ISC StormCast for Monday, December 12th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 December 2022
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, December 12, 2022 edition of the Sandsenet Stormsetters Stormcast. |
| 0:08.8 | My name is Johannes Ulrich. |
| 0:10.4 | And I'm recording from Jacksonville, Florida. |
| 0:15.1 | Rob on Friday published an update to his port scanner written in PowerShell. |
| 0:20.5 | The original version worked but was slow compared to... an update to his port scanner written in PowerShell. |
| 0:26.3 | The original version worked but, well, was slow compared to other tools, particular, |
| 0:27.4 | of course, NMAP. |
| 0:35.5 | So a Rob updated tool to actually perform scans in parallel, which did significantly increase the overall speed and then, of course, also led to results |
| 0:39.1 | that are actually faster than NMAP. |
| 0:41.9 | Well, take a look at his post |
| 0:43.9 | for the entire code of the sport scanner. |
| 0:49.1 | And the Clorati Team 802 research team |
| 0:53.4 | published a blog post with a trick that Dase allows them to bypass common |
| 1:00.5 | web application firewalls. The attack they focused on was SQL Injection. Sequel injection is, of course, |
| 1:08.0 | quite popular. OASP top 10 and all, and various replication |
| 1:13.3 | firewalls do have rules to detect a SQL injection. |
| 1:17.9 | The problem with detecting signal injection attacks is that of course with SQL, we have |
| 1:22.7 | a wide range of formats, queries and such that can be used in order to bypass some of these |
| 1:30.5 | rules. |
| 1:31.4 | And web application firewalls then have to sort of play catch up, not just with creative ways |
| 1:36.7 | how attackers are bypassing the rules, but also with SQL servers who keep sort of adding |
| 1:42.7 | features and making it more difficult |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

