meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, April 28th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 April 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. BGP Attack against VISA; Antminer DoS Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, April 28th, 2017 edition of the San Santernet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.1

BGP, the Border Gateway Protocol that organizes routing across different networks on the internet is in the news again and that's

0:23.1

usually not a good thing in this particular case a net block that's assigned to visa the credit

0:30.8

card company was rerouted to a russian ISP not 100% sure why this happened, could be a mistake, could be an attack, but the sad part

0:42.9

is that it's still possible even with a very visible netblock like this to reroute it

0:51.6

at will.

0:52.8

Now in this case, BGP Mon, which is a company that's actually part of Open DNS, did catch

0:59.8

the event.

1:01.0

That's their business.

1:02.2

They're monitoring for odd BGP traffic like that, and they wrote up a nice blog about

1:09.3

what they saw.

1:11.5

Now, one thing an attacker could do with a BGP hijacking attack like this is take advantage

1:18.0

of a vulnerability in the popular Bitcoin mining gear and miner.

1:24.8

Andminer apparently is responsible for something like 70% of the internet's

1:30.9

Bitcoin mining power. Not sure if the number is correct, but it is certainly substantial.

1:37.6

The problem with ant miner is that it does check in anywhere between every one and 11 minutes with its manufacturer.

1:48.4

So if you bought one of these devices and installed it in your network every five minutes or so,

1:55.2

it will connect back to the manufacturer.

1:57.6

And if the manufacturer sends the right signal back, since you just fail for this check-in request,

2:05.3

then the ant miner will shut down. There appears to be no authentication used for this particular

2:12.9

check-in and in addition to checking whether or not it should continue mining Bitcoin, the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.