ISC StormCast for Friday, February 23rd, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 February 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, February 23rd, 2004 edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:14.2 | Rachel Downs, one of our Sands.edu interns, has contributed a real nice diary today looking at a good range of data |
| 0:25.4 | probing for TCP port 502. |
| 0:29.2 | TCP port 502 is used for modbus and modbus is an industrial control system protocol. |
| 0:37.4 | Now, she did detect quite a bit of activity |
| 0:40.6 | here, but then looked closer at where does the activity actually come from. And to her surprise, |
| 0:49.4 | she found that 89% of the scans originated from researchers. |
| 0:56.7 | There were more than a dozen different research groups, |
| 0:59.5 | I think about two dozen different research groups, |
| 1:01.8 | that did scan her honeypot for Port 502 TCP. |
| 1:08.1 | This is something that we have talked about before. I've sometimes seen sort of the |
| 1:13.0 | overall scan rate of like 30% just originating from these researchers. A couple problems |
| 1:20.2 | with some of these researchers. First of all, they're not always easy identifiable as researchers. |
| 1:26.0 | Also, not always clear who's actually behind the research, |
| 1:30.4 | like what company, what organization or so is behind it. And then some of them do not have |
| 1:36.8 | a clear way to opt out of their scans. Putting aside some of the ethical questions about |
| 1:42.8 | scanning the internet without really asking for permission, |
| 1:47.1 | it should be sort of a minimum requirement that you at least offer some form to opt out |
| 1:53.0 | and that you clearly identify who the scan originates from. |
| 1:59.0 | And you probably already heard from the regular news that, well, Thursday |
| 2:05.5 | morning, AT&T had a major outage, if not taking down their entire wireless network, at least |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

