4.9 • 696 Ratings
🗓️ 2 January 2024
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, January 2, 2020, 24 edition of the Sansonet Storm Center's Stormcast. |
0:08.3 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:14.0 | Over the holiday week, we had a couple of interesting diaries, so let me just quickly summarize them. |
0:20.4 | First of all, Xavier looked at more Python scripts |
0:24.9 | with actually a user interface. And one interesting script, Xavier came across, was a little |
0:32.5 | bounce ball game, as it calls itself. It's sort of one of those arcade game remakes, but well, it's |
0:40.8 | actually much more than a game while you're playing the game, and the game appears to be fully |
0:45.9 | functional. You are also exfiltrating data from your system. The main goal here appears to be |
0:53.7 | exfiltration of Discord credentials, |
0:56.7 | and yes, they are being |
0:58.9 | infiltrated to Discord itself. |
1:03.7 | And Xavier also came across |
1:05.5 | another Python script that used |
1:08.1 | mailtrap.io in order to infiltrate data. Maililtrap.io in order to |
1:11.0 | infiltrate data. |
1:13.4 | MailTrap.io is a service that will allows you to send |
1:17.1 | emails, but also to receive email, in particular for debug |
1:21.5 | purposes. |
1:22.6 | That part of the service is free and offers an SMTP server on port 25, 25 instead of just 25, which of course |
1:32.3 | can be used to bypass some firewalls. Always important to block outbound emails, no matter what |
1:40.8 | port is being used, they should be going through your authorized mail relay. |
1:47.0 | We've got two more diaries, one guest diary by one of our Sands.edu interns, Elias Boussate, and this |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.