meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 16th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 16 June 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. HTML Phishing; TMobile Outage; LTE/5G GTP Issues; #SANSFIRE HAndler Talks

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 16th, 2020 edition of the Sandcent Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich.

0:09.0

And today I'm recording from Jacksonville, Florida.

0:13.0

One of the more tricky ways to do a fishing attack is instead of setting up a website and redirecting the user to the website, you are just delivering

0:24.8

an HTML file as an email attachment, and this HTML file will then implement the actual

0:32.7

phishing page.

0:34.3

So the user opens the attachment, the HTML will then be rendered by the user's default

0:40.0

browser displaying some kind of login form whatever the attacker decided to send you. And then,

0:47.9

of course, the attacker has to somehow get the data that you are submitting. And there are a couple

0:53.8

different ways of doing this.

0:55.0

Now, of course, it could be done just with a little submit in a form that then redirects

1:01.0

to the external site or JavaScript or like in this case, an I-frame that actually includes

1:09.0

part of the code from a remote website.

1:12.6

So this is kind of a little bit of a hybrid approach where some of the HTML is being delivered

1:18.3

as part of the email. The rest is then included via the iFramm. This gives the attacker some flexibility

1:26.1

to, for example, redo that part of the HTML.

1:30.3

At this point, this attack that one of our readers send us in Rick Analyzed doesn't really look all that sophisticated, a little bit clumsy as Rick describes it, but of course the sad part is, sometimes the attacker learns and then these attacks

1:46.1

are getting progressively better.

1:49.8

And you may have noticed that today and that's on Monday we had some issues with cell phone

1:57.8

connections in the US.

1:59.5

Now it appears that T-Mobile was the most affected network, but according to some reports,

2:07.2

other carriers may have been affected as well.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.