meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, August 31st 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 31 August 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. CenturyLink Outage; NZX DDoS; Pulse Connect Secure Patch

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, August 31st, 2020 edition of the Sands Internet Storm Center's

0:06.0

Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:12.8

Sunday morning, we had a large outage at Sand TrayLink that caused many large sites across the internet

0:19.9

to no longer be reachable.

0:22.6

A fact that were sides, for example, behind Cloudflare, behind Imperva, also Open DNS.

0:28.6

We heard some users where they had problems reaching their service.

0:34.6

A lot of it did not necessarily depend on these services themselves, but also how different

0:40.0

customers reached these services and if Central Link was involved in that connection. In particular,

0:47.4

connections between the US and Europe appear to be quite heavily affected by this outage.

0:56.0

Of course, it's a little bit too early to expect a full post-mortem from CentralLink about this outage, but there are a number of

1:01.9

things that CenturyLink and others announced to put together some of the pieces as to what

1:07.7

happened. Cloudflare probably at this point has the best summary of these events.

1:13.2

It all started around 10 a.m. UTC on Sunday. That's about 6 a.m. Eastern Daylight Savings

1:22.5

time. And according to Cloudflare, they essentially first noticed that Cloudflare wasn't able to reach

1:29.7

some of its customers for which they are proxying connections.

1:35.0

So the result was that Cloudflare responded with 522 errors and that then sort of started

1:41.1

Cloudflare to investigate things further. The core of the problem was

1:46.5

AS 3356. Now if you look this up in some who is data, you may get level three back, but level

1:54.8

three was purchased by CenturyLink, so this is now a CenturyLink network.

2:01.3

According to CenturyLink, the root cause was a bad FlowSpec rule.

2:07.5

Now, FlowSpec is an extension to BGP, the Border Gateway Protocol, that regulates routing

2:13.2

across the internet.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.