meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, December 12th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 December 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Sitemap.xml; Apple Patches; Android Password Autospill

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, December 12, 2020,

0:04.2

edition of the Sands and its Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich, and today I'm recording from Washington, D.C.

0:14.2

Rob today wrote about Sitemap.xml, a file that he found pretty useful for penetration testers.

0:21.6

Sitmap.xml can probably pretty well be described as the opposite of robots.

0:28.6

.

0:29.6

It's a standard formatted file that you often leave on a web server in order to give search engines

0:36.6

hints as to what files to prioritize

0:40.5

when they're sputtering.

0:42.1

And then they're often also used, for example, when you see the results being displayed

0:46.7

on a search engine, you may see a couple pages being highlighted.

0:51.7

Now these files are often auto-generated by little scripts, and the one thing that Rob

0:58.3

finds is that, well, they're often somewhat out of date, so sometimes they may lead to pages

1:05.0

that are no longer really in use, and that, of of course sometimes can lead to vulnerabilities.

1:13.0

The other issue where a sitemap.xml comes in handy that it also sometimes lists pages

1:19.9

that aren't linked from other pages within the site, like let's say pages that are created

1:27.4

for specific advertisement campaigns and such.

1:31.5

So that way, if you just would spider the site using traditional tools, well, you would have

1:39.0

missed those specific pages.

1:42.1

Rob, as usual, offers a couple PowerShell scripts and such to deal with

1:46.6

parsing the output of Sitemap.xml. And also simplifying the results and converting the results

1:54.1

into more standard formats. And Apple today released updates for iOS, iPadOS, MacOS, and TVOS, as well as watchOS.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.