4.9 • 696 Ratings
🗓️ 28 January 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, January 28th, 2025 edition of the Sands and the Storm Center's |
0:08.3 | Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:15.3 | Well, today we have a diary by Jan looking at one of his favorite topics, and that's how attackers are bypassing |
0:22.8 | fishing filters. The common trick being used here is often referred to as C-Wasp for Cerro |
0:30.1 | with characters, and there are a number of different spaces, non-breaking spaces and the |
0:35.4 | like that are often used here that are invisible to the |
0:39.2 | user, but a machine looking for keywords like password would not recognize those keywords |
0:46.2 | because they are broken up with these special characters. |
0:51.1 | A particular character that Jan is looking at in this example is the soft hyphen, |
0:57.7 | which is why Jan dubs this particular version of the attack, the C-Sci attack, where S-H-Y is the |
1:06.2 | HTML entity being used for the soft hyphen that is then included in these emails in order to |
1:12.7 | obfuscate them and make them similar to these serral white space, another sero-width characters |
1:19.8 | readable to the human but not readable to the machine. |
1:25.1 | Interesting technique and what this really drives home is that yes, you know, we have |
1:29.3 | fancy filters for our email messages that try to identify spam, but a sufficiently motivated |
1:37.4 | attacker is probably going to figure out a way around this because there are just so many |
1:43.0 | options to make a text look |
1:44.8 | very different to the machine compared to the user. |
1:50.5 | And Apple today released its usual updates for everything. |
1:54.9 | So we got updates for Vision OS, iOS, iPad, OX. |
1:58.0 | We got updates for MacOS going back three versions to Ventura of MacOS 13. |
2:06.4 | We also got updates for WatchOS, TVOS, and of course, Safari for these older versions of MacOS. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.