ISC StormCast for Tuesday, September 22nd 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 September 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, September 22nd, 2020 edition of the Sandsand and Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Jan today looked at an interesting fishing attempt that we actually received at our handler email address. |
| 0:22.8 | It attempts to overlay a login dialogue to a legitimate page by using iFrames. |
| 0:31.5 | And while it sort of almost worked, it was a little bit broken and probably sent to us by mistake. |
| 0:38.3 | One mistake was that first of all it didn't fill in a variable that's required. |
| 0:45.3 | Now the variable domain, maybe they just misspelled it and it should actually be domain, |
| 0:50.3 | but if that's filled in correctly, then the user's email address is essentially sort of |
| 0:56.7 | pre-filled as a username and just as for the password. |
| 1:02.8 | The other part that didn't really quite work right in this particular attempt is the entire |
| 1:08.6 | screen layout. |
| 1:09.8 | Seem to be more targeted at mobile device or devices with smaller screens. |
| 1:15.6 | This may also be some limited quality control on the attacker's side, then well, |
| 1:21.6 | and it's probably no different from real developers. |
| 1:25.6 | And I ran to these issues myself where it's really hard to sort of test all the different |
| 1:30.3 | browsers and screen resolutions that users use to visit your site. |
| 1:36.3 | So, yep, it doesn't always look the way you expect it to look. |
| 1:42.3 | Part of this attack is also limited by the X-frame options header, |
| 1:46.8 | of course, more recently replaced with content security policy, which also limits what can |
| 1:54.4 | be displayed inside NIFRame and can make at least the execution of some of these attacks more difficult. |
| 2:03.6 | And Adam Chester with TrustedSec wrote an interesting blog post about how to inject |
| 2:10.6 | a code on Mac OS via third-party frameworks. |
| 2:15.6 | MacOS made it more and more difficult to execute untrusted code. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

