect Patch; MSBuild Abuse

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, May 14, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich,

0:09.7

and the time I'm recording from Jacksonville, Florida. We've got a new cross-browser fingerprinting technique

0:17.8

that comes from Constantine Durutkin from Fingerprint J.S. Fingerprint J.S.

0:24.5

Of course, fingerprinting JavaScript library. And what he found was an interesting cross-browser

0:32.5

vulnerability that allows you to identify a user possibly even if they're using different browsers.

0:41.2

So often privacy conscious users will use one browser for, for example, more sensitive

0:46.2

sites and another browser for business sites. And of course, different browsers keep

0:52.9

different cookies, different extensions and such.

0:57.2

So typically there is little crosstalk between browsers and information sort of stays separate to each browser.

1:05.3

But what Constantine found is there is one interesting issue that's identical for both browsers or all browsers

1:13.6

on the system and really more a feature or property of the system the browsers are running

1:20.6

on and this is registered URL schemes. So typically if you think about a URL, you think about

1:27.4

something like

1:28.2

HTTP colon or HTTP colon, which would be the schemes here for these URLs. But various

1:36.4

applications that are installed are able to register their own schemes, like for example, Skype

1:42.8

colon. So if you are clicking on a URL that starts with Skype colon, then of course, there will

1:49.8

be a pop-up offering you to use Skype.

1:53.6

But what's less known is that the browser can actually check which URL schemes are

2:00.0

registered. And that's exactly what this fingerprinting

2:03.3

technique does. It essentially enumerates software installed on your system. Now, they can't

2:11.4

figure out all software that's installed in your system, only software that has registered a URL scheme.

2:19.0

As part of their proof of concept, they're testing 24 different applications.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.