ISC StormCast for Tuesday, May 23rd 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 May 2017
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, May 23rd, 2017 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.3 | My name is Johannes Ulrich and the damn recording from Jacksonville, Florida. |
| 0:12.1 | Typically, phishing emails isn't something we really worry about too much, |
| 0:16.9 | but they had an interesting one today targeting users of the Uber car sharing service. |
| 0:23.8 | Now these phishing emails weren't just done pretty well with respect to the layout and such, |
| 0:28.5 | but also the fishing site itself used a TLS certificate, which is somewhat unusual even though |
| 0:36.3 | not really that difficult to accomplish. |
| 0:39.3 | The fishing email itself arrived as a fake Uber email that claimed that you just took a right with Uber |
| 0:47.3 | and these emails looked just like what the receipts you usually get at the end of your right look like. Now the one thing they changed |
| 0:56.0 | is that they had a prominent link at the bottom of the email that would link to Uber disputes. |
| 1:02.7 | Of course the idea here was that as soon as you see this obviously fake or fraudulent email you would click on Uber disputes to dispute |
| 1:13.5 | that charge with Uber. This is where the fish kicked in. This domain was fake. It was not |
| 1:21.6 | associated with Uber, even though it did have a valid TLS certificate. |
| 1:28.3 | In this particular case, the attacker did use Cloudflare as a proxy in front of this particular website. |
| 1:36.3 | Cloudflare, of course, does offer as a free service TLS certificates. |
| 1:41.3 | In general, this isn't really worse than what most certificate authorities are |
| 1:46.4 | doing. Let's say let's encrypt and the like that will give you a TLS certificate if you are |
| 1:53.0 | able to prove ownership of the particular domain name. And of course, the attacker here did own |
| 1:59.3 | uberdisputes.com. |
| 2:01.7 | Another sort of interesting part here was that the site disappeared very quickly after we |
| 2:06.3 | learned of it. |
| 2:07.4 | So some of my investigation I had to perform after the site was already shut down. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

