ISC StormCast for Friday, March 2nd 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 2 March 2018
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, March 2nd, 2018 edition of the Sandton and Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:12.0 | Let me first start up with a couple of updates on stories covered earlier this week. First of all, the denial of service attack via Memcash D. |
| 0:23.0 | There's now a good write-up from GitHub who was at the receiving end of one of these |
| 0:28.6 | denial of service attempts. |
| 0:30.7 | Well, it turns out that they received well over 1 terabit per seconds. |
| 0:36.3 | So this sort of sets new records as far as the amount of traffic |
| 0:41.3 | being hurled against a victim. The other issue regarding these Mimkash, the attacks |
| 0:47.3 | is that in my original write-up I missed the important feature of these attacks. |
| 0:55.0 | In my honeypot, I just saw them use the stats command, which does for sure provide some amplification, |
| 1:03.0 | but what's actually happening here in the commenter to the original diary mentioned this, |
| 1:09.0 | that the attacker will first actually load some data |
| 1:13.0 | into the database and then requested, which then leads to these very large amplifications. |
| 1:20.9 | The other story I would like to update is regarding Trustico. |
| 1:25.3 | First of all, yes, Trustico did offer a feature where they were creating |
| 1:30.3 | the key pair for you and apparently they did hold on to the secret key. They also had sort of |
| 1:36.3 | a feature on their website where you could convert your secret key from one format into another, |
| 1:41.3 | which of course did require that you uploaded your secret key |
| 1:45.2 | to Trustico's website. |
| 1:48.2 | Second part to this is today they displayed a lot of errors to users that tried to visit |
| 1:54.5 | their site. |
| 1:56.2 | Initially it looked like it was just overwhelmed based on the traffic caused by all the news regarding Trustico, |
| 2:03.6 | but apparently they also have arbitrary command injection vulnerably on their website, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

