4.9 • 696 Ratings
🗓️ 22 November 2024
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, November 22nd, |
0:04.0 | 2024 edition of the Sansanet Storms and Stormcast. |
0:08.0 | My name is Johannes Ulrich and then I'm recording from Singapore. |
0:14.0 | Did he look at some fishing emails that made the news recently? |
0:20.0 | These fishing attachments are actually using the |
0:24.6 | little bit unusual SVG file format. |
0:28.6 | SVG is a vector-based image format. |
0:32.6 | It's often used on web pages, for example, on the United Storm Center, we have these little icons on the left |
0:39.6 | that are encoded as SVG. The advantage of SVG is that because it's a vector format, it |
0:47.3 | scales nicely, it can also easily be embedded in a web page so you don't need to load additional files. |
0:57.0 | But attackers apparently are using these images in order to bypass detection rules. |
1:04.0 | In addition, SVG may embed JavaScript and that's being abused here in order to pull in the company's logo from |
1:14.6 | a web service that offers company logos based on their domain name. So if an attack is |
1:22.6 | targeting a particular individual, then the domain name of the email address, is being used to display that company's |
1:29.8 | logo, which of course makes the attack more plausible. |
1:33.3 | Has seen similar things in the past on other phishing emails without SVG, but yes, the main |
1:41.3 | point here of SBG is to bypass detection rules, not really to launch |
1:47.1 | any fundamentally different attack. |
1:51.2 | And in today's weaknesses in Enterprise Security Tools, we have a little bit of a minor |
1:56.6 | issue in the 40 client VPN. |
2:00.3 | The issue here is logging. If NetHacker launches a |
2:03.8 | prudeforce attack with 40 client, the failed login attempts are usually logged and |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.