ISC StormCast for Friday, November 1st 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 November 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, November 1st, 2019 edition of the Sansonet Storms on us Stormcast. |
| 0:07.2 | My name is Johannes Ulrich. |
| 0:08.8 | And then I'm recording from Jacksonville, Florida. |
| 0:13.1 | Today we got a diary by Jan showing an interesting and somewhat dangerous behavior of Outlook 365 and EML file attachments. |
| 0:24.6 | EML files are essentially emails and you probably have seen them if you save an email message. |
| 0:30.6 | It often is saved as an email file. |
| 0:34.6 | And if they're used as attachment, your mail client may kind of interpret them as an email. |
| 0:41.6 | Now, many mail filters are looking at these email files just because they can easily be mistaken |
| 0:48.8 | for an actual email message, but apparently Outlook 365 doesn't do so. |
| 0:55.0 | Well, Jan looked into what he can do with this behavior as part of a pen test and what he found |
| 1:02.0 | a lot of tricks that don't work anymore in a normal email, like for example having one |
| 1:08.8 | URL visible to the user and another URL that's actually then |
| 1:13.1 | being clicked on, well, that works still as an email attachment and actually you can fake |
| 1:21.1 | the from address and Outlook 365 in his case. |
| 1:26.0 | He used PayPal, did actually put the PayPal logo right next to the |
| 1:31.0 | from address, kind of confirming to the user that this appears to be a valid PayPal email, |
| 1:37.6 | which it wasn't. |
| 1:39.7 | Jan did notify Microsoft about this behavior, but Microsoft replied that they're not really considering |
| 1:47.1 | this security issue since it does rely on social engineering. |
| 1:55.0 | And as part of October's patch Tuesday, Microsoft fixed TLS spoofing vulnerability, CVEE 2019, 1318, but apparently |
| 2:06.3 | introduced an issue with this patch that causes TLS connections to timeout. |
| 2:14.4 | To address this problem, Microsoft published now a knowledge-based article with |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

