meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 6th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 February 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Time to Spam; Anydesk Update; Latest Ivanti Exploit; Deepfake Exploits;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, February 6, 2020,

0:04.0

for edition of the Sandin and Storms, Stormcast.

0:08.0

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.9

A quick diary today from Jesse, which is really a preview of work that he sort of started,

0:24.0

and that's well how does exposing an email address to the public on a website effect spam received by that email address and how various

0:30.9

obfuscation methods kind of work and how effective they are again this is sort of still work in progress, just having

0:39.8

the email as part of a web form that apparently only took two days to receive spam, having

0:46.9

an HTML comment with an email address that took nine days. A simple obfuscation technique

0:53.6

where Jesse just replaced the ad simple with the word ad in parentheses,

0:59.7

that actually has so far been effective in stopping spam to go to that email address.

1:06.2

Of course, maybe just a matter of time.

1:07.7

As I said, this is still somewhat work in progress.

1:12.2

Personally, I found it's pretty much impossible to prevent an email address from receiving

1:18.2

spam.

1:19.1

If you just wait long enough, well, we'll see how long it will take for that obvious

1:24.7

email address to be picked up.

1:27.9

And then we got a little bit more details about what exactly happened at any desk,

1:34.0

at least what was compromised.

1:36.9

Apparently the attacker did have access to source code and also was able to compromise

1:43.4

the signing certificate used by any deskk in software it distributes,

1:48.8

which means the private key was stolen.

1:52.5

They now have used a new signing certificate.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.