ISC StormCast for Tuesday, May 15th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 May 2018
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, May 15th, 2018 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, |
| 0:09.2 | and I'm recording from Jacksonville, Florida. Monday morning, one issue made big waves, e-fail, a vulnerability in how many |
| 0:18.8 | email clients implement PGP and SMIME. |
| 0:21.6 | Now, EFail is really two distinct vulnerabilities. |
| 0:26.6 | The first one is a problem in how many email clients do implement SMIM and PGP, |
| 0:34.6 | and yes, this first problem does affect both encryption methods. |
| 0:39.3 | That all starts out with MIME. With MIME, we can have multiple parts in our email, |
| 0:45.3 | some of them may be encrypted, and your email client may be configured to automatically |
| 0:51.3 | decrypt encrypted parts. Secondly, an attacker would have a copy of the encrypted email. |
| 0:58.5 | Remember, that's why we encrypt them, |
| 1:00.3 | because the attacker can actually gain access to copies of our emails in transit. |
| 1:06.9 | Now, what the attacker is doing next is to create a three-part MIM message. |
| 1:13.4 | The first part is HTML and it's the start of an image tag. |
| 1:17.9 | The second part is the encrypted email. |
| 1:21.5 | The third part closes out the image tag. |
| 1:24.5 | So the idea here is that the user opens the email, the content is automatically |
| 1:30.3 | decrypted, but because the content is part of the image tag, it's then being sent to the |
| 1:36.3 | attacker's web server from which the client attempts to download the image. |
| 1:42.3 | So again, this first vulnerability, not a problem with either PGP and S-MIME, |
| 1:47.1 | really just a problem with sloppy parsing of MIME and HTML emails, and you should never really |
| 1:54.6 | download images from remote servers. Many email clients do protect you from that and don't do that |
| 2:02.0 | automatically so that would be the first thing to check. Secondly, you probably |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

