meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, October 5th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 5 October 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Phishing Kit; Huawei Botnet; SQL Server CU 8; Telstra BGP; Raccine @cyb3rops

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, October 5th, 2020 edition of the Sandstone Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.5

Xavier came across an interesting fishing kit on Friday.

0:17.5

It emulates the American Express login page.

0:21.6

Pretty well done and he's going over some of the parts here.

0:25.6

Now we have gone over fishing kits before nothing sort of extraordinary here.

0:30.6

Just a reminder that if your site is impersonated by a fishing kit, just like in this case, often the attacker

0:39.3

will direct the user to the legitimate website in the end.

0:43.3

Same thing happens here.

0:45.3

One little mistake they make here, and not sure if this is a little bit intentional on American

0:50.6

Express's side, but the final redirect to the Amex website goes to a page where you

0:58.3

get an access denied.

1:01.2

Another common feature that you probably have heard about if you have read a prior Fishing Kit

1:07.1

write-ups from us, but this F fishing kit also includes a block list of IP addresses

1:14.3

that are often associated with researchers, security companies, and the like in order to

1:21.4

block them from accessing the fish kit. But as you can tell, well, just like block lists for the good guys,

1:29.3

isn't all that effective.

1:30.8

Xavier still had no problems accessing it.

1:34.5

And Guy took a look at his honeypot and found, well, aside from the usual attacks

1:40.4

against home routers, particular, netgear, also some attacks against different

1:46.1

types of routers, like in particular Huawei Home Gateways. And one particular sample that

1:53.0

he recovered here was actually not yet known to Virus Total, which is somewhat unusual given

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.