meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 23rd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 23 February 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Old Vuln Still Used; Horde XSS Exploit; NoVNC Phishing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 23rd, 2022 edition of the Sandcent Storm Center's Stormcast.

0:08.6

My name is Johannes Ulrich and I am, according, from Jacksonville, Florida.

0:14.1

With all the focus on patching and patching quickly, it's sometimes sad to see how apparently old vulnerabilities are still a thing

0:22.8

or still working well enough for attackers to actually exploit them. And Xavier did run into

0:30.6

an example where a malicious word document exploited the good old equation editor vulnerability from back in 2017.

0:41.5

So essentially, I guess, a five-year-old vulnerability.

0:45.6

Now, the work document here arrived sort of as a fuzzy image with a magnification class to

0:53.5

click on.

0:54.5

So essentially, the user is sort of enticed to click on that image,

0:58.8

which then in turn launches the equation editor

1:03.0

if the victim is vulnerable and does inject the malicious code,

1:08.0

which is essentially just a bad file that will load additional malware

1:14.1

from a particular IP address.

1:16.8

Also interesting kind of here that only an IP address is being used, not a host name.

1:22.1

This is something that I always tell people to watch out for any outbound connections that go to an IP address that is

1:30.7

not the result of a DNS resolution. First is usually suspicious with few exceptions and there are

1:39.1

some nice seek scripts, for example, to detect this kind of behavior. When teaching web applications security and talking about cross-site scripting, there are usually

1:50.0

sort of a couple points I make, but two points are that first of all, one of the most difficult

1:55.0

type of applications to create is a webmail application because you often have to render HTML that's delivered

2:03.0

as part of the email as part of the HTML webmail client.

2:08.1

And of course, then it's difficult to keep things straight.

2:10.9

This is even more difficult if you are in addition to plain HTML also attempting to render, for example, open office documents.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.