meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, November 4th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 4 November 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Burp Breakpoints; TA589 JavaScript Injection; Hitachi, Fortinet, Nessus Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, November 4, 2020 edition of the Sansonet Storms, Stormcast.

0:08.4

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.9

Quick diary from Rob today about burp and setting breakpoints.

0:18.3

If you have used verb in the past, then other proxies are likely similar.

0:23.5

One of the annoying things sometimes is if you work through a complex web application,

0:28.8

well, you either turn the proxy on or off.

0:30.9

If you turn it on, then you have to click on forward all the time to approve all the

0:36.9

requests that sort of happen happen and you may miss the

0:39.6

important one well if you don't keep interception turned on then of course you may miss the page

0:48.5

that you're looking for because it didn't get intercepted well rob now has an interesting feature here in Burb that he's going into

0:56.4

in a bit more detail. And that's breakpoints. Essentially, what you can do here is you can set a

1:02.6

condition at which point interception will be turned on. In particular, in this case,

1:08.8

Rob was looking for an OAuth, an open ID exchange. So basically, just set the right parameters. And then as that exchange is happening, Burbs Interception will pop up and you'll have the ability to then alter your requests as you wish to.

1:29.3

So a pretty efficient feature like any breakpoint, of course, in a debugger

1:33.8

to help you just sort of zoom in on the part of the website,

1:37.3

not the code, of course, that you would like to inspect.

1:42.6

Well, Paulo Alto is reporting that we have yet another supply chain attack where malicious

1:49.1

actors, which Palo Alto identifies as TA569, injected malicious JavaScript into a company's

1:58.6

website that serves videos on various regional and some national news websites.

2:06.2

Apparently about 250 websites were affected by this attack.

2:12.1

ProofPoint didn't name the particular video platform that was affected here, nor individual news websites

2:19.8

that were affected. But the end effect was that the JavaScript then injected the fake

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.