meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 22nd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 22 February 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Odd E-Mail Addresses; SMS Number Rental; Xenomorph Banking Trojan; Cryptbot; Magento Clarification

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, February 22nd, 22nd, 22nd, 22 edition of the Sands and at Storm

0:07.7

Center's Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:14.6

Quick note today from Diddy about his honeypot, seeing a lot of email directed at a username, at, and then an IP address.

0:24.1

That's a common way to look for open mail relays.

0:28.5

Turns out it's not really used much, but it actually works and it's standard compliant to use

0:33.1

an IP address instead of a domain name in the email and the result will be that your mail server

0:40.2

will just connect to that IP address directly. Aside from making sure that you're not running

0:46.7

an open mail relay and luckily I don't actually see a ton of them out there these days at least

0:51.8

less than there used to be.

0:57.3

If you do have to validate email addresses,

1:00.8

make sure you don't allow an IP address as a host name.

1:04.1

It's often abused, but technically valid. So a lot of functions that just check if an email address is formatted correctly,

1:09.6

will accept this format.

1:13.9

And Trent Micro has an interesting blog post with details about an operation that they're calling

1:20.5

SMS phone verified account services.

1:24.1

What this is all about is it's yet another way how an attacker is able to monetize

1:31.2

access to a compromised Android phone. And this really only works in Android based on some of the

1:39.5

sandboxing done in iOS. So essentially the way this works is a phone is infected and then the phone

1:46.9

registers itself with the malicious SMS phone verified account service or a PVA service.

1:56.0

And that phone is now being made available as a temporary phone number that attackers are able to use

2:04.1

to, for example, register for services that require that you provide a valid phone number.

2:11.2

You may have seen this where you do register for, let's say, webmail service or something like this, but you do have to provide

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.