meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, February 25th, 2026: Open Redirects; setHTML in Firefox; telnetd issues

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 25 February 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, February 25th, 2026: Open Redirects; setHTML in Firefox; telnetd issues

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, February 25th, 2006 edition of the Sands International

0:11.0

Storm Center's Stormcast. My name is Johannes Ulrich, recording day from Jacksonville, Florida.

0:17.3

And this episode is brought you by the Sands.edu, graduate certificate program in cloud security.

0:24.0

One thing I noticed today was that our honeypots have been seeing recently a big increase

0:29.9

in the number of scans looking for open redirects.

0:34.8

An open redirect is a feature in a web application where the web application redirects you

0:39.9

to another site without any regard as to where the user is really being redirected to.

0:47.1

And it often happens as part login pages where you would like to, for example, direct a user

0:52.6

to the page the originally attempted to visit, and

0:55.7

well, also have clicked through counters and similar features that often use redirects, and

1:02.8

with that are susceptible to creating open redirects. There are a couple of problems with open

1:10.1

redirects. So open redirects is basically a redirect.

1:12.6

They are not really filtering what page you're redirecting the user to.

1:17.6

The receiving page may then, for example, receive URL parameters, but could also be used for fishing.

1:25.6

One spot where this has been particular sort of a little bit of problem lately is with Oath 2,

1:33.0

where during this of the initial credential flow where you are authorizing a site to use a particular service.

1:41.2

Well, the size is being redirected back to the client that's attempting

1:47.5

to use these credentials. But if an attacker is able to swap that redirect URI for a URI that is

1:56.4

vulnerable for an open redirect, the attacker may obtain credentials, and that sort of bypasses

2:03.8

some of the protections that sites have put in place to prevent these changes of the redirect

2:12.7

URI.

2:13.6

So it's certainly an important vulnerability.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.