Web App Security, Social Engineering Google Results, and Privacy Not Included




InfoSec ICU show

Summary: Gerry and Brandon discuss a recent web application vulnerability that has caused a business to respond with what appears to be breach notifications. They discuss social engineers attacking Google results to trick victims into trusting contact information. Finally, they cover several hot IoT items this holiday season and the privacy implications.<br> <a href="https://podcast.musc.edu/podcast/infosec/e53-infosecicu/" target="_blank" rel="noopener noreferrer">Show Notes</a><br> <br> Resources:<br> <br> Healthcare Web Application Security Issues<br> <a href="https://www.healthcareinfosecurity.com/another-healthcare-website-security-issue-revealed-a-11752" target="_blank" rel="noopener noreferrer">https://www.healthcareinfosecurity.com/another-healthcare-website-security-issue-revealed-a-11752</a><br> Social Engineers Attack Google Results<br> <a href="https://www.hackread.com/fraudsters-changing-contact-details-of-bank-on-google-maps" target="_blank" rel="noopener noreferrer">https://www.hackread.com/fraudsters-changing-contact-details-of-bank-on-google-maps</a><br> Privacy Not Included<br> <a href="https://foundation.mozilla.org/en/privacynotincluded/" target="_blank" rel="noopener noreferrer">https://foundation.mozilla.org/en/privacynotincluded/</a><br> One Cool Thing<br> Blue Team Handbooks<br> <a href="https://www.amazon.com/Blue-Team-Handbook-condensed-Responder/dp/1500734756" target="_blank" rel="noopener noreferrer">https://www.amazon.com/Blue-Team-Handbook-condensed-Responder/dp/1500734756</a><br> Quad9 DNS Resolver<br> <a href="https://www.quad9.net/" target="_blank" rel="noopener noreferrer">https://www.quad9.net/</a><br>  <br> Contact<br> Email <a href="mailto:infosecicu@musc.edu">infosecicu@musc.edu</a><br> Twitter:<br> <br> * <a href="https://twitter.com/Gerald_Auger" target="_blank" rel="noopener noreferrer">Gerry Auger (@Gerald_Auger)</a><br> * <a href="https://twitter.com/sgcardinal" target="_blank" rel="noopener noreferrer">Steven Cardinal (@sgcardinal)</a><br> <br>