meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, October 18th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 18 October 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. NewShareCount Abuse; D-Link Vulns; RID Hacking

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, October 18th, 2018 edition of the Sansonet Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and I'm recording from McLean, Virginia.

0:13.0

Today we've got yet another example why it's so important to watch for any code that you are including from third party sites in

0:23.6

your website.

0:25.4

The latest example here comes from new share counts.

0:29.3

New share counts was sort of a Twitter plugin button that you could display on your webpage

0:35.4

in order to display the number of likes and follows and the like.

0:41.4

Well, it turns out that back in July, this service actually ceased to exist.

0:46.9

And more recently, the service was apparently taken over and abused in order to redirect users to malicious websites.

0:57.0

In order to include this counter on your website, all you needed to do was add the Newshare

1:02.3

Count JavaScript to your site, which was loaded from the Newsharecount.com website. So this

1:09.7

wasn't JavaScript that you downloaded and installed on your server.

1:13.9

So once the domain changed hands, apparently the new owner or whoever is control of that site now

1:20.7

swapped out the JavaScript and it will now redirect users to scams.

1:26.7

Overall, the script doesn't seem to be super popular, something like 800 plus sites, according

1:31.3

to Sukuri, but it's probably just one of many similar scripts that people are including

1:37.3

in their sites without due diligence and monitoring these scripts for any changes.

1:49.5

Now, you can use sub-resource integrity SRI in order to protect yourself somewhat.

1:55.1

Of course, that requires that you are actually being notified by the legitimate owner off the site you're loading scripts from whenever you need to update this particular feature.

2:02.3

And Polish researcher, Pl Dumchick released three different vulnerabilities affecting, I believe,

2:09.0

about eight different models of D-Link routers.

2:13.1

The first one is a simple directory traversal.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.