ISC StormCast for Friday, April 10th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 April 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, April 10th, 2020 edition of the Sandstone at Storm Center's Stormcast. |
| 0:06.9 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.1 | Today we have a quick diary by Manuel about how to spoof OS fingerprints. |
| 0:20.0 | Now, NMAP, of course, always had the ability |
| 0:22.6 | to pretty accurately identify operating systems, |
| 0:26.6 | and it had a well-established database |
| 0:30.6 | of different operating system fingerprints. |
| 0:33.6 | A system under an attacker's control |
| 0:36.6 | can of course fake the response responses it's sending back. |
| 0:40.8 | And Manuel is introducing here a quick tool called OSFooler NG that's able to impersonate different operating systems. |
| 0:51.0 | Pretty neat little tool to play around with and learn more about how these subtle |
| 0:55.7 | difference in particular in TCP can be used to identify an operating system. And with everybody |
| 1:02.3 | still working from home, it's of course really important that you do have robust remote access |
| 1:08.6 | to your systems. One way to achieve this is the Dell IDRAG cards. |
| 1:15.4 | These are plugin boards that give you full access to power the console over IP networks, |
| 1:21.7 | and well, hopefully not over the internet. |
| 1:25.3 | Because Dell just released an update for the ID rack cards from version 7 through 9 that |
| 1:32.6 | fixes an unauthenticated buffer overflow vulnerabilities in these systems. |
| 1:39.5 | So an attacker could use this vulnerability to effectively take over the ID rack card and of course once they |
| 1:45.8 | have access to that they essentially do have a console access like physical access to the |
| 1:53.7 | affected system now as part of the advisory del does reiterate that you should connect these cards only to a separate management network. |
| 2:04.8 | So definitely be very careful about how you deploy them and they should never, ever be |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

