A Tale of Two Phishing Sties

Two phishing sites may use very different backends, even if the site itself appears to be visually very similar. Phishing kits are often copied and modified, leading to sites using similar visual tricks on the user facing site, but very different backends to host the sites and reporting data to the miscreant.

https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810

A Phihsing Tale of DOH and DNS MX Abuse

Infoblox discovered a new variant of the Meerkat phishing kit that uses DoH in Javascript to discover MX records, and generate better customized phishing pages.

https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/

Using OpenID Connect for SSH

Cloudflare opensourced it's OPKSSH too. It integrates SSO systems supporting OpenID connect with SSH.

https://github.com/openpubkey/opkssh/

Podden och tillhörande omslagsbild på den här sidan tillhör Johannes B. Ullrich. Innehållet i podden är skapat av Johannes B. Ullrich och inte av, eller tillsammans med, Poddtoppen.

Senast besökta

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Monday, March 31st: Comparing Phishing Sites; DOH and MX Abuse Phishing; opkssh

00:00