meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, December 12th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 December 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Fast PS Portscanner; Bypassing WAFs; Invisible npm malware; PCI Software Security; vmware advisory

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, December 12, 2022 edition of the Sandsenet Stormsetters Stormcast.

0:08.8

My name is Johannes Ulrich.

0:10.4

And I'm recording from Jacksonville, Florida.

0:15.1

Rob on Friday published an update to his port scanner written in PowerShell.

0:20.5

The original version worked but was slow compared to... an update to his port scanner written in PowerShell.

0:26.3

The original version worked but, well, was slow compared to other tools, particular,

0:27.4

of course, NMAP.

0:35.5

So a Rob updated tool to actually perform scans in parallel, which did significantly increase the overall speed and then, of course, also led to results

0:39.1

that are actually faster than NMAP.

0:41.9

Well, take a look at his post

0:43.9

for the entire code of the sport scanner.

0:49.1

And the Clorati Team 802 research team

0:53.4

published a blog post with a trick that Dase allows them to bypass common

1:00.5

web application firewalls. The attack they focused on was SQL Injection. Sequel injection is, of course,

1:08.0

quite popular. OASP top 10 and all, and various replication

1:13.3

firewalls do have rules to detect a SQL injection.

1:17.9

The problem with detecting signal injection attacks is that of course with SQL, we have

1:22.7

a wide range of formats, queries and such that can be used in order to bypass some of these

1:30.5

rules.

1:31.4

And web application firewalls then have to sort of play catch up, not just with creative ways

1:36.7

how attackers are bypassing the rules, but also with SQL servers who keep sort of adding

1:42.7

features and making it more difficult

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.