4.9 • 696 Ratings
🗓️ 12 April 2021
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, April 12, 2021 edition of the Sanct Storm Center's Stormcast. My name is Johannes. Ulrich, |
0:09.5 | and I'm recording from Jacksonville, Florida. This weekend, Xavier wrote about a new remote access |
0:18.4 | tool that was written in Python and targeting Windows. Now, of course, |
0:23.6 | the problem with Windows is that it doesn't come with Python re-installed. So the little installer |
0:31.0 | script that came with this particular backdoor does just download a complete Python environment to the system. |
0:40.3 | Another approach, of course, if you have seen in the past, is where the Python code is just |
0:45.3 | compiled into an executable. It doesn't look like this approach did any good for the attacker. |
0:52.3 | It has a pretty good virus total score. So evasion didn't really |
0:58.1 | work here, but then again, it's also fairly straightforward code. And it looks like that Mozilla's |
1:06.0 | public suffix list did get in the middle of a sort of a spat between Apple and Facebook on tracking users. |
1:15.9 | So first of all, what is the public suffix list? It's something that's maintained by Mozilla, |
1:20.6 | but used by many other browsers and internet-related products. And it's essentially a list of domains that behave like |
1:29.5 | top-level domains. Technically, a top-level domain is the last label in a host name, but there are |
1:37.0 | certain top-level domains that split up further and that have suffixes that really behave like |
1:43.8 | top-level domains. |
1:45.4 | So, for example, for dot UK, the United Kingdom, top-level domain, we have dot-CO, dot-uk, |
1:52.4 | dot-ac-ac, dot-UK, that really behave like top-level domains, and the public suffix list does track |
1:59.9 | those domains. |
2:01.8 | Apple comes in here with a change the announced for iOS 14.5 |
2:07.3 | that will require applications to ask users for permission if they are trying to track users. |
2:15.5 | Now, Apple has, in recent releases of iOS iOS added more and more sort of of these restrictions |
2:22.0 | on user tracking, and this is sort of the latest expression of this new policy. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.