meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, December 29th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 December 2016

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. More PHPMailer Issues; Picking Smart Locks; #IPv6 Scanning

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, December 29th, 2016 edition of the Sands and Storm Center's Stormcast.

0:07.2

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:12.1

Well, by now it should be old news that a PHP mailer, this PHP class that allows you to send email is vulnerable.

0:20.0

But to add a little bit to this,

0:21.7

we actually have a second vulnerability to talk about. It's very similar, actually related to the

0:27.5

first vulnerability that was originally discovered around Christmas. This new vulnerability is

0:33.8

more or less just an incomplete fix of the first vulnerability.

0:38.5

So if you updated PHP Mailer a few days ago, I hope you kept good notes and can do so again

0:45.8

with this new update.

0:48.3

There are a couple of issues now because of the additional escaping that PHP Mailer does. There were some issues where people

0:56.8

did escape before they passed the arguments to PHP Mailer, then it got double escaped and

1:02.7

the like. So I don't think this problem is actually completely solved at this point. Your

1:08.6

best bed is if you are setting a from address, set it to a fixed

1:14.0

string. The from address should match the server. The email comes from anyway. It's bad practice

1:21.4

to set it to an address that's provided by the user because you're not necessarily authorized

1:27.2

to send email

1:28.8

on that user's domain's behalf. So if that user has things configured like SPF records or

1:35.8

D-Kim, there's a good chance that the email will end up in a spam filter if you do set the from

1:43.7

address. Set the reply to address. That way, if you do set the from address.

1:44.6

Set the reply to address.

1:46.1

That way if you reply to the email, it will go to that user.

1:50.3

But keep the from address to a fixed address that is associated with your web server.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.