meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, April 3rd, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 3 April 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Preventing Framing; Oledump Supports MSI; 3CX Update; PinDuoDuo App Issues;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, April 3, 2020, edition of the Sands and Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.9

Let's start out by catching up about some of the diaries published over the weekend.

0:18.3

Jan published on Friday a diary about the use of the X-frame options

0:23.8

header and the respective content security policy option frame ancestors. So the big difference

0:30.9

between the two is that first of all, the X-frame options header is being obsoleted. It's still

0:37.0

supported in current browsers, but maybe going

0:39.5

away the CSP frame Ancestors is the more modern way of doing it. It is widely supported. And unlike

0:47.4

X-frame options, you're able to specify specific origins that are allowed to eye frame your page.

0:55.0

So what are the results?

0:56.0

Well, Jan looked at the top 1,000, 100,000 and 1 million domains.

1:03.0

It looks pretty sad.

1:05.0

I'm actually a little bit surprised that the top popular domains are more likely having either header.

1:14.2

I would expect that they may intentionally allow more eye-framing than some of the less

1:20.1

popular sites, but well, appears that as with many security features, more popular, larger

1:27.3

sites, of course, with more resources

1:29.3

are implementing more of these security features.

1:33.3

And then we got an update from DDE for its Oli Dump tool.

1:38.3

Well, it's now supporting MSI files.

1:41.3

MSI files, the Microsoft installer files, of course, that's what you typically use

1:45.8

to install software on Windows.

1:48.5

They are OLE files, and well, now they are natively supported by OlyDump for analysis.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.