meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, November 19th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 19 November 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. JavaScript Delivers Agent Tesla; GitHub vs cookies.sqlite; Fatpipe VPN Exploited; Abusing ClouDNS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, November 19th, 2021 edition of the Sandcent and at Storm Center's Stormcast. My name is Johannes Ulrich.

0:10.0

And I'm recording from Fort Walton Beach, Florida.

0:14.3

Savoyer today took a quick look at a piece of JavaScript that he came across that was used in order to deliver an ancient Tesla

0:23.7

Trojan.

0:24.3

Ancient Tesla, a pretty common info stealer.

0:28.5

And the way it's usually deployed is by sending some JavaScript to the user and asking

0:34.9

them to run the JavaScript locally.

0:38.3

So you would receive, for example, a SIPP attachment with the JavaScript and then when you save the file and sip it, double click.

0:46.3

You're basically executing the JavaScript locally, which of course does provide access to additional functionality, like in this case the ability

0:55.7

to download and execute additional malware.

0:59.9

The JavaScript was obfuscated as so often with these types of JavaScript, but Xavier

1:06.0

walks you through a quick analysis of the JavaScript that is pretty straightforward because some of the

1:13.4

URLs, for example, that were used to download the next stage were still readable, even though

1:19.6

the obfuscation took place.

1:23.4

And the register has a story discussing findings of security researcher Idon, Marilyn.

1:29.8

Now, Idan did find that GitHub is hosting multiple cookies SQLite databases.

1:39.4

Cookies SQLite is, as the name implies, SQLite database that is used by Firefox in order to store session cookies.

1:48.0

This file is stored usually in a profiles folder, but apparently often uploaded to GitHub by unwitting users.

1:56.7

And this is a problem well because if I have your session cookie, I am you as far as a website is

2:04.2

concerned. So leaking these session cookies can be almost as dangerous as leaking your

2:11.3

username and password. GitHub rejected a bug report here as out of scope.

2:17.7

After all, it's not really GitHub's fault that users are uploading this type of data.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.