4.9 • 696 Ratings
🗓️ 31 July 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, July 31st, 2023 edition of the Sandton and Stormtuner's Stormcast. My name is Johannes Ulrich and the recording from Jacksonville, Florida. |
0:16.0 | Well, let's start out with some diaries that we published over the weekend. First of all, on Sunday, |
0:23.6 | I wrote about a sort of interesting fishing scam. Maybe we want to call it smishing, but |
0:28.9 | what's different here is that it's not actually using an SMS message, but an Apple |
0:34.8 | iMessage, which does require an Apple device to actually send the message. Also, |
0:41.2 | some off vacation. It came from a phone number in the Philippines. Sadly, they didn't accept my |
0:47.0 | request for a FaceTime connection. It did impersonate the United States Postal Service. |
0:54.6 | Overall, the message was done reasonable, I have to say, not perfect, but I've seen verse. |
1:01.4 | It was also very picky in that it only accepted the mobile version of Safari. |
1:07.4 | If you came with any other browser or even the desktop version of Safari, you were |
1:12.3 | redirected to the authentic USPS website. |
1:17.5 | This is likely also going to help with not having the fishing page removed, because of course, |
1:24.2 | this makes it less likely that casual sort of inspection of the URL leads |
1:29.9 | directly to the fishing page. |
1:32.9 | The question that has often been asked and Xavier is asking again in his diary this weekend |
1:39.6 | was why attackers don't pay more attention to IPV6, or maybe they do and we're just not |
1:46.7 | really looking for it. |
1:48.2 | Xavier found a malicious Python script that actually specifically looks into establishing |
1:53.7 | whether or not the particular host that has infected has IPV6 connectivity. |
1:59.2 | They actually do have a sense research paper coming hopefully in next month or so |
2:04.9 | that will look into this in particular for NTP. |
2:08.3 | Of course, you're not going to see a lot of sort of the blind scanning like we see |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.