4.9 • 696 Ratings
🗓️ 28 February 2019
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, February 28, 2019 edition of the Sandinand Storm Center's Stormcast. |
0:07.0 | My name is Johannes Ulrich. |
0:09.0 | And today I'm recording from Augusta, Georgia. |
0:13.0 | Coin Hive today announced that it will discontinue operations in about a week on March 8th. Coin Hive made a name for itself by providing |
0:23.9 | JavaScript code that allowed you to mine Monero in browsers. Now this of course has been |
0:31.1 | heavily abused and Coin Hive has taken a lot of criticism for this. The reason to shut down isn't related to this controversy as much |
0:40.9 | as to the decrease in the profitability of Monero mining and some changes to the Monero |
0:48.5 | algorithm that will hit on March 9th. So instead of adjusting their code for this new algorithm, of course, |
0:56.9 | there have been a couple other services that essentially copied the Coin Hive concept. We'll see if |
1:02.5 | they will continue to operate and if the discontinuation of Coin Hive will lead to a drop in the |
1:09.5 | proliferation of cryptojacking. |
1:13.3 | And a security company Edgewave has yet another case of fissures using Asia block storage. |
1:21.3 | The reason this is interesting is that URLs for Asia's blog storage and in Windows.net. |
1:29.5 | So if I visit an HTML page that's stored within Asia, well, I actually get a Windows.net |
1:37.6 | domain with a proper HTTP certificate, which may make users more likely to actually enter their credentials. |
1:48.8 | Of course, this is used for Office 365 fishing, which will take best advantage of this domain. |
1:57.0 | Like I said, I don't think that's the first time I've seen this. |
1:59.8 | Also, last week I think it was, |
2:01.7 | we saw Google Translate being used in similar ways in order to hide the actual fishing page |
2:08.2 | behind what looks like a legitimate Google host name. And while it should be clear that |
2:14.4 | old Warner Blitz never really go away, |
2:25.5 | the Cisco Talas research team is reporting that they see sort of an uptick against an old Elasticsearch vulnerability. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.