meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, August 28th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 August 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. security.txt; DNS Queries; MSFT Extends Win10 1803 Deadline; LemonDuck Tricks

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, August 28, 2020 edition of the Sandtonet Storm Center's

0:06.5

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.1

Good reminder today by Jan about security.com. This is a text file that you should have on your web server in order to give contact information to a researcher who finds a security vulnerability.

0:30.6

Either in your web application, of course, that's the obvious reason, but also in your organization at large.

0:39.0

Couple side notes on this.

0:40.1

First of all, this file is found in the dot well-known directory.

0:45.5

Again, something that's seriously known, but instead of littering essentially the document

0:51.2

route with all of these files.

0:53.4

Lately, these files have been moved into the dot well-known

0:57.3

directory secondly it may be a good idea to take a look at who is accessing that file

1:03.9

because a researcher may take a look at the secure text file but then not necessarily report the vulnerability, sort of have

1:13.0

second thoughts as to whether or not to do so. And yes, of course, there is a little bit of

1:18.2

reconnaissance value in this file as well that a bad guy may attempt to exploit. But in the end,

1:25.5

it's all about helping the bad guys to get in touch with you and report

1:30.1

a problem.

1:31.1

And from my own experience, I can tell you this makes a huge difference.

1:34.4

I often haven't gotten around to really track down security contacts if it's just way

1:41.9

too complex to find them.

1:44.0

At this point, security.comtext is not yet sort of a complete finalized RFC,

1:51.7

but it's a draft and it's easy enough to implement that there is really very little downside to it.

1:59.0

Now, talking about security features that backfire and cause problems,

2:04.5

apparently Google Chrome's DNS hijacking feature is causing problems for the root DNS infrastructure.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.