meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, September 22nd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 September 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Free Phishing; Insecure tarfile.extract; Twitter Logout

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, September 22nd, 22nd, 22nd, 22ndt, StormCast.

0:08.9

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.7

Xavier today took a look at fishing pages that are not hosted on compromised servers,

0:20.7

but instead they take advantage of free services

0:24.8

to host various components of the fishing kit. In particular, Xavier is looking at some

0:30.4

resources that may not be as well known as, for example, Google Forms. One example is catbox.m.O.E.

0:40.3

A simple free file hosting site, as often, it does allow files up to 200 megabytes.

0:48.3

By the way, if anybody knows why, this is sort of a common limit, let me know.

0:52.3

And that's, of course, sufficient for most HTML and collateral

0:56.9

like images and such that you may need to create a fishing page. Of course, where Google Forms

1:03.1

still shines here is that you also get sort of that form submission part. Well, there are other

1:09.2

services that allow you to take care of this. Formsubmit.C.O

1:14.0

is one that Xavi has observed being used for fishing sites. It also does actually do the

1:21.6

submission for you. So it turns the form submission in an email, so you don't have to write any code.

1:27.8

I mentioned before, I think about two weeks ago, IPFS.io.

1:32.7

That's another service that allows you to sort of create forms and host them essentially

1:38.1

in their IPFS cloud.

1:41.5

This provides a little bit more work, but still quite effective, and of course, doesn't

1:46.7

have that annoying disclaimer that you have on all Google forms that basically tells people that

1:52.0

this is not a legitimate login page and that you shouldn't submit any passwords. But the real

1:58.8

lesson here is that any free service like this will be abused. So if you

2:04.0

offer a free service like this, you may have good intentions, but please come up with some kind

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.