ISC StormCast for Friday, July 15th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 July 2022
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, July 15, 2020 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich, and this is the last podcast that I'll be recording this year from Sands Fire here in Washington, D.C. |
| 0:18.3 | With me here in Washington, D.C. is Robbannon Bring, and Rob actually wrote today's |
| 0:24.5 | diary about an interesting network problem that he had at a client and how he identified the |
| 0:32.2 | root cause. This was not an attack. It was sort of a self-inflicted denial of service attack. |
| 0:38.9 | The initial indication that something went wrong was that essentially clients didn't get replies to their DHCP discover messages. |
| 0:49.4 | Turned out that it was really just too much traffic going through a particular switch, |
| 0:55.1 | maxing out the switch because of a badly configured old legacy switch |
| 1:00.8 | that was connected to the network and then causing broadcast storms, |
| 1:06.6 | overloading the network and preventing these DHSP messages from actually being received and responded to properly. |
| 1:15.4 | Fixing these kind of issues, of course, always require a good mix of experience and a solid procedure in debugging networks. |
| 1:22.6 | And hopefully you can cleanse some of these procedures from Rob's diary. |
| 1:30.8 | Then we got yet another method in order to de-anonomize web browsers presented in a paper |
| 1:38.1 | by researchers from the New Jersey Institute of Technology. |
| 1:43.2 | Like some of these methods, it may be more theoretical than practical, |
| 1:47.8 | but certainly in some targeted cases could be applied. |
| 1:52.6 | The trickier is as so often to try to trick the victim into caching image or any other content and then measuring how fast that content |
| 2:04.8 | is being retrieved. This would work, for example, if the operator of a particular forum is trying |
| 2:10.8 | to de-anonymize a particular user and has a suspicion as to, for example, what that particular |
| 2:17.0 | user's Gmail address is. |
| 2:19.6 | The attacker, which is the forum owner in this case, |
| 2:23.8 | would send an image to that Gmail address, |
| 2:26.7 | and the user will likely load that image in their browser |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

