meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 25th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 25 October 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Outlook.com C2; Apple Patches; Cisco Vuln; Dormant Colors

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, October 24, 2022 edition of the Sandsenage Storm Center's

0:07.8

Stormcast. My name is Johannes Ulrich, and today I'm recording from Augusta, Georgia.

0:15.1

Xavier today wrote up a Python script that uses Outlook.com as a covert channel. The use of popular cloud services

0:23.5

like this for covert channels and data X filtration, of course, has become more and more

0:28.0

popular cloud services often offer APIs that are easily scripted. And then, of course,

0:35.9

the wide use of these cloud services and enterprises

0:38.3

makes the cover channel traffic really sort of disappear in all of the noise of the

0:43.3

legitimate traffic to these services now in this case discovered by Xavier the command

0:51.0

control channel actually doesn't use sort of any fancy Outlook 365 APIs.

0:56.8

Instead, it uses good old email protocols.

1:00.9

The bot essentially just the polls for new emails via IMAP.

1:06.3

There's a specific account that's sort of being configured in that bot and the emails that are being read

1:13.8

will then contain any commands for the bot. Now, if there's any data that's coming back as a result

1:21.5

of the commands, that's then being sent to the same Outlook.com address via SMTP. Of course, the TLS versions of both

1:30.5

protocols are being used, making detection even more difficult. I think if anything, maybe the

1:37.1

volume, the number of requests over time for these IMAP SMTP connections could sort of raise suspicion for an analyst monitoring the networks

1:48.7

carefully, but overall this is the kind of a co-vart channel that is fairly difficult to detect.

1:59.1

And Apple today released one of its massive updates.

2:02.9

The most significant part was the release of Mac OS 13 Ventura.

2:09.4

iPad OS also received a new major version jumping straight from 15 to 16.1, which is now in sync with iOS, because also for iOS, we got

2:21.1

16.1, of course, the original 16 version came a little bit earlier for iOS a few weeks ago.

2:29.8

The update patches, I think I counted in 108 different vulnerabilities.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.