ISC StormCast for Thursday, March 16th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 16 March 2023
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, March 16th, 2020, 3 edition of the Sansanet Storm Center's |
| 0:07.8 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:15.3 | Jan today wrote up what I would call sort of a more modern fish, and that's something that we do see quite a bit lately. |
| 0:23.4 | First of all, the email links to an address in IPFS.io. |
| 0:30.4 | This is the Interplanetary File System, a distributed storage system, which makes it difficult to take down specific phishing pages. |
| 0:39.6 | The other thing they're doing is that they're displaying the victim's homepage based on the |
| 0:46.3 | email domain in an eye frame. |
| 0:48.8 | Now, this is something that you can actually easily prevent. |
| 0:53.0 | We have seen in the past sometimes where they're using sort of screenshot services |
| 0:56.8 | like thumb.io, that's a little bit more difficult to prevent, |
| 1:01.1 | but you should have the right headers in your HTTP response |
| 1:07.5 | that will prevent your page from being displayed in an eye frame. It used to be that X frame |
| 1:14.4 | options was the header to use here, but more recently this switched over to Con and Security Policy. |
| 1:21.3 | So you really need Con and Security Policy in order to prevent this from happening. |
| 1:29.9 | And one of the interesting vulnerabilities that Microsoft patched yesterday was CVE |
| 1:36.6 | 2020-23-23-397. |
| 1:39.7 | This was the Microsoft Outlook vulnerability. |
| 1:42.5 | I told you that this is likely something very easy to |
| 1:47.4 | exploit. Well, it turns out that MDSec now has a great write-up about this vulnerability, |
| 1:53.8 | showing what it's all about and how to exploit it. It's actually sort of a little bit an odd |
| 1:58.9 | feature here. Apparently, you're able to include a |
| 2:03.7 | URL that's being used for the notification sound when you are sending a calendar invite. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

