meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 29th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 August 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Open Redirects; ADB Botnet; Android CamScanner Malware; Cisco REST API Auth Bypass

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, August 29, 2019 edition of the Sandsenvit Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich.

0:10.3

And I'm recording from New York City, New York.

0:14.7

Today we have another guest diary from Jan Correba to talk about.

0:19.6

This one is about an often neglected and sometimes

0:23.6

underestimated web application vulnerability open redirects. OAS patted as part of its top

0:32.1

10 list in, I think up to 2013 open redirects usually happen if a website redirects a user to a different

0:42.6

page or a site based on an unvalidated URL parameter.

0:48.3

So what happens here is that someone can send a victim a link that goes to a page that the victim trusts, but as part

0:57.6

of the URL, there is a second URL that's then being used to redirect the victim. One concern

1:04.9

with this vulnerability is, of course, fishing an attacker could craft a link that leads to the page to be fished and have it redirect the victim to the actual fishing page.

1:18.3

Of course, in most cases, attackers can get away with simpler fishing attacks.

1:23.4

That's why you probably don't see this attack done really that often, even though one

1:29.2

thing Jan found is that there are a ton of websites out there that suffer from exactly this

1:37.0

vulnerability.

1:38.9

And Jan offers some Google dorks to help track down possible vulnerable pages.

1:47.0

And yet again, we got Android malware to talk about.

1:50.0

This one is a bit more tricky than the one I talked about yesterday.

1:55.0

The problem in question is cam scanner, an application that allows you to scan documents with your phone's camera

2:04.1

and turn them into PDFs. The application itself is essentially legit and works, but like often

2:12.6

with free software, the application does earn some money via advertisements, and apparently the author of

2:21.9

the application may have gotten a little bit greedy recently. In order to support the advertisement

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.