ISC StormCast for Monday, December 19th 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 December 2016
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, December 19th, 2016 edition of the Sandsenet Storms, |
| 0:06.2 | on a stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.0 | We've got yet another webmail cross-site scripting exploit, and I keep saying webmail is really one |
| 0:19.5 | of these real hard-to-secure systems systems given that it has to be able to display a variety of HTML email messages correctly within the web page. |
| 0:30.6 | The latest victim here is Verizon's webmail system and what I really like about this write-up is not so much that they actually found the vulnerability, |
| 0:40.3 | but how they found it. |
| 0:41.7 | They really go into quite a bit of detail how you sort of systematically probe for different |
| 0:47.8 | HTML entities and HTML tags that are allowed, are not allowed, and how you go from there to actually finding |
| 0:56.5 | an exploit against a particular cross-side scripting vulnerability. |
| 1:00.8 | So if you're a pen tester, take a look at this and see some of the methods that are being |
| 1:05.7 | used here. |
| 1:06.9 | If you are a developer, of course, then take this particular test. |
| 1:12.4 | They're running here and try it against your own site before someone else does. |
| 1:18.3 | A lot of recent exploits, of course, take advantage of PowerShell, and then they use PowerShell to download |
| 1:25.6 | additional malware, or in some cases even |
| 1:29.0 | exfiltrate data straight using PowerShell. The problem has been that of course |
| 1:36.0 | PowerShell is a legitimate binary that you have on your system and as such some |
| 1:41.6 | white listing techniques don't work but Tom now has an interesting configuration option for the Windows firewall that allows you to selectively block connections made by PowerShell. |
| 1:55.0 | So once you enable this rule, then PowerShell is no longer allowed to enable or to set up a network |
| 2:03.0 | connection, breaking a lot of these exploits that are trying to download additional components. |
| 2:09.5 | This may of course also affect some legitimate PowerShell scripts, so make sure you test this |
| 2:16.6 | careful in your environment. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

