4.9 • 696 Ratings
🗓️ 3 April 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, April 3, 2020, edition of the Sands and Storm Center's Stormcast. |
0:08.0 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:12.9 | Let's start out by catching up about some of the diaries published over the weekend. |
0:18.3 | Jan published on Friday a diary about the use of the X-frame options |
0:23.8 | header and the respective content security policy option frame ancestors. So the big difference |
0:30.9 | between the two is that first of all, the X-frame options header is being obsoleted. It's still |
0:37.0 | supported in current browsers, but maybe going |
0:39.5 | away the CSP frame Ancestors is the more modern way of doing it. It is widely supported. And unlike |
0:47.4 | X-frame options, you're able to specify specific origins that are allowed to eye frame your page. |
0:55.0 | So what are the results? |
0:56.0 | Well, Jan looked at the top 1,000, 100,000 and 1 million domains. |
1:03.0 | It looks pretty sad. |
1:05.0 | I'm actually a little bit surprised that the top popular domains are more likely having either header. |
1:14.2 | I would expect that they may intentionally allow more eye-framing than some of the less |
1:20.1 | popular sites, but well, appears that as with many security features, more popular, larger |
1:27.3 | sites, of course, with more resources |
1:29.3 | are implementing more of these security features. |
1:33.3 | And then we got an update from DDE for its Oli Dump tool. |
1:38.3 | Well, it's now supporting MSI files. |
1:41.3 | MSI files, the Microsoft installer files, of course, that's what you typically use |
1:45.8 | to install software on Windows. |
1:48.5 | They are OLE files, and well, now they are natively supported by OlyDump for analysis. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.