ISC StormCast for Friday, December 20th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 December 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, December 20th, 2019 edition of the Sansonet Storm Center's |
| 0:07.0 | Stormcast. |
| 0:08.0 | My name is Johannes Ulrich Entertainment recording from Jacksonville, Florida. |
| 0:14.0 | Well, as I mentioned yesterday, today I made the blog post live with additional details about DNS over HTPS and how to possibly |
| 0:25.7 | decode some of the content. |
| 0:28.7 | The basic principle is pretty straightforward. |
| 0:32.9 | The actual content of the DNS query, so the DNS data that would usually go over UDP is, well, sent over |
| 0:40.0 | HTTP 2, but the actual DNS content is sent in a packet by itself, and the size of this |
| 0:48.3 | packet directly correlates with the size of the host name you're looking up. Now, not a huge vulnerability in that sense, but certainly something that should probably |
| 0:58.8 | be fixed and Firefox already indicated that they're working on this. |
| 1:04.8 | There is a DNS option that they can take advantage of, which will allow them to add padding to each DNS query |
| 1:13.2 | to obscure the actual length of the query. |
| 1:17.7 | Now, I did some testing today with different DNS over HGPS providers. |
| 1:23.3 | Most of them will actually not support this option. |
| 1:27.0 | Cloudflare, for example, in my testing at least, didn't respond at all. |
| 1:32.5 | Others responded with errors. |
| 1:35.1 | There are only a couple that really support the option. |
| 1:38.3 | Also interesting with Cloudflare, Cloudflare actually pads the responses that are coming back. |
| 1:44.0 | So that's a little bit odd even if you're not sending this option. Cloudflare actually pads the responses that are coming back. |
| 1:45.7 | So that's a little bit odd. |
| 1:51.2 | Even if you're not sending this option, it will still respond with that option, which is actually not quite sort of RFC compliant. |
| 1:54.7 | Well, I'll certainly keep playing with this. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

