ISC StormCast for Monday, October 23rd, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 October 2023
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, October 23rd, 2003 edition of the Sansonet Storm Center's |
| 0:06.8 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.3 | Anybody who has ever touched malware reverse engineering probably knows how useful some of DDA's tools are to accomplish that. |
| 0:24.5 | One of the tools that he created is base 64 dump.py. |
| 0:30.0 | Now, this tool, of course, as the name implies, was initially created to decode base 64 data |
| 0:37.3 | that was sort of found in matter samples and other files. |
| 0:41.3 | Well, as the DEA reminds us today, it can actually do a whole lot more, like, for example, |
| 0:47.4 | decode a number of hex encodings and the like net bias encodings with like upper lowercase and such. |
| 0:55.7 | So if you're interested in some of these advanced features of Bay 64 dump, |
| 1:00.9 | well, take a look at DDA's diary where he goes over some of these features. |
| 1:08.2 | Now probably I have neglected a little bit talking about some noteworthy bug bounty write-ups. |
| 1:13.7 | One of the nice things about buck bounties is that the discoverer then writes up the process, |
| 1:19.5 | how they found a certain vulnerability, and what the root cause of the issue was. |
| 1:24.4 | Nice example of vulnerability in the harvest app and related to |
| 1:32.2 | OAuth tokens particular Microsoft account ORAT tokens one problem with OAuth is as the |
| 1:40.3 | client connects to the authentication server in this case Microsoft, it will supply a redirect |
| 1:48.0 | URL that's then being used to redirect the user back to the original application, asking for |
| 1:56.3 | the Oath credentials. The problem here is, well, that redirect will also include the credentials. |
| 2:03.1 | And if an attacker is able to provide malicious redirect, then the credentials are first being sent |
| 2:12.0 | to the attacker's website, which of course could steal them. Now, this is prevented usually by limiting the URLs |
| 2:19.9 | that the redirect can point to, typically limited kind of to the host name, sometimes a little bit |
| 2:26.4 | more specific of the particular app that uses the credentials. But if that particular website now does have within the scope of allowed |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

