meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, February 22nd, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 February 2024

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Archive.org Phish; ScreenConnect PoC; Post Quantum iMessage;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, February 22nd, 2024 edition of the Sandsenet Storm Center's Stormcast.

0:08.5

My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:14.7

Jan today wrote up a fishing scam that used Archive.org to host the actual fishing page. Archive.org, of course,

0:24.8

most well known for its way back machine that archives old websites, has also the ability to

0:31.9

upload files and archive files, and that's the feature being abused here. So the fishing pages that

0:40.1

are in Archive.org, at least the ones that Jan talked about, are not sort of accidentally

0:45.2

indexed and copied fishing pages, but the fishing pages deliberately uploaded to this site

0:52.3

by likely the person behind these fishing scams.

0:56.4

Archive.org, of course, only serves static HTML, but that does not prevent the attacker

1:03.0

then from using JavaScript to make the pages more malicious or more dynamic.

1:09.0

In this particular case, for example, they are loading a screenshot of the website

1:14.7

from thumb.io, have seen that site used in the past for it as well, as well as logos from

1:22.6

logo.com. Archive.org, of course, is often cited specifically allowed to be visited.

1:31.0

You have to be a little bit careful here because it sort of could be used as kind of a proxy.

1:35.7

But as Jan explains, these phishing pages, because they're deliberately uploaded, not sort of what Archive.

1:42.7

org would index from existing websites. They use a

1:47.5

slightly different URL scheme with a four-part host name, randomstring.us.org, which differs from

1:56.8

the host names typically being used for the more legitimate or more normal wayback machine

2:03.1

archive.org content. And then we do have a proof-of-concept exploit available now for the

2:12.4

screen connect vulnerability, and apparently this vulnerability is already being exploited in the wild. No surprise

2:20.6

given how trivial it is to exploit it. The problem here is similar to another vulnerability and I

2:26.7

forgot what system it was. I think talked about it last week but where you have essentially a setup

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.