ISC StormCast for Monday, December 9th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 December 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, December 9th, 2019 edition of the Sansanet Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich. |
| 0:09.4 | And today I'm recording from Jacksonville, Florida. |
| 0:13.2 | On Friday, our handler Jan came across an interesting fishing email. |
| 0:19.0 | What made it stand out was the size of the HTML attachment |
| 0:23.6 | in this email. It carried about 930 kilobytes. The HTML file did not only include simple |
| 0:32.6 | HTML code to replicate a legitimately looking login page, but the author event as far as to include |
| 0:40.9 | a complete copy of JQuery and Bootstrap to make the site look and behave more plausible. |
| 0:49.4 | Now, once a user fills in credentials into the HTML page, they are of course submitted to a website, but it's more difficult to take down these |
| 0:59.5 | websites because once you look at it, well, it's just an empty page. |
| 1:04.8 | There is no trademarkable logo or anything like this on the actual website, which of course means that many |
| 1:13.8 | automated tools and sort of try to identify shutdown fishing sites will not work. |
| 1:21.5 | And China is dusting off its great cannon again, or sometimes it's also called the red cannon to launch denial of |
| 1:30.4 | service attacks against a forum supporting the protesters in Hong Kong. |
| 1:36.1 | This great cannon is a feature of China's great firewall. |
| 1:41.0 | The firewall is not only able to block access to content, but it is also able to |
| 1:47.5 | modify content. The first time I remember having heard of this feature was back in 2015 when |
| 1:55.4 | GitHub was attacked using the Great Canon. Back then, the Great Canon was used to convince GitHub to remove projects that attempt |
| 2:05.2 | to bypass the Great Firewall. |
| 2:08.6 | Since then, it has been used a couple of times, but those attacks haven't really sort of |
| 2:14.7 | hit the news in a major way. |
| 2:16.8 | The Great Cannon borrows a technique used by the low orbit. attacks haven't really sort of hit the news in a major way. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

