ISC StormCast for Friday, March 22nd, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 22 March 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, March 22nd, 24 edition of the Sands and its Storms and Stormcast. |
| 0:08.3 | My name is Johannes Ulrich and today I'm recording from Jackstable, Florida. |
| 0:13.9 | The diary I wrote today is about a feature that I see being used more and more in recent years, and that feature is the geo-feed attribute in Who-Is data. |
| 0:26.3 | Essentially, what this is about is that if you're looking at the Who-Is data |
| 0:30.3 | for a particular network, you will see a URL, the Geo-Feed URL. |
| 0:37.0 | This URL has a simple comma delimited file that will indicate |
| 0:42.7 | which net block is located at what location. There are a couple different fields that are |
| 0:49.0 | available. It starts with the country, then a region, like that would be a state in the United States, |
| 0:55.6 | can then go down to a city and even a postal code, even though these fields are then |
| 1:02.5 | optional and I don't see the postal code being used that terribly much. |
| 1:07.0 | But the point here is that this feature provides more granularity than you usually get |
| 1:13.6 | from who is. Who is usually just lists the headquarter address of the particular cloud provider |
| 1:20.2 | or ISP. And then it also allows the ISP to more easily keep that data up to date. |
| 1:28.5 | Interesting approach, and if you are interested in doing some geolocation on your own, |
| 1:34.8 | this may be a nice thing to use. |
| 1:38.3 | There's also a GitHub repo I have a link for in the diary that has a geofeed finder, Node.js script that can go out |
| 1:48.5 | and collect all of these geofeed files and ran it earlier, ran pretty well, not even sure |
| 1:55.8 | how complete it is yet. Anyway, so that's just if you're trying to do a little bit geolocation on IP addresses. |
| 2:05.9 | And then today we also got updates for iOS and iPad OS from Apple, also for Vision OS. There are |
| 2:14.2 | security updates that are being addressed with these patches, but Apple has not released any details yet. |
| 2:22.1 | This is very common. We probably will see in the next couple days the respective macOS, watchOS, |
| 2:29.1 | the other operating systems being updated. And once all the updates are released, Apple will then typically |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

