meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday Mar 25th: Privacy Awware Bots; Ingress Nightmare; Malicious File Converters; VSCode Extension Leads to Ransomware

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 25 March 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday Mar 25th: Privacy Awware Bots; Ingress Nightmare; Malicious File Converters; VSCode Extension Leads to Ransomware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, March 25th, 2025 edition of the Sands and at Storm Center's

0:09.2

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.6

Well, after yesterday's issue with Next.js and the interesting headers around that. I decided today to look a little bit

0:23.7

closer at some of the headers being sent by bots against our honeypots and notice the use

0:30.9

of a couple particular little bit odd headers. The first one, SEC dash GPC, this is a header that's specifically assigned to

0:40.7

indicate your privacy preferences. This is, I see it as a replacement for the do not track header,

0:47.7

which of course we all know kind of spectacularly failed. This new header is a little bit more

0:53.4

aligned with GDPR and other regulations like this.

0:56.6

So apparently they hope that in doing so, there will be more acceptance of that header.

1:03.3

At this point, only Firefox actually adds it. There are a couple other headers as

1:08.8

saw all of them start with the SEC Dash prefix,

1:12.3

which just indicates that, hey, this is not great by JavaScript.

1:16.1

That's really all that means there's nothing so particular secure kind of other than that fact about these headers.

1:23.3

Makes it a little bit easier for browser developments to decide what they should allow JavaScript to set and what, well, JavaScript must not set.

1:33.1

The reason that bots at these headers is typically in trying to impersonate real browsers better.

1:42.0

Now, the SECGPC header is a little bit odd here

1:46.0

because, well, it is only by Firefox.

1:49.7

And they're using user agents that are not Firefox.

1:53.4

So in some ways, they're actually giving away

1:55.5

that this is not a normal browser.

1:58.6

And of course, for the attacks,

2:00.5

they're trying to attempt here. Well,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.